Spectra logo

Spectra MacCollect — User Guide

Documented live triage & logical acquisition for macOS
Software version 2.0.1 · Guide revised June 18, 2026 · Spectra FIC, LLC — Cleveland, Texas

1 · What it is — and what it isn't

Spectra MacCollect performs documented live triage and logical acquisition on a running Mac.

It takes a read-only, point-in-time snapshot of the subject's data, copies it into a logical image, optionally collects high-value artifacts for triage, and seals the whole result so any later change is detectable. Its value is the record it leaves behind: a complete, hashed, self-verifying evidence set, with an honest account of what it could and could not capture.

It is deliberately not a physical, bit-for-bit image of the subject's storage. On modern Macs — particularly Apple Silicon and FileVault-encrypted systems — a traditional physical image of the internal drive is frequently unobtainable. Spectra MacCollect does not claim to produce one, and it does not recover unallocated space, deleted-but-not-overwritten data, or drive slack. It is a logical capture of live, accessible data.

2 · Before you begin

Have the following ready:

3 · The licensed drive

Spectra MacCollect runs from an external drive with two partitions:

Launch the app from the MacCollect volume. The license travels with the drive, so it activates automatically on later launches.

Bring-your-own-drive: the license binds to your drive's serial number. If you supplied your own drive, the license was issued against that serial and the app detects it on launch.

4 · License activation (first launch)

The first time the app runs on a drive, it shows the activation screen. After that it re-checks the saved license automatically and skips straight ahead.

License activation
License activation

5 · Drive readiness (one-time)

Right after first activation, a one-time readiness check confirms the three things that matter most before a run.

Drive readiness
Drive readiness

If Full Disk Access isn't granted, use Open Full Disk Access, grant it to this app copy, fully quit and relaunch, then Re-check. Once passed on a licensed drive, this screen is skipped on future launches.

6 · Starting a collection — the gate

Each run opens at the gate.

License & authorization gate
License & authorization gate

7 · Best-practices checklist

A short pre-flight checklist, headed by a live Full Disk Access status banner.

Best-practices checklist
Best-practices checklist

The banner is green when Full Disk Access is detected and red when it isn't; Continue is unavailable until it's granted. Review the best-practice items — power, closing other apps, destination space and health, keeping the Mac awake, post-imaging eject/verify, and backups — then select I'm Ready — Continue.

Antivirus: in rare cases third-party antivirus can interfere with a collection. If you hit issues, temporarily disable it and reactivate immediately after.

8 · Choosing a collection mode

Choose a collection mode
Choose a collection mode

Data Presets lets you save and reuse artifact selections for triage runs.

9 · Case setup & options

Setup is a guided, scrolling set of cards. Fields and options vary by the mode you chose.

Case setup & options
Case setup & options

Case information

Examiner, case / matter number, collection number, examiner title, collection location, client, and primary contact. Required fields are marked; optional fields are simply omitted from the record when blank.

Evidence destination

Choose the destination on your evidence drive. The tool creates its EVIDENCE folder (SparseImage / Collection Log / Triage) there. You can also set the unified-log window (how far back system logs are collected).

Sparse image / E01 encryption

Collection profile & artifacts (triage modes)

For triage and combined modes, pick a collection profile or a custom selection, then confirm the artifact modules to collect. The screen shows how many of the available modules are selected and what each one captures. When everything is set, select Begin Collection.

10 · Running the collection

The progress screen shows exactly where the collection is, with a live elapsed timer.

Collection in progress
Collection in progress

Sequential phase bars track Pre-check of device, Imaging, Triage, Collection close-out, and Convert to E01 (the last appears only when E01 conversion is on). A completed phase fills green; the active phase shows its own progress and elapsed time.

The live collection log streams every action as it happens; derivation and cleanup logs are written alongside it, and the whole set is SHA-256 hashed.

Do not interrupt. Near the end, a content-hash fixity pass reads the full image to prove integrity. This can take several minutes and runs quietly — the progress bar and elapsed timer show it is still working. Let it finish.

11 · The sealed evidence set

When the run completes, the EVIDENCE folder holds an organized, sealed set:

Honest non-capture: files that are off-device (consistent with iCloud "Optimize Mac Storage"), permission-protected, or locked are documented rather than silently omitted.

12 · Verifying a collection

A sealed set can be checked by anyone, independently, with standard tools — no Spectra software required:

  1. Recompute the seal anchors and confirm they match the values recorded at collection time.
  2. Verify every sealed file against the integrity manifest:
shasum -a 256 -c <manifest>
  1. Confirm the triage manifest reports every collected artifact as present and intact.
  2. Confirm the E01 derivative's acquired and verified SHA-256 equals the image content hash recorded under the seal — the three values match (seal = acquire = verify).

13 · Troubleshooting

Full Disk Access shows as not granted

Grant Full Disk Access to this exact app copy on the drive, then fully quit and relaunch before re-checking — macOS only re-reads the permission on a fresh launch.

License shows invalid

The most common cause is a serial mismatch. On the activation screen, type or paste the exact serial the license was issued against rather than relying on auto-detect.

The run seems slow

Collection time tracks the number of files, not just data size. A volume with very large numbers of tiny files (for example, a large local version-history store) takes longer to read. This is machine state, not a fault, and the elapsed timer confirms the tool is still working.

Destination won't accept the image

The tool refuses to write evidence to the subject's internal disk or to the same device being imaged. Use a separate external evidence drive.

14 · Support & licensing

For licensing, evaluations, renewals, or to submit a drive serial for a bring-your-own-drive license, contact info@spectramacollect.com.

All guidance regarding forensic methodology and admissibility is engineering and informational in nature, not legal advice. Admissibility is jurisdiction- and matter-dependent and is a question for counsel in a specific matter. Interface images are representative of the v2.0 application. © 2026 Spectra FIC, LLC.