# mcp-hayabusa

> mcp-hayabusa — sbecraft-mcp-hayabusa. Use this tool when you need to analyze Windows event logs for forensic purposes, as it enables EVTX scanning, Sigma rule exploration, and ATT&CK coverage analysis to aid in detection engineering and threat hunting. It takes Windows event log files as input and provides detailed analysis and insights as output. This tool is ideal for security professionals and incident responders investigating potential security threats on Windows systems.

Canonical page: https://skillsregistry.net/skills/sbecraft-mcp-hayabusa  
JSON: https://api.skillsregistry.net/v1/skills/sbecraft-mcp-hayabusa

## Description

Enables Windows event log forensics by wrapping Hayabusa, offering EVTX scanning, Sigma rule exploration, ATT&CK coverage analysis, and detection engineering resources.

## Trust

- **Trust score (0–1):** 0.70
- **Verification tier:** verified
- **Last scanned:** 2026-08-29

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-08-29

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/xs2h386e8p)
- **Repository:** <https://github.com/SBecraft/mcp-hayabusa>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "sbecraft-mcp-hayabusa"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/sbecraft-mcp-hayabusa` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/sbecraft-mcp-hayabusa/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
