The Coroner's Toolkit (TCT)

Not Rated
Description
TCT is a collection of programs for a post-mortem analysis of a UNIX system after break-in. It enables you to collect data regarding deleted files, modification times of files and more.

Install this BEFORE you need to use it, so you do not risk destroying essential forensic data before you begin.

Tools contained within this package: grave-robber, lazarus, inode-cat, ils, unrm and pcat.
Interface: Command Line
Associated Programs
acct The GNU Accounting utilities for process and login accounting
dd GNU core utilities
File Determines file type using magic numbers
lsof Utility to list open files
TimeOut run a command with a time limit
Available deb Repositories (how-to add a respository)
Debian 32-bit 64-bit
stable 1.19-1 1.19-1

Ubuntu 32-bit 64-bit
lucid 1.19-1 1.19-1

Rating: Not Rated (0 votes)


Login or Register to rate The Coroner's Toolkit (TCT), add a Tag, or designate as an alternative to a Windows app



Upload Screenshots
Images must be in GIF, JPG, or PNG formats and can be no larger than 2 MB. Only one file can be uploaded at a time. A description can be included, but it is optional.
Desc:
File:
You must login or register to upload a screenshot.
Submit Web Links
Submit the title and link (including http://) to an article pertaining to The Coroner's Toolkit (TCT) and it will appear in the Web Links section of the right banner. Contact us here if an entry needs to be removed.
Title:
Link:
You must login or register to post links.