Enables fast, scriptable access to Windows .evtx event logs for incident response and digital forensics. Supports filtering events by time windows, Event IDs, and keywords with field projection to reduce output size.
Enables AI-assisted Windows digital forensics analysis including parsing Windows Event Logs (EVTX), analyzing registry hives (SAM, SYSTEM, SOFTWARE), and remotely collecting artifacts via WinRM with built-in security queries and forensic reference data.
Enables ingestion and full-text search of Windows application logs via MCP tools. Supports dual-backend indexing with Elasticsearch and SQLite for fast retrieval.
Enables context-aware EVTX hunting with process lineage tracing and rarity baselining to surface real threats from security logs, transforming raw alerts into actionable kill chain intelligence.
Enables forensic analysis of Windows event logs (.evtx) using Hayabusa, providing tools for timeline generation, threat hunting, and rule updates via MCP.