# Windows Forensics

> Use this tool when you need to analyze Windows system artifacts for incident response and forensic investigations. It solves problems related to parsing event logs, analyzing registry hives, and collecting forensic evidence from Windows systems. The tool takes in Windows artifacts such as EVTX logs and registry hives as input and provides parsed logs, identified persistence mechanisms, and correlated forensic evidence as output.

Canonical page: https://skillsregistry.net/skills/x746b-winforensics  
JSON: https://api.skillsregistry.net/v1/skills/x746b-winforensics

## Description

A Windows digital forensics server that enables analysis of Windows artifacts including EVTX event logs and registry hives. Provides tools for parsing Security, System, and Sysmon logs with pre-built security event searches, analyzing SAM/SYSTEM/SOFTWARE registry hives for persistence mechanisms and user accounts, and remotely collecting artifacts via WinRM with password or pass-the-hash authentication. Designed for incident response workflows where analysts need to quickly extract and correlate forensic evidence from Windows systems.

## Trust

- **Trust score (0–1):** 0.24
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-01

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/x746b-winforensics)
- **Repository:** <https://github.com/x746b/winforensics-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "x746b-winforensics"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/x746b-winforensics` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/x746b-winforensics/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
