evtxecmd

Installation
SKILL.md

EvtxECmd

Deterministic extraction of Windows event logs for objective-driven incident analysis.

When to use

  • You need structured parsing of .evtx logs at scale.
  • You need precise ScriptBlock/process/account/security event timelines.
  • You want reproducible CSV/JSON exports for timeline reconstruction.
  • You need fast offline analysis without SIEM dependency.

Core workflow

  1. Identify high-value log channels relevant to the objective.
  2. Parse EVTX files into structured output.
  3. Pivot by event IDs, providers, host, user, and time window.
  4. Normalize timezone assumptions before cross-source correlation.
  5. Promote findings only when evidence pointers are explicit.
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
evtxecmd — aeondave/malskill