Agent skill

Evtxecmd Maps

by EricZimmerman in EricZimmerman/evtx

Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.

MITAuto-check passedDocuments & Office

Install Evtxecmd Maps

skills CLI
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/evtxecmd-maps .claude/skills/evtxecmd-maps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
evtxecmd-maps
GitHub stars
376
Token cost
~2.9k tokens
SKILL.md length
1,290 words
Files
2 (incl. assets)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.

  • Works in 5 steps: What a map file is → Authoring workflow → Reference structure → …
  • Tasks that involve CSV and tabular files
  • SKILL.md covers 1. What a map file is, 2. Authoring workflow, 3. Reference structure and 4. Validating a map file, plus 1 more section
  • Calls pip; reaches learn.microsoft.com and schemas.microsoft.com

What it does

Evtxecmd Maps is an agent skill from EricZimmerman/evtx. Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets.

It sits in Documents & Office, covering CSV and tabular files. The repository describes itself as: C based evtx parser with lots of extras. The licence is MIT.

When your agent uses it

  • Tasks that involve CSV and tabular files

Example prompts

  • “/evtxecmd-maps”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. What a map file is
  2. Authoring workflow
  3. Reference structure
  4. Validating a map file
  5. Quick checklist for an agent creating a new map

What it can do on your machine

Read from SKILL.md and the folder at commit 03a7a1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com
    • schemas.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Evtxecmd Maps loads about 2.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,290 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EricZimmerman/evtx at commit 03a7a1f, republished under its MIT licence (© EricZimmerman). 1,290 words, ~2,903 tokens.

Download SKILL.mdSave it as .claude/skills/evtxecmd-maps/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
evtxecmd-maps
description
Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.

EvtxECmd Maps

This skill describes how an agent should understand, create, and validate EvtxECmd map files in this repository (the files under evtx/Maps/ ending in .map). Map files are YAML documents that tell EvtxECmd how to extract values from an event's EventData (and optionally System) elements and project them into a small set of standardized columns (UserName, RemoteHost, ExecutableInfo, PayloadData1 … PayloadData6).

A starter template is included alongside this skill at assets/!Channel-Name_Provider-Name_EventID.template. Always start a new map by copying that template rather than writing one from scratch.


1. What a map file is

A map is a YAML file whose filename and four header fields together identify a specific event:

Header fieldRequiredMeaning
AuthoroptionalName / contact of the map author.
DescriptionrequiredHuman description of the event. No trailing period.
EventIdrequiredThe integer Event ID (matches <EventID> in the XML).
ChannelrequiredThe exact value from the <Channel> element.
ProviderrequiredThe exact value of <Provider Name="…">. Mandatory since December 2020 to disambiguate event IDs that are reused by multiple providers.

Below the header is a Maps: sequence describing how to build each output column, and an optional Lookups: sequence defining value-translation tables.

The map is matched to an event when all of Channel, Provider, and EventId match the event's XML. The filename does not select the map, but it must follow the naming rules below so duplicates can be detected.

Filename rules

Format:

<Channel-Name>_<Provider-Name>_<EventID>.map
  • Underscores (_) separate the three elements.
  • Hyphens (-) replace any spaces, slashes, or special characters within Channel and Provider names.
  • The extension must be .map (lowercase is used throughout the repo).
  • Filenames may be long; that is expected.

Example — for Channel = Microsoft-Windows-TaskScheduler/Operational, Provider = Microsoft-Windows-TaskScheduler, EventID = 201:

Microsoft-Windows-TaskScheduler-Operational_Microsoft-Windows-TaskScheduler_201.map

To override an existing default map without losing your changes on update, prepend 1_ to the filename. Maps load alphabetically, so the 1_… copy wins:

1_Security_Microsoft-Windows-Security-Auditing_4624.map

2. Authoring workflow

  1. Get real XML for the event. Run EvtxECmd against a sample log to dump the records to XML:

    EvtxECmd.exe -f <your eventlog.evtx> --xml c:\temp\xml

    Open the resulting XML and locate the event of interest. Note the values of <Channel>, <Provider Name="…">, and <EventID>, and inspect the <EventData> block for the <Data Name="…"> fields you want to surface.

  2. Copy the template. Start from assets/!Channel-Name_Provider-Name_EventID.template (also located at evtx/Maps/!Channel-Name_Provider-Name_EventID.template). Save it under evtx/Maps/ using the filename rules above.

  3. Fill in the header. Set Author, Description, EventId, Channel, Provider. There must be no blank line between Provider: and Maps:.

  4. Define each Maps: entry. Each entry produces one output column:

    • Property: — must be exactly one of UserName, RemoteHost, ExecutableInfo, PayloadData1, PayloadData2, PayloadData3, PayloadData4, PayloadData5, PayloadData6. Use this exact casing (e.g. UserName, never Username).
    • PropertyValue: — the rendered string, with %name% placeholders for every variable referenced in Values.
    • Values: — list of { Name, Value } pairs. Name must match a %name% placeholder. Value is an XPath expression, normally "/Event/EventData/Data[@Name=\"<FieldName>\"]". You can also index by position: /Event/EventData/Data[1] (first <Data> node), [2], etc.
    • Refine: (optional, on a Values entry) — a regex applied to the XPath result to extract a substring. Example: Refine: "IPv4 address: [0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}".
    • Delete any Property blocks you don't need. Not every event has enough data to fill all six PayloadDataN columns.
    • When organizing PayloadData1…PayloadData6 for an event that's similar to existing maps (e.g. Sysmon), follow the column order used by those maps for analyst consistency.
  5. Quoting and escaping. XPath strings must be wrapped in double quotes, and embedded quotes inside the XPath escaped with \". PropertyValue strings that contain spaces, colons, or backslashes should be quoted, and a literal backslash is written as \\ (e.g. "%domain%\\%user%").

  6. Lookups (optional). Use a Lookups: block to translate raw values (often numeric codes) into human-readable strings. The lookup is applied when its Name matches the Name of a Values entry. To keep both raw and translated values in the same column, reference the field twice with different Names — only the one whose name equals a Lookups Name is translated:

    yaml
    Lookups:
      -
        Name: WakeSourceType
        Default: Unknown code
        Values:
            0: Unknown
            1: Power button
            3: Waking from sleep to hibernate

    If the map has multiple lookup tables, nest them all under a single Lookups: key (see Security_Microsoft-Windows-Security-Auditing_4769.map and …_4771.map for examples).

  7. Documentation footer. End the file with two commented blocks:

    • # Documentation: — one URL per line (Microsoft docs, blogs, research), each line commented with #. Use # N/A if there is none.
    • # Example Event Data: — a sanitized copy of a real <Event>…</Event> XML block, every line prefixed with #. Remove any sensitive data.
    • The file must end with a single trailing newline (the .yamllint rule new-line-at-end-of-file is enabled).
  8. Test against real data. Run EvtxECmd on the source log and confirm the target columns are populated as expected before submitting.


3. Reference structure

This is the canonical shape of a map. The full template is in assets/!Channel-Name_Provider-Name_EventID.template.

yaml
Author: Your name <you@example.com>
Description: Short description of the event
EventId: 4624
Channel: Security
Provider: Microsoft-Windows-Security-Auditing
Maps:
  -
    Property: UserName
    PropertyValue: "%domain%\\%user%"
    Values:
      -
        Name: domain
        Value: "/Event/EventData/Data[@Name=\"SubjectDomainName\"]"
      -
        Name: user
        Value: "/Event/EventData/Data[@Name=\"SubjectUserName\"]"
  -
    Property: PayloadData1
    PropertyValue: "LogonType %LogonType%"
    Values:
      -
        Name: LogonType
        Value: "/Event/EventData/Data[@Name=\"LogonType\"]"
Lookups:
  -
    Name: LogonType
    Default: Unknown
    Values:
        2: Interactive
        3: Network
        4: Batch
        5: Service

# Documentation:
# https://learn.microsoft.com/...
#
# Example Event Data:
#  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
#  ...
#  </Event>

Show full SKILL.md (522 more words)Show less

4. Validating a map file

Before committing a new or modified map, an agent must validate it. CI runs the same check via .github/workflows/verify.yml, which invokes yamllint evtx/Maps using the rules in the repository's .yamllint. The .yamllint yaml-files list explicitly includes *.map, so map files are linted as YAML.

4.1 Structural / lint validation

Run from the repository root:

bash
pip install yamllint
yamllint evtx/Maps

To target only the file you are editing:

bash
yamllint evtx/Maps/<your-file>.map

The repo's .yamllint enforces (failures, not warnings):

  • braces, brackets, colons, commas, hyphens, indentation — correct YAML punctuation and 2-space block indentation consistent with neighbors.
  • empty-lines — no stray blank lines (in particular, no blank line between Provider: and Maps:).
  • key-duplicates — every key in a mapping must be unique. In a map file, this means each Property: value (UserName, PayloadData1, …) may appear at most once in Maps:, and each Name: inside a single Values: list must be unique.
  • trailing-spaces — no spaces at end of line.
  • new-line-at-end-of-file — file must end with exactly one \n.

comments, comments-indentation, and truthy are configured as warnings and will not fail CI, but should still be addressed when easy.

If yamllint evtx/Maps exits 0, the structural check passes.

4.2 Semantic checks the linter cannot catch

After yamllint is clean, also confirm by inspection:

  • Filename matches headers. Filename is <Channel>_<Provider>_<EventId>.map with /, spaces, and special chars in Channel/Provider replaced by -. The Channel/Provider/EventId in the filename match the corresponding header fields exactly.
  • All required headers are present and non-placeholder: Description, EventId, Channel, Provider. Description has no trailing period.
  • Property values are from the allowed set with exact casing: UserName, RemoteHost, ExecutableInfo, PayloadData1–PayloadData6.
  • No duplicate Property entries within Maps:.
  • Every %name% placeholder in PropertyValue has a matching Name entry in that block's Values:, and vice versa (no orphan variables, no unresolved placeholders).
  • XPaths are quoted with "…" and embedded " escaped as \". Backslashes in PropertyValue strings are doubled (\\).
  • Lookups: is a single top-level key (all lookup tables are nested under it), each with Name, Default, and Values of integer/string pairs. A lookup Name matching a Values Name is what triggers translation.
  • Footer is present: a # Documentation: block (URLs or N/A) and a # Example Event Data: block containing a real, sanitized XML sample.
  • File ends with a trailing newline.
  • Test on real data: run EvtxECmd against a sample .evtx and confirm the produced CSV/JSON columns are populated correctly.

If any of the above fails, fix the map and re-run yamllint evtx/Maps until it is clean.


5. Quick checklist for an agent creating a new map

  1. Dump the source .evtx to XML and locate the target event.
  2. Copy assets/!Channel-Name_Provider-Name_EventID.template to evtx/Maps/<Channel>_<Provider>_<EventId>.map.
  3. Set Author, Description, EventId, Channel, Provider.
  4. Replace the template's Maps: blocks with Property entries that match the actual event; delete unused PayloadDataN blocks.
  5. Add Lookups: only if codes need translating; keep all tables under one Lookups: key.
  6. Replace the template footer with real # Documentation: URLs and a sanitized # Example Event Data: XML sample.
  7. Ensure the file ends with a single newline and contains no trailing whitespace and no blank line between Provider: and Maps:.
  8. Run yamllint evtx/Maps and fix any errors.
  9. Run the map against real data with EvtxECmd and confirm output columns.

© EricZimmerman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (assets) in .github/skills/evtxecmd-maps of EricZimmerman/evtx.

  • SKILL.md
  • assets/!Channel-Name_Provider-Name_EventID.template

Open the folder on GitHubat commit 03a7a1f

Compare with similar skills

Evtxecmd Maps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Evtxecmd Maps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Evtxecmd Maps this skillEricZimmerman/evtx376—~2.9kAutomated safety check: PassMIT
Data Table Managern8n-io/n8n207k—~2.3kAutomated safety check: PassCustom licence
Instrument Data To Allotropeaws-samples/amazon-bedrock-agents-healthcare-lifesciences2742 repos~2.7kAutomated safety check: PassApache-2.0
Abuse Hunternexu-io/harness-engineering-guide664—~1.9kAutomated safety check: PassMIT
Intelligence Requirements BuilderTracecatHQ/tracecat3.8k—~6kAutomated safety check: PassMIT
Markitshift-labs-ai/markit1.3k—~299Automated safety check: PassMIT

Similar skills

  • Official

    Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Instrument Data To Allotrope

    aws-samples/amazon-bedrock-agents-healthcare-lifesciences

    Official

    Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV.

    274 GitHub starsUsed in 2 repos~2.7k tokens
    Documents & OfficeAuto-check passed
  • Abuse Hunter

    nexu-io/harness-engineering-guide

    Detect and investigate bulk registration abuse on SaaS platforms.

    664 GitHub stars~1.9k tokensUpdated 5 mo ago
    Documents & OfficeAuto-check passed
  • Turns a vague, high-level stakeholder ask into a structured set of intelligence requirements for a CTI team, complete with Essential Elements of Information, collection guidance, success criteria…

    3.8k GitHub stars~6k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Markit

    shift-labs-ai/markit

    Convert files and URLs to Markdown. An agent skill from shift-labs-ai/markit.

    1.3k GitHub stars~299 tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Sector Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing sector rotation patterns and market cycle positioning.

    3k GitHub starsUsed in 1 repo~2.3k tokens
    Documents & OfficeAuto-check passed

Questions about Evtxecmd Maps

What does Evtxecmd Maps do?

Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns. Evtxecmd Maps is an agent skill from EricZimmerman/evtx. Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.

When should I use Evtxecmd Maps?

Evtxecmd Maps fits situations like: tasks that involve CSV and tabular files.

How do I install Evtxecmd Maps in Claude Code?

Run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a claude-code`. Or copy the skill folder (.github/skills/evtxecmd-maps in EricZimmerman/evtx) into .claude/skills/evtxecmd-maps in your project. Claude Code loads it when a task matches its description.

How do I install Evtxecmd Maps in Codex?

Run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a codex`. Or copy the skill folder (.github/skills/evtxecmd-maps in EricZimmerman/evtx) into .agents/skills/evtxecmd-maps in your project. Codex loads it when a task matches its description.

Can I use Evtxecmd Maps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/evtxecmd-maps, .gemini/skills/evtxecmd-maps, .github/skills/evtxecmd-maps and .opencode/skills/evtxecmd-maps in your project.

What does Evtxecmd Maps need to run?

Going by SKILL.md and its folder, Evtxecmd Maps needs the command-line tools its instructions call (pip). Our summary lists: Python 3.

Does Evtxecmd Maps access the network?

SKILL.md names 2 domains. In commands or code: learn.microsoft.com and schemas.microsoft.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Evtxecmd Maps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Evtxecmd Maps use?

Evtxecmd Maps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Evtxecmd Maps use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Evtxecmd Maps?

Skills that share tags, products or a category with Evtxecmd Maps: Data Table Manager (n8n-io/n8n, 207k stars), Instrument Data To Allotrope (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars), Abuse Hunter (nexu-io/harness-engineering-guide, 664 stars) and Intelligence Requirements Builder (TracecatHQ/tracecat, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Evtxecmd Maps?

EricZimmerman (a GitHub user) maintains it in EricZimmerman/evtx, which has 376 GitHub stars. The repository was last updated on June 17, 2026.

Source: EricZimmerman/evtx on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.