Making a forensic acquisition using a forensic work station and a hardware write blocker is the preferred method of acquiring a suspect drive. Although this setup is ideal, it may not always be an option for investigators. At times this may mean that the hard drive acquisition may need to be done using the suspects own computer. MacForensicsLab includes a bootable DVD for doing such acquisitions. This DVD has been specially designed to prevent writing to the drive and compromising the forensic integrity of the evidence.
- Start up the machine while holding the "Option" key. This will prevent the machine from booting to the internal drive and instead prompt you to to select the drive you would like to boot from.
- Insert the MacForensicsLab bootable DVD. Once it appears on the screen, double-click the MacForensicsLab icon to boot from the DVD.
MacForensicsLab will automatically launch once the system loads. You can then acquire an image of the suspect drive and even explore it using MacForensicsLab.