So, just to ensure expectations are set - Carving in our terminology currently only refers to copying, we're not doing raw disk block copies yet, but it's on our feature map. @dallendoug with that in mind - osquery has an internal runnable that kicks off when it receives a distributed query (you can do this with scheduled queries if you really wanted tohug), that grabs the data, tar's all of the files you've specified, then POST's them back to an endpoint