evtx_security_search
Search Windows Event Logs (EVTX) for specific security events like logon attempts, process creation, or account changes to support forensic investigations.
Instructions
Search for security events by type: logon, failed_logon, process_creation, etc.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| evtx_path | Yes | ||
| event_type | Yes | ||
| limit | No |