config/default.discovery.json

{
  "schemaVersion": "1.1.0",
  "description": "Master discovery configuration. 'defaults' is the global fallback layer for tunable parameters and IS read at runtime - precedence is: explicit command line > fast/deep parameterDefaults > these defaults > built-in fallback. Per-mode module enablement is driven by each module's own metadata (DefaultInFast / DefaultInDeep), refined by fast/deep discovery config plus command-line Include/Exclude. Every key below is consumed by code; do not add aspirational keys here - an unread key looks like a working knob and is worse than no key at all.",
  "defaults": {
    "outputRoot": "C:\\Temp",
    "maxDepth": 3,
    "largeFileThresholdGB": 5,
    "oldFileYears": 7,
    "eventLogDays": 14,
    "maxEventSamplesPerLog": 50,
    "configScanMaxFileSizeMB": 10,
    "deepFileShareScan": false,
    "includeConfigDependencyScan": false,
    "attemptSqlIntegratedAuth": false,
    "fullEventLogExport": false,
    "includeUserProfiles": false,
    "includeRecycleBin": false,
    "includeWindowsFolder": false,
    "moduleTimeoutSeconds": 600
  },
  "synthesisModules": [
    "RiskEngine",
    "DecommissionReadiness",
    "ScopeLanguage",
    "ClientInterviewPack",
    "EvidenceManifest"
  ],
  "collectorModuleOrder": [
    "SystemInventory",
    "RolesFeatures",
    "ServicesTasks",
    "Applications",
    "Network",
    "Storage",
    "FileShares",
    "SecurityPosture",
    "WindowsUpdate",
    "ActiveDirectory",
    "TimeSync",
    "DNS",
    "DHCP",
    "IIS",
    "SQL",
    "HyperV",
    "Cluster",
    "RDS",
    "NPS_RADIUS",
    "Certificates",
    "BackupDR",
    "PrintServer",
    "ConfigDependencyScan",
    "Licensing",
    "VendorAgents",
    "UserProfiles",
    "AzureHybrid",
    "PerformanceSnapshot",
    "EventLogs"
  ]
}