tclahr/uac
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris. observed · 2026-08-28
Health v2 · maintenance only
84/100
- Activity 99
- Release rhythm 56
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 148
- age_days: 2429
- days_rel: 139
- days_push: 8
- n_releases_24m: 4
Adoption not part of the score
1437 stars · 197 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
UAC (Unix-like Artifacts Collector) is a portable, dependency-free shell-based incident response tool that automates forensic artifact collection across Unix-like systems. It uses customizable YAML profiles to gather processes, logs, configuration, and volatile memory while respecting the order of volatility.
Use cases
- collect forensic artifacts from a compromised Linux server
- run live response triage on macOS during an intrusion
- gather evidence from AIX, Solaris, or FreeBSD systems
- acquire volatile memory from a Linux host
- customize data collection with YAML profiles
- perform compliance checks and forensic investigations without installing agents
- collect artifacts from IoT devices or NAS systems
When to choose
- you need a portable, no-installation forensic collector that runs on nearly any Unix-like system
- you want customizable, extensible artifact collection via YAML profiles
- you need to respect order of volatility during evidence acquisition
- you support heterogeneous environments including IoT, NAS, and legacy Unix systems
When to avoid
- you need Windows endpoint forensics collection
- you want a centralized agent-based EDR or continuous monitoring platform
- you require deep automated analysis rather than raw artifact collection
Facets
cli-tool · maturity active
security developer-tools cli security developer-tools cli cross-platform bsd incident-response forensics dfir artifact-collection live-response triage shell-script memory-acquisition yaml-profiles command-line linux macos
2 sources
- readme: https://github.com/tclahr/uac · fetched 2026-08-28 · 35e986743f64
- homepage: https://tclahr.github.io/uac-docs · fetched 2026-08-29 · 7c21782037ac
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| tclahr/uac | main | 84 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem