Report Catalog¶
Run reports with:
uv run perceptor --root ROOT report REPORT_NAME --case CASE_ID --format table
Most reports support json, table, csv, and md, but some specialized
reports have narrower options. Use uv run perceptor report REPORT_NAME --help for
the exact switches.
This catalog is generated from the current report --help command set and
groups all 228 report subcommands by topic.
Core Case Review¶
summarydashboardtriage-dashboardcase-reviewexecutive-summarycase-overviewactivity-digestactivity-summarynext-actionsrunbookreview-statushandoff-packagecase-comparisonevidence-gapsevidence-qualityartifact-summaryartifact-completenessartifact-processing-statuscombined-artifactsoperation-manifestevidence-extractions
Validation, Specs, and Storage¶
validatevalidate-outputsspecsspecstorage-policyissuessqlite-inventorydb-storageregression-smokeworkspace-healthprocessing-estimateworkspace-mapunmapped-importsprogressprogress-manifestsresume-planprocessing-decisionsprocessing-readinessreadiness-gatetool-runsprocess-timingscleanup-candidates
Execution and Threat Activity¶
executionexecution-correlationpersistenceautostartsbrute-forcemalware-hiding-placesinteresting-executablessuspicious-executionssuspicious-timeline-windowsdata-exfiltrationaccount-compromisebits-activityexaminer-edge-artifactsprogram-provenancecd-burningprefetchamcacheshimcachesdeletetor-usageuninstalled-app-artifactsencrypted-volumesphone-linkvirtualization
Accounts, Sessions, and Computers¶
accountssessionssessioncomputer-inventoryusersuser-activityuser-timelineuser-intent
Filesystems, NTFS, and Recovery¶
mftfilesystem-entriesntfs-indexntfs-logfilentfs-namespacenon-standard-adsntfs-security-descriptorsfilesystem-reviewuser-file-referencesuser-file-reference-sourcerecycledeleted-foldersrecovery-coveragecarve-coveragedeep-recovery-statusfilesfile-namesfile-name-drilldownfile-dossierfile-intelligencefile-historycopied-filescopied-file-indicatorscopied-file-groupscopied-file-drilldowncopied-usb-files
File Metadata and User Documents¶
file-metadatafile-metadata-skippedfile-metadata-unresolvedfile-metadata-skipped-deletedfile-metadata-skipped-orphansfile-metadata-foldersfile-metadata-summaryoffice-backstageoffice-trustuser-dictionariesdownloaded-filesthumbcacheimage-analysis
Browser, WebCache, and Windows Activity¶
firefoxbrowserbrowser-artifactsbrowser-downloadsbrowser-cachebrowser-hostsbrowser-activitybrowser-profile-activitybrowser-deep-storagebrowser-cache-correlationswindows-activitieswebcachewebcache-files
Cloud Storage¶
cloud-artifactscloud-mountscloud-removable-overlapcloud-filescloud-configurationweb-cloud-correlationscloud-server-eventsopened-from-cloud-storage
Email, Messaging, and Communications¶
email-artifactsmailbox-messagesmailbox-attachmentsmailbox-attachment-coveragemailbox-attachment-copiesmailbox-copiescommunicationscommunication-groupscommunication-reviewmessaging-artifactsmessaging-messages
Timeline and Correlation¶
timelinetimeline-sourcestimeline-reviewderived-timeline-eventsevent-interpretationclipboardartifact-sourcesartifact-correlationscorrelation-groupscorrelation-groupcorrelations
Registry and Shell Artifacts¶
registryregistry-artifactsregistry-activityshellbagsshellbag-external-storagetaskbar-feature-usagetaskbar-pinscommon-dialog-itemsshortcutsshortcut-droid-changesshortcut-object-tracking
USN, SRUM, UAL, and Event Logs¶
evtxevtx-recoverytelemetry-artifactsusnusn-summaryusn-pathusn-userusn-reasonsusn-timelineusn-suspicioususn-user-filesusn-renamesusn-lifecycleusn-burstsusn-usb-candidatessrumsrum-networkssrum-app-usagesrum-contextual
Remote Access, RDP, and VPN¶
rdprdp-cacherdp-visual-observationsremote-accessremote-access-attributionmapped-network-pathsremote-access-tool-logsvpn-activityvpn-local-activityvpn-connectionsvpn-configvpn-executionvpn-sessions
Windows Search¶
windows-searchwindows-search-combinedsearch-index-runs
USB and External Storage¶
usbexternal-storagedevice-inventoryusb-filesusb-timelineusb-verboseusb-dossieropened-from-removable-media
Memory¶
memory-artifactsmemory-support-filesmemory-analysismemory-credentialsmemory-credential-reviewmemory-disk-correlationsmemory-string-hitsstructured-memorycrash-dump-analysis
Artifact Search¶
artifact-searchartifact-search-sourceslead-searchrerun-search-packetchanged-search-packets
File Movement Identity¶
file-movement-identityshortcut-droid-changesshortcut-object-trackingopened-from-removable-mediaopened-from-cloud-storage
Export¶
exportwrite-bundle