Icon Menu
Icon Search

Recon ITR

Recon ITR is an macOS Imaging, Triage and Reporting solution.

RECON ITR brings both Bootable and Live imaging options into one. An indispensable tool for anyone who needs to image and capture data from all Intel macOS computers.

RECON ITR is designed for both novice and advanced investigators. Be up and running to get answers in seconds with limitless reporting options.

RECON forensic solutions are built natively on the macOS platform to support imaging and triaging a Mac natively. With RECON ITR there is no need to wait for answers like other solutions. RECON ITR does the triage and analysis within the same tool. With RECON ITR there is no need to collect data with one tool then purchase another tool to do the analysis. Get the answers you need right now.

Collect and image only the files that matter, including artifacts from iOS, macOS, and Boot Camp. RECON ITR is specifically designed to get the maximum amount of data in the least amount of time.

Both Bootable and Live Imaging Solutions

Take the guesswork out of what tool to use for imaging Macs. RECON ITR includes both Bootable and Live Imaging solutions to image all Intel Macs and their filesystems.

RECON ITR combines both the functions of bootable and live imaging from RECON TRIAGE and RECON IMAGER PRO into an integrated solution that automatically identifies, displays and can image FileVault, APFS and Core Storage volumes and disks at a cost well below any other tool.

RECON ITR images all Intel based Macs including the newest generation of Mac’s with APFS and T2 Chipsets. No more waiting for other solutions to catch up to the latest technology to do what RECON ITR can do today.

macOS Triage Solution Provides Answers in Seconds

RECON ITR has hundreds of plugins to parse thousands of artifacts from macOS, iOS backups and Boot Camp built-in. RECON ITR performs analysis and triage within the same tool to give you answers in seconds of live running Macs or Macs connected in Target Disk Mode in a write-blocked environment.

SUMURI has designed RECON ITR with the customer in mind, ensuring examiners have the most versatile tool available when changes occur to Apple hardware or Mac operating systems. RECON ITR accomplishes this and much more by including unique and revolutionary features while keeping the price significantly lower than competitors.

RECON ITR Main Features Include:

  • Support for the imaging and triaging of Apple Silicon Macs

  • macOS Volatile Data Collection

  • Software write-blocking built-in at no additional charge

  • Support for T2 Chipsets, APFS, and local time machine snapshots (APFS snapshots)

  • Logical Imaging with Automatic Artifact Collection

  • Rapid release schedule for updates and new module development

  • Triage and process iOS Backups

  • Reporting formats – PDF, HTML, CSV and XML

  • Advanced Timeline Analysis

  • Track and view a suspect’s location

  • Recover user and system passwords

  • Identify the origin of files

  • Automatic chat timeline construction for iMessage and Skype

  • Ability to customize and save templates

  • Advanced and in-module File Exporter

  • Custom Plugin development available

  • Identify and export Virtual Machines

  • Included are USB Type C-to-C and Type C-to-A cables for added convenience

  • Built-in security options on the T7 utilizes the AES 256-bit encryption

  • Includes both a Bootable drive and a live imaging drive with space for data collection

  • Mac forensic imaging and a whole lot more!

RECON ITR includes PALADIN PRO at no extra charge to support imaging and triage of macOS, Windows, and Linux.

PALADIN PRO

PALADIN, SUMURI’s bootable Linux distribution, was created as an opportunity to give back to the forensics community.

PALADIN PRO is a preconfigured USB with 64-bit and 32-bit versions of PALADIN and PALADIN EDGE on a new USB drive that now features connections for both USB Type-A and C! This eliminates having to carry multiple disks and supports the widest variety of hardware.

PALADIN includes over 150 pre-compiled open-source tools and our PALADIN ToolBox. The PALADIN ToolBox features imaging, hashing, image conversion, selective logical imaging, imaging of unallocated space, and automatic write blocking.

PALADIN has been court-tested and is used by thousands of forensics examiners around the globe.

Ask Fulcrum for a trial license today