get_security_events
Retrieve critical Windows security events (process creation, logon, privilege use) from the last N hours. Specify max events count and lookback period.
Instructions
Security log convenience: IDs 4688, 4624, 4672, 4648 (requires elevation).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| max_events | No | ||
| hours_back | No |