# EventWhisper

> Use this tool when you need to quickly analyze Windows event logs for incident response and digital forensics, filtering by time, Event IDs, and keywords to identify specific events. It enables scriptable access to .evtx logs, reducing output size through field projection. Ideal for use cases requiring fast and targeted log analysis, such as security investigations and troubleshooting.

Canonical page: https://skillsregistry.net/skills/hexastrike-eventwhisper  
JSON: https://api.skillsregistry.net/v1/skills/hexastrike-eventwhisper

## Description

Enables fast, scriptable access to Windows .evtx event logs for incident response and digital forensics. Supports filtering events by time windows, Event IDs, and keywords with field projection to reduce output size.

## Trust

- **Trust score (0–1):** 0.97
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-09-19

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/f4khdc4lre)
- **Repository:** <https://github.com/Hexastrike/EventWhisper>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "hexastrike-eventwhisper"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/hexastrike-eventwhisper` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/hexastrike-eventwhisper/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
