Chainsaw: pivot process lineage
chainsaw_process_lineagePivot process GUIDs across scoped evidence files for a specific host to reconstruct Windows process lineage, including unmatched events.
Instructions
Pivot process GUIDs in explicitly scoped original evidence, including unmatched events.
Supply files from one investigation (not a shared evidence root) and an exact host. Each hop queries process/parent GUIDs; output is capped and reports incomplete traversal.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| paths | Yes | Explicit evidence files from one investigation. Directories and shared roots are rejected so unrelated scenarios stay separate. | |
| preview | No | Events to include inline (0-100). | |
| computer | Yes | Computer value of the host, compared case-insensitively; other hosts are ignored. | |
| max_hops | No | Parent/child hops to traverse (0-5). | |
| max_events | No | Total events to collect across all hops (1-5000). | |
| max_queries | No | Searches allowed before traversal stops as incomplete (1-256). | |
| process_guid | Yes | Starting Sysmon ProcessGuid, canonical GUID with or without braces. |