UAC (Unix-like Artifacts Collector) is a portable incident response and forensic acquisition tool for collecting system artefacts from Linux and a wide range of other Unix-like environments.
It is particularly useful for live-response situations where an investigator needs a repeatable collection process without installing a substantial agent or resolving additional dependencies on the target system. Collection behaviour is controlled by YAML profiles and artefact definitions, allowing investigators to perform focused triage or broader forensic acquisition.
Its lightweight approach also makes UAC useful for servers, appliances, NAS systems, network devices and other environments where deploying a conventional forensic suite may be impractical.
This is free and open source software.
Key Features
- Runs directly from a shell without requiring installation or additional runtime dependencies.
- Uses customizable YAML profiles and artefact definitions.
- Respects the order of volatility during evidence collection.
- Collects information about running processes, including processes without an executable remaining on disk.
- Calculates hashes for processes and executable files.
- Collects file and directory status information for forensic bodyfiles.
- Gathers system information, user data, configuration files and logs.
- Supports volatile-memory acquisition on Linux using multiple approaches.
- Can transfer collected output to supported cloud storage platforms.
- Runs on AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
- Can operate on NAS appliances, OpenWrt devices and other systems with a compatible shell.
Website: github.com/tclahr/uac
Support:
Developer: Thiago Lahr
License: Apache License 2.0
Related Software
| Network Analyzers | |
|---|---|
| Wireshark | Network protocol analyzer with a rich and powerful feature set |
| Sniffnet | Visualise live network traffic with a friendly interface |
| Kismet | Wireless network and device detector, sniffer, wardriving tool |
| Ettercap | Comprehensive suite for man in the middle attacks |
| IPTraf-ng | Feature-laden network statistic monitoring tool |
| Zeek | Network security monitoring with deep traffic insight |
| netsniff-ng | Swiss army knife for daily Linux network plumbing |
| Kyanos | Networking analysis tool using eBPF |
| Arkime | Indexes full packet captures for rapid, large-scale traffic investigation |
| EtherApe | Graphical network monitor |
| darkstat | Captures network traffic, calculates usage statistics, and serves reports |
| justniffer | Network TCP packet sniffer with reliable TCP flow rebuilding |
| tcpflow | TCP/IP packet demultiplexer |
| tcpdump | Powerful and hugely respected command-line packet analyzer |
| sniffglue | Packet sniffer written in Rust |
| sniffer | Alternative network traffic sniffer |
| RustNet | Terminal monitor for connections and bandwidth |
| Malcolm | Traffic analysis suite for capture, hunting and forensics |
| dsniff | Collection of tools for network auditing and penetration testing |
| ngrep | grep applied to the network layer |
| Network Monitor | Rreal-time network connection monitoring tool |
| sniffit | CORBA based sniffer system with ncurses interactive mode |
| Jomon | Network forensics and sniffer tool |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |


Please read our Comment Policy before commenting.