Skip to content

Glossary

UAC (Unix-like Artifacts Collector)

UAC is an open source shell-script triage collector that gathers live-response data and forensic artifacts from Linux and other Unix-like systems.

UAC, the Unix-like Artifacts Collector (github.com/tclahr/uac), is a triage collection tool written in shell script. Because it relies on the shell and standard utilities already present on the system, it runs on Linux distributions as well as other Unix-like platforms without installing an agent or compiling anything. It collects live-response output (processes, network connections, users), logs, configuration files, shell histories, persistence locations and file system metadata into a single archive.

Collections are driven by profiles and artifact definitions written in YAML. The ir_triage profile is the usual starting point for incident response and full gathers much more. The output directory is a positional argument:

sudo ./uac -p ir_triage /media/ir/uac-out
sudo ./uac -p ir_triage --mount-point /mnt/evidence /media/ir/uac-out

The --mount-point option points collection at a mounted image or a disk from another system, which allows offline triage without running anything on the suspect host. Run UAC from external media, write output off the suspect filesystem and hash the resulting archive. Like any live tool, it sees the system through the running kernel, so a kernel rootkit can hide data from it; pair it with memory acquisition when that matters. See triage collection with UAC and Velociraptor.