Forensic analysis of Macs, as used in law enforcement, can now be carried out in the field with the introduction of MacMarshal 2 in both a forensic and a new field edition, the latter coming pre-loaded on a USB thumb drive to analyze live running machines, including volatile states such as RAM contents, prior Wi-Fi access points, swap and hibernation file contents and Spotlight searches. The program can analyze both drives and disk images, detecting and displaying virtual-machine images or Windows partitions as well.