Chainsaw: SRUM analysis
chainsaw_analyse_srumAnalyse Windows SRUM database activity from SRUDB.dat and a SOFTWARE hive to extract per-app resource usage; optionally return stats only. Output is saved to a result handle for export.
Instructions
Analyse the System Resource Usage Monitor (SRUM) database.
Wraps chainsaw analyse srum. Output is stored under a result handle; use
chainsaw_result_export for the complete text.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| srum_db | Yes | SRUDB.dat under an allowed evidence root. | |
| stats_only | No | Only report table statistics, not the full extraction. | |
| preview_bytes | No | Bytes of output to include inline. | |
| software_hive | Yes | SOFTWARE registry hive under an allowed evidence root. |