The Coroner's Toolkit (TCT) provides post-break-in data collection that could be useful in determining what happened. Less polished that the authors (Dan Farmer and Wietse Venema) usual work, the toolkit offers a patch-work of tools that help exhume interesting stuff from violated systems. Should be installed and examined before a break-in happens!
Category:
Random Site Quote:
The Coroner's Toolkit (TCT)
TCT is a collection of programs by Dan Farmer and Wietse Venema
for a post-mortem analysis of a UNIX system after break-in. The
software was presented first in a Computer Forensics Analysis class
in August 1999 (handouts can be found here ).
Examples of using TCT can
waiting for hand_moderation
Date Added: Jun 2, 2009 Hits: Rating: 0.00 Votes: 0