forensics_list_important_events
Identify critical Event IDs for Windows forensic analysis in Security, System, PowerShell, or Sysmon logs to detect security incidents and system anomalies.
Instructions
List important Event IDs for a log channel.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| channel | Yes |