Evtxsift
Verified IntegrationClient Configuration
— Connect Evtxsift to Claude Desktop or Cursor in seconds{
"mcpServers": {
"evtxsift": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-evtxsift"
],
"env": {}
}
}
}~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).System Overview
Identifies brute-force, persistence, and lateral-movement signals within exported Windows event logs.
7/23/2026
Open Source
stdio / SSE RPC
Frequently Asked Questions
Architecture and operational details for Evtxsift
Yes, Evtxsift is built for simplicity. You can install it via pip, Docker, Homebrew, or direct script, and it operates with a single command and zero configuration. Just point it at your event logs, and get prioritized findings in seconds.
Related MCP Servers
Browse all servers →Empower AI assistants to generate and convert documents, manage templates, and automate document workflows efficiently.
Provides a multi-tenant, AI-native Content Delivery Network deployable on Cloudflare, featuring sub-100ms TTFB, AI agent controllability, and comprehensive accessibility.
Deploy a Model Context Protocol server on Cloudflare Workers without requiring authentication.