evtxecmd
Installation
SKILL.md
EvtxECmd
Deterministic extraction of Windows event logs for objective-driven incident analysis.
When to use
- You need structured parsing of
.evtxlogs at scale. - You need precise ScriptBlock/process/account/security event timelines.
- You want reproducible CSV/JSON exports for timeline reconstruction.
- You need fast offline analysis without SIEM dependency.
Core workflow
- Identify high-value log channels relevant to the objective.
- Parse EVTX files into structured output.
- Pivot by event IDs, providers, host, user, and time window.
- Normalize timezone assumptions before cross-source correlation.
- Promote findings only when evidence pointers are explicit.