etch  ] [  etch-m68k  ] [  lenny  ] [  squeeze  ] [  sid  ]
[ Source: tct  ]

Package: tct (1.19-1)

collection of forensics related utilities

TCT is a collection of programs for a post-mortem analysis of a UNIX system after break-in. It enables you to collect data regarding deleted files, modification times of files and more.

Install this BEFORE you need to use it, so you do not risk destroying essential forensic data before you begin.

Tools contained within this package: grave-robber, lazarus, inode-cat, ils, unrm and pcat.

Tags: User Interface: Command Line, Role: Program, Scope: Utility, Security: Forensics, Intrusion Detection

Other Packages Related to tct

  • depends
  • recommends
  • suggests
  • dep: file
    Determines file type using "magic" numbers
  • dep: libc6 (>= 2.6)
    GNU C Library: Shared libraries
    also a virtual package provided by libc6-udeb
  • dep: libdate-manip-perl
    module for manipulating dates
  • dep: timeout
    run a command with a time limit
    or coreutils (>= 7.5-1)
    GNU core utilities
  • rec: lsof
    List open files
  • sug: acct
    The GNU Accounting utilities for process and login accounting

Download tct

Download for all available architectures
Architecture Package Size Installed Size Files
sparc 160.6 kB596 kB [list of files]