How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
The main features of tclahr/uac are: Evidence Collection, Forensics and Incident Response, Live Forensics and Response, Digital Forensics, Forensics and Evidence Collection, Threat Hunting Tools.
Projects with overlapping indexed features include: orlikoski/cylr — CyLR - Live Response Collection Tool. velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… forensicartifacts/artifacts — Digital Forensics artifact repository. google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… diogo-fernan/ir-rescue — A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response. volatilityfoundation/volatility — Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from…
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro
Digital Forensics artifact repository