// the find
omnia-projetcs/RtCA
Windows forensic analysis tool, registry, audit logs, files, process, etc.
RtCA is a Windows forensic collection tool written in C. It appears to pull registry hives, event logs, prefetch, shellbags, USB history, process and network state, and files from a live machine into a SQLite database for review. It is aimed at incident responders and DFIR analysts who want a standalone binary to run against a suspect host.
- Artifact coverage is wide for one binary. The tree has dedicated modules for shellbags, UserAssist, MRU lists, USB history, prefetch, deleted registry keys, browser history, firewall and ARP state, and includes an MFT parser and shadow-copy access under tools/tools_copy.
- Writing results to SQLite (RtCA.sqlite, with the sqlite3 source bundled) means the output can be queried with standard tooling instead of being locked into a viewer. That suits triage work.
- Event log handling has test files for both the legacy .evt format and .evtx, which still matter for older hosts and historical investigations.
- Documentation is provided in both English and French as text files, so users outside a single language community have something to read.
- The README is one line. The Documentation/ text files are the only real usage guide, and there are no build instructions beyond a Code::Blocks project file (RTCA.cbp), so a newcomer has to work out the toolchain alone.
- The last push was in May 2018 and there is no CI. The test_*.c files look like manual harnesses rather than unattended tests, and nothing here shows the parsers have been checked against Windows 10 or 11 artifact changes.
- Repository hygiene is poor. Prebuilt RtCA_x86.exe and RtCA_x64.exe binaries, a RtCA.sqlite database, and stray files such as 'Copie de test_log.c' and tools_copy.c.save-failed are committed. Vendored SQLite and DES/RC4/MD5/SHA-2 code sits next to project code, which makes it hard to tell upstream code from local patches.
- The credential-recovery code (rev_mdp.c, windows_users_hashs_registry.c) handles password hashes from the registry. Nothing in the tree says how that material is protected in the output database, which matters for anyone running this on a host they do not fully control.