UAC

UAC

Incident response artifact collection for Unix

Description

After a breach you must grab logs, processes and connections before evidence disappears, and manual commands miss things. UAC is an incident response tool for forensic investigators and security analysts.

It automates artifact collection across Linux, macOS, BSD, Solaris and more, with extensible YAML artifacts.

Features



Automated:Logs to processes.

Compatible:Many Unix-likes.

Extensible:YAML artifacts.

No install:Runs directly.