Skip to content

Rename root#436

Open
halpomeranz wants to merge 71 commits intotclahr:mainfrom
halpomeranz:rename-root
Open

Rename root#436
halpomeranz wants to merge 71 commits intotclahr:mainfrom
halpomeranz:rename-root

Conversation

@halpomeranz
Copy link
Contributor

Renaming "[root]" to "collected_files" makes things easier in the uac code and also for analysts using the collected files.

I'm not wedded to "collected_files" if you want to change the name to something else. There are only a very few spots in the uac script needed to make the change.

This is apropos of Issue #435

ekt0-syn and others added 30 commits August 21, 2025 15:28
Detect running processes that inserted BPF filters in the Linux server
Update ss.yaml to show bpf filters
Add output and log filenames to the Azure Storage SAS URL.

Fixes tclahr#389
The output and log file names are now automatically appended to the URL provided in `--azure-storage-sas-url` ([tclahr#389](tclahr#389)). Consequently, the `--azure-storage-sas-url-log-file` option is no longer needed and has been removed.
feat: add statf tool for FreeBSD based systems
fix: parse special permissions in statx binary
Add an action to close stale pull requests older than 180 days.
artif: add binfmt_misc artifact
Resolved a bug that prevented proper artifact collection when the mountpoint of a mounted disk image included spaces or special characters.
tclahr and others added 29 commits January 15, 2026 08:32
Add one more parameter as command was added to _find_based_collector function.
feat: find collectors may include a command to use with xargs
artif: add additional possible persistence locations
Move artifact to a different artifact directory.
Add changelog.
Collect the SSH private key path only, and not the full key content.
Add System.map* to avml.yaml.
fix: look for systemd journal only in /var/log
artif: collect SSH public keys, test secret keys for null passphrases
Not only is the new name more descriptive, it's a lot less hassle in
both the "uac" code and also for later analysis.

Signed-off-by: Hal Pomeranz <hrpomeranz@gmail.com>
@halpomeranz
Copy link
Contributor Author

Unit tests will need to be updated to account for the new directory name

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants