The Coroner's Toolkit (TCT) :: Forensic Data Analysis
TCT is a collection of programs by Dan Farmer and Wietse Venema for a post-mortem analysis of a UNIX system after break-in. The software was presented first in a Computer Forensics Analysis class in August 1999 (handouts can be found here). Examples of using TCT can also be found on-line in a series of columns in the Doctor Dobb's Journal.
0 TrackBacks
Listed below are links to blogs that reference this entry: The Coroner's Toolkit (TCT) :: Forensic Data Analysis.
TrackBack URL for this entry: http://kennethhunt.com/mt/mt-tb.cgi/387