Analyze Windows EVTX logs and retrieve detection rules through Hayabusa tools.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "hayabusa-mcp" yet — see the docs or source repo.
Use hayabusa-mcp to scan this Windows EVTX log directory and summarize suspicious events, timeline, and high-risk alerts.
A summary of suspicious events, key timestamps, and notable alerts based on Hayabusa scan results.
Use hayabusa-mcp to retrieve available detection rules and organize those related to logon, privilege escalation, and execution.
A list or categorized view of rules that helps the user understand available detections for EVTX analysis.
Using hayabusa-mcp scan results, identify the most important anomalous activities to investigate first in these Windows event logs.
A prioritized list of anomalies with short reasons for further security investigation.
DevOps or security staff can use it to scan EVTX logs and quickly find suspicious events when investigating host anomalies. It helps narrow down the scope of manual analysis.
Developers or researchers can retrieve Hayabusa-related rules to understand what detections are used in log analysis. This helps assess rule coverage and intended use.
It is an MCP tool that wraps Hayabusa to support Windows Event Log (EVTX) analysis and provides scan and rule retrieval capabilities.
Based on the description, it is intended for Windows Event Log (EVTX) analysis. For any additional input formats, see the source repository.
Its scope is more specific: it focuses on analyzing Windows EVTX through Hayabusa and exposing scan and rule retrieval tools. It is not described as a general-purpose log platform.
Scan Windows EVTX logs and inspect Hayabusa detection rules in chat.
Analyze Windows event logs and EVTX files for forensics and threat hunting.
Analyze packet captures in natural language for protocols, flows, and threats.
Analyze network traffic with natural language for packet stats and anomaly detection.
Use Wireshark/TShark through MCP for packet analysis and network troubleshooting.
Analyze log files with natural language to find errors and anomalies fast.