Categories
TCT
'TCT' is a collection of programs for a post-mortem analysis of a *NIX system after break-in. It is meant to create areconstruction of the past - determining as much as possible what happened with a static snapshot of a system. 'TCT' was designed primarily for people in the trenches - systems administrators, security response teams, security investigators, etc.
There are currently four major parts to TCT:
o grave-robber (data capturing tool) o the C tools (ils, icat, pcat, file, etc.) o unrm & lazarus (collection & analysis of data on a file) o mactime (analyzes the mtime file)
Last updated 5 Aug, 2004
About
Leadership
- Dan Farmer - Maintainer
- Wietse Venema - Maintainer
Requirements
- Perl 5.004 or later (Use Requirement)
Subprograms
graverobber, unrm, lazarus, mactime, ils, icat, pcat, file
Versions
1.15
1.15 beta released 2004-01-06
- Released: 6 Jan, 2004
- Code Maturity: Beta
- Source Archive: http://www.porcupine.org/forensics/tct-1.15.tar.gz
- Licenses: IBM Public License 1.0
- Interfaces: Command Line
User Community and Support
User README and man pages included



