#
ENJA

EventWhisper

Hexastrike/EventWhisper

EventWhisper is a Model Context Protocol (MCP) server written in pure Python that enables fast, scriptable querying of Windows .evtx log files without relying on PowerShell command execution.

49 7GPL-3.0Updated 2025-08-25

Overview

Designed specifically for incident response, digital forensics, and threat hunting, EventWhisper provides direct reading and parsing of Windows Event Log files. It exposes dedicated tools to list log directories recursively and filter events by time window, specific Event IDs, and case-insensitive keywords, returning targeted fields to minimize token consumption in AI clients.

Capabilities

  • List EVTX files recursively or in flat directories
  • Filter events by time windows (start/end)
  • Filter events by specific Event IDs
  • Perform case-insensitive include and exclude keyword searches
  • Project specific dotted fields to reduce output size
  • Model Context Protocol (MCP) server integration

Best for

Performing digital forensics and incident response (DFIR) directly through AI assistants, Threat hunting in Windows event logs using natural language queries, Inspecting and filtering security, system, and application log files without manual Event ID lookups

Works with

Claude CodeCursorChatGPT
Evoa Score breakdown= Σ (score × weight)
73
Task usefulness20%100 → +20.0

実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 AIによるcapabilities/use-cases解析

Code quality15%90 → +13.5

実装・指示の品質。 AIによるSKILL.md/README解析

Maintenance15%50 → +7.5

リポジトリがどれだけ活発に保守されているか。 GitHub 最終push日時の新しさ

Documentation12%32 → +3.8

ドキュメントの充実度・分かりやすさ。 README/独自要約の情報量

Security15%80 → +12.0

危険・不審な挙動が無いか。 AIによるセキュリティレビュー

Originality10%85 → +8.5

ありふれたラッパーではない独自性。 AIによる独自性判定

Popularity8%45 → +3.6

コミュニティの採用度。 GitHub Stars/Forks(対数スケール)

Compatibility5%75 → +3.8

対応AIエージェントの広さ。 AIによる対応エージェント判定

Weighted total72.7 / 100

ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →

Security considerations

The tool reads local .evtx files via a pure Python library without executing arbitrary shell commands, minimizing the remote code execution risk associated with typical PowerShell wrappers. However, giving an LLM read access to system security logs should be done with appropriate permission boundaries.

Categories

Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.