# evtxsift

> evtxsift — cognis-digital-evtxsift. Use this tool when you need to analyze Windows event logs for signs of malicious activity, such as brute-force attacks, persistence, and lateral movement. It takes exported Windows event logs as input and outputs signals indicating potential security threats. Ideal for security professionals and incident responders investigating suspicious activity on Windows systems.

Canonical page: https://skillsregistry.net/skills/cognis-digital-evtxsift  
JSON: https://api.skillsregistry.net/v1/skills/cognis-digital-evtxsift

## Description

Find brute-force, persistence & lateral-movement signals in exported Windows event logs

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/cognis-digital/evtxsift)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cognis-digital-evtxsift"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-evtxsift` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-evtxsift/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
