TCT is a collection of programs by Dan Farmer and Wietse Venema for a post-mortem analysis of a UNIX system. The software was presented first in a Computer Forensics Analysis class in August 1999 (handouts can be found here). Examples of using TCT can be found in our Forensic Discovery book.
Note: consider using Brian Carrier's Sleuthkit. It is the official successor, based on parts from TCT. Development of the Coroner's Toolkit was stopped years ago. It is updated only for for bugfixes which are very rare, and after Wietse discovers that the programs no longer work on a new machine.
TCT requires Perl 5.004 or later, although Perl 5.000 is probably
sufficient if you only use the data collection software, and do
the analysis on a different machine.
Extensions by other people
TCT has inspired people to implement additional functionality.
In order to have your software listed here, send mail to the
tct-users mailing list (see below).
This mailing list is now closed. The announcement below is kept for historical reasons.
We've created a mailing list tct-users@porcupine.org to discuss the toolkit and methods used to forensically analyze Unix systems. This list accepts postings from subscribers only.