01List EVTX files (optionally recursive) for any directory
02Filter events by time window, EventID(s), and case-insensitive keywords (include/exclude)
03Project specific fields to return only necessary data
04Accepts flexible input formats for robust operation
05MCP-ready for seamless integration with Claude Desktop and other clients
0617 GitHub stars