disk_file_timeline
Generate a recursive MACB file timeline from a disk partition to trace file activity, and narrow results by path substring.
Instructions
Sleuth Kit fls — recursive file timeline from a partition (MACB timestamps).
Use path_filter (substring) to focus, e.g. 'Windows/Prefetch' or 'Users'.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| source | Yes | ||
| image_path | Yes | ||
| path_filter | No | ||
| sector_offset | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tool | Yes | ||
| source | Yes | ||
| preview | Yes | First rows only; query the rest via artifact_query | |
| row_count | Yes | ||
| artifact_id | Yes | Cite this id in findings (artifact_refs) | |
| payload_sha256 | Yes |