Skip to main content
Glama
MadameFabulous

Chainsaw MCP Server

Chainsaw: shimcache timeline

chainsaw_analyse_shimcache

Builds an execution timeline from the Windows shimcache registry hive, optionally enriched with Amcache, and outputs CSV for analysis.

Instructions

Build an execution timeline from the shimcache with optional Amcache enrichment.

Wraps chainsaw analyse shimcache. Output is CSV stored under a result handle; the preview holds the first rows. Use chainsaw_result_export for the full file.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
previewNoRows to include inline.
patternsNoRegexes identifying entries whose shimcache timestamp equals their insertion time (e.g. known-good installer paths). Default: bundled list if present, otherwise none.
system_hiveYesSYSTEM registry hive under an allowed evidence root.
amcache_hiveNoOptional Amcache.hve for timeline enrichment.
timestamp_pairsNoEnable near-timestamp pair detection with Amcache.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare readOnlyHint=false and destructiveHint=false but do not explain why a read-style 'analyse' is not read-only; the description supplies that answer by disclosing that output is a CSV persisted under a result handle with only a preview returned inline. That is meaningful context beyond the annotations, though it says nothing about permissions or runtime cost.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, front-loaded with the core action, then the implementation, then the output/export contract. No filler and nothing redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description correctly explains the return contract (CSV under a result handle, preview inline) and points to the export tool for full retrieval. It is nearly complete for a 5-parameter forensics tool; only the when-to-use selection against sibling analyses is absent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already carries the parameter burden, and the description adds no syntax or format detail for system_hive, patterns, timestamp_pairs, or preview. The phrase 'the preview holds the first rows' loosely echoes the preview parameter but adds no new semantics, so baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Build an execution timeline from the shimcache') and names the optional enrichment source (Amcache). The artifact focus distinguishes it from the sibling analyse tools (evtx, srum, gaps) without needing the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It routes the agent forward ('Use chainsaw_result_export for the full file') which is real guidance, but it never states when to choose shimcache analysis over sibling analyses such as chainsaw_analyse_srum or chainsaw_analyse_evtx, nor any prerequisite conditions. Usage is implied by the tool name rather than explained.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.