Built-in write blocking

macOS Volatile Data Collection – Automatic Volatile Data collection of important artifacts related to malware, hacking and user logins.
Image all Intel Macs with the power of RECON IMAGER PRO with both bootable and live imaging options.
Software write-blocking built in at no additional charge.
Support for T2 Security Chipsets, APFS file systems and Local Time Machine Snapshots (APFS snapshots).
RECON ITR brings both Bootable and Live imaging options into one. An indispensable tool for anyone who needs to image and capture data from all Intel macOS computers.

RECON ITR is designed for both novice and advanced investigators. Be up and running to get answers in seconds with limitless reporting options.

RECON forensic solutions are built natively on the macOS platform to support imaging and triaging a Mac natively. With RECON ITR there is no need to wait for answers like other solutions. RECON ITR does the triage and analysis within the same tool. With RECON ITR there is no need to collect data with one tool then purchase another tool to do the analysis. Get the answers you need right now.

Collect and image only the files that matter, including artifacts from iOS, macOS, and Boot Camp. RECON ITR is specifically designed to get the maximum amount of data in the least amount of time.

Both Bootable and Live Imaging Solutions

Take the guesswork out of what tool to use for imaging Macs. RECON ITR includes both Bootable and Live Imaging solutions to image all Intel Macs and their filesystems.

RECON ITR combines both the functions of bootable and live imaging from RECON TRIAGE and RECON IMAGER PRO into an integrated solution that automatically identifies, displays and can image FileVault, APFS and Core Storage volumes and disks at a cost well below any other tool.

RECON ITR images all Intel based Macs including the newest generation of Mac’s with APFS and T2 Chipsets. No more waiting for other solutions to catch up to the latest technology to do what RECON ITR can do today.

The Only macOS Triage Solution to Provide Answers in Seconds

RECON ITR has hundreds of plugins to parse thousands of artifacts from macOS, iOS backups and Boot Camp built-in. RECON ITR performs analysis and triage within the same tool to give you answers in seconds of live running Macs or Macs connected in Target Disk Mode in a write-blocked environment.

Endless Reporting Options at your Fingertips to get the Answers you need Quickly

RECON ITR automatically finds important artifacts, parses the data and presents them to you in a unified format that can be refined to produce the perfect report.
macOS Volatile Data Collection

RECON ITR includes automatic collection of Volatile Data for important artifacts related to malware, hacking and user logins

Capture Mac RAM from both the live and bootable environments with RECON ITR’s RAM Imager.

Forensic images produced by RECON ITR can be processed easily in RECON LAB – SUMURI’s Flagship Full Forensic Suite which automates analysis of Mac, iOS, Windows and more! 

Find out about RECON LAB here.

Logical Imaging with Automatic Artifact Collection

RECON ITR includes Selective Logical Imaging with RECON IMAGER PRO included. Quickly select the data to be imaged down to a single file.

RECON ITR is the only tool capable of preserving original timestamps during logical imaging of Mac data.

RECON ITR also has the ability to automatically collect macOS artifacts from any user account which can be processed automatically in RECON LAB!

Built in Software Write-Blocking

RECON ITR comes with built in write blocking capabilities. No need to purchase additional solutions to image and triage in a forensically sound manner.

iOS Backup Triage and Process

RECON ITR automatically detects, parses and can triage iOS backups. Recover messages, web browsing history and more in seconds.

Bootcamp Triage

RECON ITR has the ability to triage Boot Camp partitions in the field.  There is no need to create an image and return to the lab to see the data.

