Mac-robber is a forensics and incident response program that collects Modified, Access, and Change (MAC) times from files. Its output can be used as input to the ‘mactime’ tool in The @stake Sleuth Kit (TASK) to make a time line of file activity. mac-robber is similar to running the ‘grave-robber’ tool from The Coroner’s Toolkit with the ‘-m’ flag, except this is written in C and not Perl.
You can download it from the following link: https://packetstormsecurity.com/files/download/29624/mac-robber-1.00.tar.gz
Source: https://packetstormsecurity.com/files/29624/mac-robber-1.00.tar.gz.html