evtx_list_files
Lists all Windows Event Log (EVTX) files in a specified directory for forensic analysis. Use this tool to identify log files for investigation.
Instructions
List all EVTX (Windows Event Log) files in a directory.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| directory | Yes | Directory path to search | |
| recursive | No |