The investigation process is a simple 4-step procedure: MacLockPick inserted into a suspect’s Macintosh computer. * Insert the MacLockPick flash drive into your suspect’s computer * Double Click on the MacLockPick Application * Eject the MacLockPick flash drive from your suspect’s computer * Return to the lab and investigate the data acquired and stored on the MacLockPick flash drive using the included program “KeyLog Reader”. KeyLog Reader is shipped for Mac OS X, Microsoft Windows, and Linux. (via MacLockPick - Live Forensics for OS X)