Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mac OS 12 - nothing from Files/Shell collected #244

Closed
tmill-strt opened this issue Jul 8, 2024 · 6 comments
Closed

Mac OS 12 - nothing from Files/Shell collected #244

tmill-strt opened this issue Jul 8, 2024 · 6 comments
Assignees
Labels
type: unconfirmed This doesn't seem right

Comments

@tmill-strt
Copy link

Hey Tclahr, great work with UAC. I like using it but in the past couple weeks while trying it out for Mac OS systems, I noticed trouble getting the shell history, shell session, and shell configuration plugins to collect from Apple Mac OS 12 hosts. I tried a number of command line variations but so far, nothing has produced teh expected files in the collection.

An example run:
% sudo ./uac -a files/shell/* --hostname /bin/hostname --debug /tmp


|: | | |: _ |: |
| |
| | | | | |
_
||| |||

Unix-like Artifacts Collector 2.7.0

Operating System : macos
System Architecture : arm64
Hostname : TSIRs-Virtual-Machine.local
Mount Point : /
Running as : root
Temp Directory : /tmp/uac-data.tmp

Artifacts collection started...
[001/003] 2024-07-08 12:10:30 -0700 files/shell/config.yaml
[002/003] 2024-07-08 12:10:33 -0700 files/shell/history.yaml
[003/003] 2024-07-08 12:10:36 -0700 files/shell/sessions.yaml

  • true
  • set +x

As in this example, I was hoping to get those three artifacts collected, but none of them were in the collection archive.

Can you look and confirm? If you like I can send you the debug uac file, just message me as a dm.
Thanks.
TWM

@tclahr
Copy link
Owner

tclahr commented Jul 8, 2024

Hello there. UAC 2.7.0 is quite old. Can you try the latest version 2.9.1 please? If it does not work, can you provide me the uac.log file?
Thanks!

@tclahr
Copy link
Owner

tclahr commented Jul 8, 2024

Also, can you provide the output for the following command, please?

ls -la ~

@tmill-strt
Copy link
Author

tmill-strt commented Jul 9, 2024 via email

@tclahr
Copy link
Owner

tclahr commented Jul 9, 2024

I did not receive the log file. Can you send it to [email protected] please?

@tclahr tclahr self-assigned this Jul 9, 2024
@tmill-strt
Copy link
Author

tmill-strt commented Jul 9, 2024 via email

@tclahr tclahr added the type: unconfirmed This doesn't seem right label Jul 11, 2024
@tclahr
Copy link
Owner

tclahr commented Jul 11, 2024

Closing this one as it was confirmed that files are being properly collected.

@tclahr tclahr closed this as completed Jul 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: unconfirmed This doesn't seem right
Projects
None yet
Development

No branches or pull requests

2 participants