# tclahr/uac

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

Repository: https://github.com/tclahr/uac
Canonical: https://ross.abutalabs.com/products/uac
Homepage: https://tclahr.github.io/uac-docs
Language: Shell
License: Apache-2.0
License Family: permissive
Topics: incident-response, forensics, computer-forensics, triage, linux, aix, solaris, macos, openbsd, freebsd, netbsd, dfir, netscaler, esxi, live-response, shell, security, terminal, script, collector
Last push: 2026-08-25T23:51:03+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 56, longevity 100
- inputs: {"age_days": 2429, "days_push": 8, "days_rel": 139, "gap_med": 148, "n_releases_24m": 4}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1437, forks 197 (observed 2026-08-28T04:04:43.753976+00:00)

## What it is
UAC (Unix-like Artifacts Collector) is a portable, dependency-free shell-based incident response tool that automates forensic artifact collection across Unix-like systems. It uses customizable YAML profiles to gather processes, logs, configuration, and volatile memory while respecting the order of volatility.

## Use cases
- collect forensic artifacts from a compromised Linux server
- run live response triage on macOS during an intrusion
- gather evidence from AIX, Solaris, or FreeBSD systems
- acquire volatile memory from a Linux host
- customize data collection with YAML profiles
- perform compliance checks and forensic investigations without installing agents
- collect artifacts from IoT devices or NAS systems

## When to choose
- you need a portable, no-installation forensic collector that runs on nearly any Unix-like system
- you want customizable, extensible artifact collection via YAML profiles
- you need to respect order of volatility during evidence acquisition
- you support heterogeneous environments including IoT, NAS, and legacy Unix systems

## When to avoid
- you need Windows endpoint forensics collection
- you want a centralized agent-based EDR or continuous monitoring platform
- you require deep automated analysis rather than raw artifact collection

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, developer-tools, cli
- domain: security, developer-tools
- platform: cli, cross-platform, bsd
- tags: incident-response, forensics, dfir, artifact-collection, live-response, triage, shell-script, memory-acquisition, yaml-profiles, command-line, linux, macos

## Member repositories
- tclahr/uac (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:43.753976+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:36:45.371741+00:00, confidence not recorded.
  - readme: https://github.com/tclahr/uac (fetched 2026-08-28T04:04:43.753976+00:00, sha 35e986743f64)
  - homepage: https://tclahr.github.io/uac-docs (fetched 2026-08-29T11:47:29.955205+00:00, sha 7c21782037ac)
- Data as of 2026-08-30T08:39:29.467469+00:00.
