Most definitely, the U.K. government will play an integral part in the investigations since RIPA provides such sweeping powers. |
One thing for certain, the correlation and analyses of all of the digital data will be a key factor in any investigation. There will be many librarians and clerks who will be trying to analyze the systems. It could take months. |
Rather than test these tools, which involves a lot of complicated technology and the understanding of related technologies, courts instead rely on tools that have been used in past trials -- even if there are technologies that are more up-to-date and effective. TCT is certainly one of those tools as it's been used many times in court cases. |
TCT is a standard tool, or rather a collection of tools that are designed to assist in a forensic examination of a computer. It's designed for Unix systems, but it can also get some data collection and analysis from non-Unix disks and media. |
The investigation is going to be very physical, checking such things as flight records and credit records. I'm not sure what area of digital security may be used right now, but forensic tools will most likely play a part at some point. Probably at this stage there will not be a lot of direct forensic evidence needed. |
The TCTUTIL tools are for investigations using the file and directory name layer, for viewing deleted file names and it also gives mappings between the different file system layers. |