The Coroner's Toolkit
From Wikipedia, the free encyclopedia
The Coroner's Toolkit (or TCT) is a suite of computer security programs by Dan Farmer and Wietse Venema. It is intended to assist in a forensic analysis of a UNIX system after a break-in.
The suite runs on FreeBSD, OpenBSD, BSD/OS, SunOS/Solaris and Linux. There is also a port to HP-UX.
Parts of TCT are also somewhat applicable to analysis of and data recovery from other computer disasters.