Chainsaw: shimcache timeline
chainsaw_analyse_shimcacheBuilds an execution timeline from the Windows shimcache registry hive, optionally enriched with Amcache, and outputs CSV for analysis.
Instructions
Build an execution timeline from the shimcache with optional Amcache enrichment.
Wraps chainsaw analyse shimcache. Output is CSV stored under a result handle;
the preview holds the first rows. Use chainsaw_result_export for the full file.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| preview | No | Rows to include inline. | |
| patterns | No | Regexes identifying entries whose shimcache timestamp equals their insertion time (e.g. known-good installer paths). Default: bundled list if present, otherwise none. | |
| system_hive | Yes | SYSTEM registry hive under an allowed evidence root. | |
| amcache_hive | No | Optional Amcache.hve for timeline enrichment. | |
| timestamp_pairs | No | Enable near-timestamp pair detection with Amcache. |