Tool Spotlight: Unix-like Artifacts Collector
An incident response tool that captures forensic evidence from Linux, macOS, and other Unix-like systems without taking them offline. Instead of manually pulling logs and config files one by one, it automatically collects system files and current state into a single package so you can preserve key evidence and start your investigation faster.
Here's how it helps during investigations:
- No installation needed. Just drop it on the host and run it.
- Collects key artifacts such as command history, processes, and network connections
- Lets you customize what to collect so you only grab what you need
Can optionally capture Linux memory dumps for deeper triage.
#cybersecurityawareness #Cybertools #incidentresponse #Linux #cybersecuritytools #digitalforensics #securitytools #cyberinvestigation
I recently had to use UAC, the Unix-like Artifacts Collector, for the first time.
I had seen it before, but I mostly relied on custom tooling for Unix-like artifact collection. After using it properly, I honestly donβt know why I waited this long.
Itβs a really solid tool for live response and triage. It can collect useful artifacts like system logs, process and network state, user activity, persistence locations, shell history, SSH artifacts, and suspicious file permissions.
If you are collecting forensic data from Unix-like systems and donβt want to take a full disk image, UAC is absolutely worth checking out.
https://t.co/Tcw3oT3oVb
π We are thrilled to announce that SandsBytes now supports 70+ artifacts from UAC (Unix-like Artifacts Collector)!
DFIR investigators can now analyze multiple Unix-like machines from a single interface to spot malicious activity at scale.
#DFIR#ThreatHunting#UAC
New #UAC (Unix-like Artifacts Collector) v3.0.0 released!
π New features
π New artifacts
π¨βπ» Thanks to all the contributors!!!
Get it here: https://t.co/Bexp7cc6Zt #digitalforensics#cybersecurity#infosec
#UAC (Unix-like Artifacts Collector) v2.9.0 released!
π New artifacts
π¨βπ» Special thanks to all the contributors!
Get it here: https://t.co/8lPPHaDPkv
#dfir#digitalforensics#cybersecurity#infosec
New #UAC (Unix-like Artifacts Collector) v2.8.0 released!
π New features
π New artifacts
π Bug fixes
π¨βπ» Thanks to all the contributors!!!
Get it here: https://t.co/8lPPHaDPkv
#dfir#digitalforensics#cybersecurity#infosec
New #UAC (Unix-like Artifacts Collector) v2.7.0 released!
πNew artifacts
π¨βπ»Thanks to all the contributors!!!
Get it here: https://t.co/8lPPHaDPkv
#dfir#digitalforensics#cybersecurity#infosec
@Securityblog It collects running processes info, hashes running processes and executable files, lists network connections, collects logs, shell history files, it extracts information from files and directories to create a bodyfile (very useful for timeline creation)...
Today I got an opportunity to hang out with @tclahr, the creator of UAC. He has recently released a @velocidex artifact so that UAC can be used to collect *NIX triage images at scale. Have you lveraged Velo for collections, you want to follow him Thanks for your time/work on UAC!
Did you miss the @sansforensics#DFIR Summit 2022 last week?
No worries! This is a curated list of links and resources brought to the #DFIRSummit attendees this year (Including mine βΊοΈ)
https://t.co/VoruexnKGK
#CyberSec#InfoSec