The Coroner’s Toolkit (TCT)

E298653

The Coroner’s Toolkit (TCT) is a pioneering suite of Unix-based digital forensics tools created by Wietse Venema and Dan Farmer for post-mortem analysis of compromised systems.

All labels observed (2)

Label Occurrences
The Coroner’s Toolkit 2
The Coroner’s Toolkit (TCT) canonical 1

How this entity was disambiguated

Statements (46)

Predicate Object
instanceOf Unix software
computer security tool
digital forensics software suite
creatorRoleOfDeveloper Dan Farmer
Wietse Venema
developer Dan Farmer
Wietse Venema
distributionForm source code
field computer forensics
computer security
genre security forensics toolkit
hasAbbreviation TCT
hasComponentType command-line utilities
hasDocumentation TCT man pages
online usage guides
includesTool findkey
grave-robber
ifind
ils
lazarus
mactime
pfind
tctutil
unrm
wcmd
influenced sleuthkit
surface form: The Sleuth Kit
license open source software
notableFor file system post-mortem analysis
pioneering Unix-based digital forensics
operatingSystem Unix
Unix-like systems
platform Unix command-line environment
primaryUse digital forensics
incident response
post-mortem analysis of compromised systems
programmingLanguage C
supportsTask analysis of compromised hosts
analysis of file system metadata
collection of forensic evidence from Unix systems
recovery of deleted files
timeline analysis of file activity
targetUser digital forensics investigators
incident responders
system administrators
typicalEnvironment Unix servers
RSA NetWitness
surface form: security incident response labs

How these facts were elicited

Referenced by (3)

Full triples — surface form annotated when it differs from this entity's canonical label.

Wietse Venema knownFor The Coroner’s Toolkit (TCT)
Wietse Venema developed The Coroner’s Toolkit (TCT)
this entity surface form: The Coroner’s Toolkit
Wietse Venema notableWork The Coroner’s Toolkit (TCT)
this entity surface form: The Coroner’s Toolkit