Skip to content

Glossary

UAC (Unix-like Artifacts Collector)

An open-source shell-script collector for Linux and other Unix systems that gathers logs and artifacts into a tar.gz for forensic analysis.

UAC (Unix-like Artifacts Collector) is an open-source live-response and collection tool written in shell script. It runs from an extracted folder on the target with no installation and no dependencies beyond the tools already present, which is why it works on almost any Unix-like system: Linux distributions old and new, but also the BSDs, macOS, Solaris and AIX.

What UAC collects is described in YAML artifact files grouped under artifacts/, for example files/logs/var_log.yaml for /var/log or files/system/utmp.yaml for the login records. Profiles bundle many artifacts: ir_triage for a standard incident-response triage, full for a broader collection, and offline and offline_ir_triage for a mounted disk image instead of the running system. The result is a single archive, by default uac-<host>-<os>-<date>.tar.gz, with the original folder layout preserved.

Why it matters in investigations

Log analysis is only as good as the collection behind it. UAC gathers the pieces that manual collection often misses: rotated generations, .journal~ files, user journals, the volatile journal in /run/log/journal, /run/utmp, and the context files needed to interpret times and UIDs (/etc/localtime, /etc/passwd). Because it keeps paths and modification times, a parser can recognise each file and infer the year of traditional syslog lines. It also gives a repeatable, documented procedure, which helps when the collection has to be defended later.

Example

Only the log artifacts, written to /tmp:

sudo ./uac -a files/logs/var_log.yaml,files/logs/run_log.yaml,files/system/etc.yaml,files/system/utmp.yaml /tmp

The standard triage profile, which includes the same logs and much more:

sudo ./uac -p ir_triage /tmp

Writing to /tmp changes the target's disk; use mounted external media when that matters.

Linux Log Parser opens UAC tarballs directly. See collecting Linux logs for forensics.