config/default.discovery.json
|
{ "schemaVersion": "1.1.0", "description": "Master discovery configuration. 'defaults' is the global fallback layer for tunable parameters and IS read at runtime - precedence is: explicit command line > fast/deep parameterDefaults > these defaults > built-in fallback. Per-mode module enablement is driven by each module's own metadata (DefaultInFast / DefaultInDeep), refined by fast/deep discovery config plus command-line Include/Exclude. Every key below is consumed by code; do not add aspirational keys here - an unread key looks like a working knob and is worse than no key at all.", "defaults": { "outputRoot": "C:\\Temp", "maxDepth": 3, "largeFileThresholdGB": 5, "oldFileYears": 7, "eventLogDays": 14, "maxEventSamplesPerLog": 50, "configScanMaxFileSizeMB": 10, "deepFileShareScan": false, "includeConfigDependencyScan": false, "attemptSqlIntegratedAuth": false, "fullEventLogExport": false, "includeUserProfiles": false, "includeRecycleBin": false, "includeWindowsFolder": false, "moduleTimeoutSeconds": 600 }, "synthesisModules": [ "RiskEngine", "DecommissionReadiness", "ScopeLanguage", "ClientInterviewPack", "EvidenceManifest" ], "collectorModuleOrder": [ "SystemInventory", "RolesFeatures", "ServicesTasks", "Applications", "Network", "Storage", "FileShares", "SecurityPosture", "WindowsUpdate", "ActiveDirectory", "TimeSync", "DNS", "DHCP", "IIS", "SQL", "HyperV", "Cluster", "RDS", "NPS_RADIUS", "Certificates", "BackupDR", "PrintServer", "ConfigDependencyScan", "Licensing", "VendorAgents", "UserProfiles", "AzureHybrid", "PerformanceSnapshot", "EventLogs" ] } |