The MacLockPick Process
The investigation process is a simple 4-step procedure:

-
Insert the MacLockPick flash drive into your suspect's computer
-
Double Click on the MacLockPick Application
- Eject the MacLockPick flash drive from your suspect's computer
- Return to the lab and investigate the data acquired and stored on the MacLockPick flash drive using the included program "KeyLog Reader". KeyLog Reader is shipped for Mac OS X, Microsoft Windows, and Linux.

KeyLog Reader works on Linux, Mac OS X, and Microsoft Windows.
The opening window for the KeyLog Reader program has three buttons on it:
- Open a keylog file - Press this button to select a keylog file. The files are stored in a folder on the flash drive.
- Show Help... - Press this button to open the help file.
- Quit - Press this button to quit the KeyLog Reader program.
Once you have selected a log file you will be presented with a window showing all of the data that has been collected from the suspect's computer. From within this window you can search for items of interest, sort items in alphabetical order by column, or export selected items to a plain text file.
