Chainsaw: list evidence
chainsaw_list_evidenceList artefact files below an evidence path with sizes and types to scope hunts; page results instead of scanning entire mounts.
Instructions
List artefact files below an evidence path with sizes and types.
Use it to scope a hunt: pick directories or individual .evtx files instead of hunting an entire mount. Follow next_offset until null for a complete inventory; the evidence tree must remain unchanged between pages.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | Directory or file under an allowed evidence root; '.' for the first root. Use chainsaw_status to see the roots. | . |
| limit | No | Maximum files to return. | |
| offset | No | Next offset from the preceding page. | |
| pattern | No | Case-insensitive substring filter on the full path. |