01Built-in knowledge base of important Windows Event IDs and registry keys
02Seamless integration with MCP-compatible AI clients for interactive analysis
034 GitHub stars
04EVTX Parsing with filtering, search, and pre-built security queries
05Registry Analysis for SAM, SYSTEM, SOFTWARE, SECURITY, and NTUSER.DAT hives
06Remote artifact collection via WinRM with password or pass-the-hash authentication