Collect Unix-like incident-response artifacts into one portable evidence bundle with UAC
Capture volatile and persistent Unix-like system artifacts quickly before evidence disappears or responders start changing the host.
Prerequisites
Shell access to the target Unix-like host, UAC runtime, sufficient privileges for artifact collection, storage location for the output bundle
Installation
Requirements and caveats from upstream:
- ⚡ Lightweight, portable, and requires no installation or dependencies.
Basic usage or getting-started notes:
-
Usage
-
Run everywhere with no dependencies (no installation required).
-
🚀 Usage
-
Source: https://github.com/tclahr/uac
-
Extracted from upstream docs: https://raw.githubusercontent.com/tclahr/uac/HEAD/README.md