-
-
Notifications
You must be signed in to change notification settings - Fork 4
README
Logicytics is a Windows-focused, run-oriented evidence collector. It plans a bounded request, gives every selected collector an isolated workspace, registers the resulting files, and records the outcome in a durable manifest. This manual is for operators who need a defensible collection workflow and developers who need to preserve the engine's contracts.
Start with Installation, then follow Getting Started. For an actual investigation or administrative collection, keep Operations open beside the terminal and finish with Evidence Review.
| Goal | Read |
|---|---|
| I have never used the tool | Installation, Getting Started, Safety |
| I need to run a collection responsibly | Operations, Safety, Core Collector Catalog |
| I need to review or hand over evidence | Evidence Review, Results, Formats |
| I need every command | Command Reference |
| I want to understand the engine | Engine, Architecture |
| I need to change settings | Configuration |
| I need to find an evidence source | Core Collector Catalog |
| I need to read JSON, CSV, HTML, or ZIP output | Results and Formats |
| I want to run a plugin | Plugins |
| I want to write a collector | Plugin Authoring, Contracts |
| Something went wrong | Troubleshooting, Error Reference |
| I am maintaining the repository | Development, Verification |
Logicytics can collect sensitive local evidence. Only run it on systems and data you are authorized to examine. Start
with preflight, review the plan, use the smallest profile that answers the question, and inspect the selected
capabilities before authorizing a run.
- Install or repair the managed environment with the installer.
- Run
preflight; resolve invalid sources before collecting. - Create a
planfor the exact mode and selectors you intend to use. - Review the collector IDs, declared capabilities, output location, and any sensitive sources. Add exclusions or
--block-capabilitywhere needed. - Run only after adding
--acknowledge-authorizationdeliberately. - Read
manifest.jsonbefore relying on or sharing the output. A package is evidence delivery, not a success signal by itself.
The engine intentionally records skipped, partial, failed, and cancelled work instead of silently treating it as success. Those statuses are useful evidence: read them before retrying or expanding scope.
- A collector ID is the exact dotted identifier such as
core.system.system_info. - A profile selects a documented group of collectors;
--includeand--excluderefine it. - A capability is an access category a collector must declare before it can request that access.
- A run is one planned, isolated execution with a manifest and optional package.
- Paths in examples are Windows paths. Keep the managed interpreter path exactly as shown when using PowerShell.
The repository workflow publishes this directory to the GitHub repository wiki after documentation changes land on the default branch.