Ross ROSS = Recommend OSS · open-source software intelligence for agents

tclahr/uac

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris. observed · 2026-08-28

github.com/tclahr/uac · homepage · Shell · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 56
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 148
  • age_days: 2429
  • days_rel: 139
  • days_push: 8
  • n_releases_24m: 4

Full methodology

Adoption not part of the score

1437 stars · 197 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

UAC (Unix-like Artifacts Collector) is a portable, dependency-free shell-based incident response tool that automates forensic artifact collection across Unix-like systems. It uses customizable YAML profiles to gather processes, logs, configuration, and volatile memory while respecting the order of volatility.

Use cases

  • collect forensic artifacts from a compromised Linux server
  • run live response triage on macOS during an intrusion
  • gather evidence from AIX, Solaris, or FreeBSD systems
  • acquire volatile memory from a Linux host
  • customize data collection with YAML profiles
  • perform compliance checks and forensic investigations without installing agents
  • collect artifacts from IoT devices or NAS systems

When to choose

  • you need a portable, no-installation forensic collector that runs on nearly any Unix-like system
  • you want customizable, extensible artifact collection via YAML profiles
  • you need to respect order of volatility during evidence acquisition
  • you support heterogeneous environments including IoT, NAS, and legacy Unix systems

When to avoid

  • you need Windows endpoint forensics collection
  • you want a centralized agent-based EDR or continuous monitoring platform
  • you require deep automated analysis rather than raw artifact collection

Facets

cli-tool · maturity active

security developer-tools cli security developer-tools cli cross-platform bsd incident-response forensics dfir artifact-collection live-response triage shell-script memory-acquisition yaml-profiles command-line linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
tclahr/uacmain84

For agents

markdown · JSON · MCP: product_card(name="tclahr/uac")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem