tclahr / uac

UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
https://tclahr.github.io/uac-docs
Apache License 2.0
739 stars 114 forks source link

artif: new systemd journal artifacts #277

Open mnrkbys opened 1 week ago

mnrkbys commented 1 week ago

Add new artifact to collect the "*.journal~". These journal files are created when system crashes or fails to shut down properly. Also, add artifacts related to "journalctl" command. These artifacts verify the integrity of journal files and show a listing of time periods between boots.