Data Table Manager
n8n-io/n8n
Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.
Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/evtxecmd-maps .claude/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .claude/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-mapsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/evtxecmd-maps .agents/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .agents/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/evtxecmd-maps .cursor/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .cursor/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/EricZimmerman/evtx.git --path .github/skills/evtxecmd-maps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/evtxecmd-maps .gemini/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .gemini/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install EricZimmerman/evtx evtxecmd-mapsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/evtxecmd-maps .github/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .github/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install EricZimmerman/evtx evtxecmd-maps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EricZimmerman/evtx.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/evtxecmd-maps .opencode/skills/evtxecmd-maps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "evtxecmd-maps" agent skill from https://github.com/EricZimmerman/evtx/tree/master/.github/skills/evtxecmd-maps into .opencode/skills/evtxecmd-maps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "evtxecmd-maps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
evtxecmd-mapsUnderstand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.
Evtxecmd Maps is an agent skill from EricZimmerman/evtx. Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets.
It sits in Documents & Office, covering CSV and tabular files. The repository describes itself as: C based evtx parser with lots of extras. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 03a7a1f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
learn.microsoft.comschemas.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Evtxecmd Maps loads about 2.9k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,290 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from EricZimmerman/evtx at commit 03a7a1f, republished under its MIT licence (© EricZimmerman). 1,290 words, ~2,903 tokens.
.claude/skills/evtxecmd-maps/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.This skill describes how an agent should understand, create, and validate
EvtxECmd map files in this repository (the files under evtx/Maps/ ending in
.map). Map files are YAML documents that tell EvtxECmd how to extract values
from an event's EventData (and optionally System) elements and project them
into a small set of standardized columns (UserName, RemoteHost,
ExecutableInfo, PayloadData1 … PayloadData6).
A starter template is included alongside this skill at
assets/!Channel-Name_Provider-Name_EventID.template. Always start a new
map by copying that template rather than writing one from scratch.
A map is a YAML file whose filename and four header fields together identify a specific event:
| Header field | Required | Meaning |
|---|---|---|
Author | optional | Name / contact of the map author. |
Description | required | Human description of the event. No trailing period. |
EventId | required | The integer Event ID (matches <EventID> in the XML). |
Channel | required | The exact value from the <Channel> element. |
Provider | required | The exact value of <Provider Name="…">. Mandatory since December 2020 to disambiguate event IDs that are reused by multiple providers. |
Below the header is a Maps: sequence describing how to build each output
column, and an optional Lookups: sequence defining value-translation tables.
The map is matched to an event when all of Channel, Provider, and
EventId match the event's XML. The filename does not select the map, but it
must follow the naming rules below so duplicates can be detected.
Format:
<Channel-Name>_<Provider-Name>_<EventID>.map_) separate the three elements.-) replace any spaces, slashes, or special characters within
Channel and Provider names..map (lowercase is used throughout the repo).Example — for Channel = Microsoft-Windows-TaskScheduler/Operational,
Provider = Microsoft-Windows-TaskScheduler, EventID = 201:
Microsoft-Windows-TaskScheduler-Operational_Microsoft-Windows-TaskScheduler_201.mapTo override an existing default map without losing your changes on update,
prepend 1_ to the filename. Maps load alphabetically, so the 1_… copy wins:
1_Security_Microsoft-Windows-Security-Auditing_4624.mapGet real XML for the event. Run EvtxECmd against a sample log to dump the records to XML:
EvtxECmd.exe -f <your eventlog.evtx> --xml c:\temp\xmlOpen the resulting XML and locate the event of interest. Note the values of
<Channel>, <Provider Name="…">, and <EventID>, and inspect the
<EventData> block for the <Data Name="…"> fields you want to surface.
Copy the template. Start from
assets/!Channel-Name_Provider-Name_EventID.template (also located at
evtx/Maps/!Channel-Name_Provider-Name_EventID.template). Save it under
evtx/Maps/ using the filename rules above.
Fill in the header. Set Author, Description, EventId, Channel,
Provider. There must be no blank line between Provider: and Maps:.
Define each Maps: entry. Each entry produces one output column:
Property: — must be exactly one of
UserName, RemoteHost, ExecutableInfo,
PayloadData1, PayloadData2, PayloadData3,
PayloadData4, PayloadData5, PayloadData6.
Use this exact casing (e.g. UserName, never Username).PropertyValue: — the rendered string, with %name% placeholders for
every variable referenced in Values.Values: — list of { Name, Value } pairs. Name must match a
%name% placeholder. Value is an XPath expression, normally
"/Event/EventData/Data[@Name=\"<FieldName>\"]". You can also index by
position: /Event/EventData/Data[1] (first <Data> node), [2], etc.Refine: (optional, on a Values entry) — a regex applied to the XPath
result to extract a substring. Example:
Refine: "IPv4 address: [0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}".Property blocks you don't need. Not every event has
enough data to fill all six PayloadDataN columns.PayloadData1…PayloadData6 for an event that's similar
to existing maps (e.g. Sysmon), follow the column order used by those
maps for analyst consistency.Quoting and escaping. XPath strings must be wrapped in double quotes,
and embedded quotes inside the XPath escaped with \". PropertyValue
strings that contain spaces, colons, or backslashes should be quoted, and a
literal backslash is written as \\ (e.g. "%domain%\\%user%").
Lookups (optional). Use a Lookups: block to translate raw values
(often numeric codes) into human-readable strings. The lookup is applied
when its Name matches the Name of a Values entry. To keep both raw
and translated values in the same column, reference the field twice with
different Names — only the one whose name equals a Lookups Name is
translated:
Lookups:
-
Name: WakeSourceType
Default: Unknown code
Values:
0: Unknown
1: Power button
3: Waking from sleep to hibernateIf the map has multiple lookup tables, nest them all under a single
Lookups: key (see Security_Microsoft-Windows-Security-Auditing_4769.map
and …_4771.map for examples).
Documentation footer. End the file with two commented blocks:
# Documentation: — one URL per line (Microsoft docs, blogs, research),
each line commented with #. Use # N/A if there is none.# Example Event Data: — a sanitized copy of a real <Event>…</Event>
XML block, every line prefixed with #. Remove any sensitive data..yamllint rule
new-line-at-end-of-file is enabled).Test against real data. Run EvtxECmd on the source log and confirm the target columns are populated as expected before submitting.
This is the canonical shape of a map. The full template is in
assets/!Channel-Name_Provider-Name_EventID.template.
Author: Your name <you@example.com>
Description: Short description of the event
EventId: 4624
Channel: Security
Provider: Microsoft-Windows-Security-Auditing
Maps:
-
Property: UserName
PropertyValue: "%domain%\\%user%"
Values:
-
Name: domain
Value: "/Event/EventData/Data[@Name=\"SubjectDomainName\"]"
-
Name: user
Value: "/Event/EventData/Data[@Name=\"SubjectUserName\"]"
-
Property: PayloadData1
PropertyValue: "LogonType %LogonType%"
Values:
-
Name: LogonType
Value: "/Event/EventData/Data[@Name=\"LogonType\"]"
Lookups:
-
Name: LogonType
Default: Unknown
Values:
2: Interactive
3: Network
4: Batch
5: Service
# Documentation:
# https://learn.microsoft.com/...
#
# Example Event Data:
# <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
# ...
# </Event>Before committing a new or modified map, an agent must validate it. CI
runs the same check via .github/workflows/verify.yml, which invokes
yamllint evtx/Maps using the rules in the repository's .yamllint. The
.yamllint yaml-files list explicitly includes *.map, so map files are
linted as YAML.
Run from the repository root:
pip install yamllint
yamllint evtx/MapsTo target only the file you are editing:
yamllint evtx/Maps/<your-file>.mapThe repo's .yamllint enforces (failures, not warnings):
braces, brackets, colons, commas, hyphens, indentation — correct
YAML punctuation and 2-space block indentation consistent with neighbors.empty-lines — no stray blank lines (in particular, no blank line between
Provider: and Maps:).key-duplicates — every key in a mapping must be unique. In a map file,
this means each Property: value (UserName, PayloadData1, …) may appear
at most once in Maps:, and each Name: inside a single Values: list
must be unique.trailing-spaces — no spaces at end of line.new-line-at-end-of-file — file must end with exactly one \n.comments, comments-indentation, and truthy are configured as warnings
and will not fail CI, but should still be addressed when easy.
If yamllint evtx/Maps exits 0, the structural check passes.
After yamllint is clean, also confirm by inspection:
<Channel>_<Provider>_<EventId>.map with /, spaces, and special chars in
Channel/Provider replaced by -. The Channel/Provider/EventId in the
filename match the corresponding header fields exactly.Description,
EventId, Channel, Provider. Description has no trailing period.Property values are from the allowed set with exact casing:
UserName, RemoteHost, ExecutableInfo, PayloadData1–PayloadData6.Property entries within Maps:.%name% placeholder in PropertyValue has a matching Name
entry in that block's Values:, and vice versa (no orphan variables, no
unresolved placeholders)."…" and embedded " escaped as \".
Backslashes in PropertyValue strings are doubled (\\).Lookups: is a single top-level key (all lookup tables are nested
under it), each with Name, Default, and Values of integer/string
pairs. A lookup Name matching a Values Name is what triggers
translation.# Documentation: block (URLs or N/A) and a
# Example Event Data: block containing a real, sanitized XML sample..evtx and confirm
the produced CSV/JSON columns are populated correctly.If any of the above fails, fix the map and re-run yamllint evtx/Maps
until it is clean.
.evtx to XML and locate the target event.assets/!Channel-Name_Provider-Name_EventID.template to
evtx/Maps/<Channel>_<Provider>_<EventId>.map.Author, Description, EventId, Channel, Provider.Maps: blocks with Property entries that match
the actual event; delete unused PayloadDataN blocks.Lookups: only if codes need translating; keep all tables under one
Lookups: key.# Documentation: URLs and a
sanitized # Example Event Data: XML sample.Provider: and Maps:.yamllint evtx/Maps and fix any errors.© EricZimmerman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (assets) in .github/skills/evtxecmd-maps of EricZimmerman/evtx.
Open the folder on GitHubat commit 03a7a1f
Evtxecmd Maps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Evtxecmd Maps this skillEricZimmerman/evtx | 376 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Data Table Managern8n-io/n8n | 207k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Instrument Data To Allotropeaws-samples/amazon-bedrock-agents-healthcare-lifesciences | 274 | 2 repos | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Abuse Hunternexu-io/harness-engineering-guide | 664 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Intelligence Requirements BuilderTracecatHQ/tracecat | 3.8k | — | ~6k | Automated safety check: Pass | MIT | |
| Markitshift-labs-ai/markit | 1.3k | — | ~299 | Automated safety check: Pass | MIT |
n8n-io/n8n
Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.
aws-samples/amazon-bedrock-agents-healthcare-lifesciences
Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV.
nexu-io/harness-engineering-guide
Detect and investigate bulk registration abuse on SaaS platforms.
TracecatHQ/tracecat
Turns a vague, high-level stakeholder ask into a structured set of intelligence requirements for a CTI team, complete with Essential Elements of Information, collection guidance, success criteria…
shift-labs-ai/markit
Convert files and URLs to Markdown. An agent skill from shift-labs-ai/markit.
tradermonty/claude-trading-skills
This skill should be used when analyzing sector rotation patterns and market cycle positioning.
Categories
Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns. Evtxecmd Maps is an agent skill from EricZimmerman/evtx. Understand, author, and validate EvtxECmd map files that normalize Windows event log EventData into first-class CSV/JSON columns.
Evtxecmd Maps fits situations like: tasks that involve CSV and tabular files.
Run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a claude-code`. Or copy the skill folder (.github/skills/evtxecmd-maps in EricZimmerman/evtx) into .claude/skills/evtxecmd-maps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a codex`. Or copy the skill folder (.github/skills/evtxecmd-maps in EricZimmerman/evtx) into .agents/skills/evtxecmd-maps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EricZimmerman/evtx --skill evtxecmd-maps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/evtxecmd-maps, .gemini/skills/evtxecmd-maps, .github/skills/evtxecmd-maps and .opencode/skills/evtxecmd-maps in your project.
Going by SKILL.md and its folder, Evtxecmd Maps needs the command-line tools its instructions call (pip). Our summary lists: Python 3.
SKILL.md names 2 domains. In commands or code: learn.microsoft.com and schemas.microsoft.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Evtxecmd Maps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Evtxecmd Maps: Data Table Manager (n8n-io/n8n, 207k stars), Instrument Data To Allotrope (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars), Abuse Hunter (nexu-io/harness-engineering-guide, 664 stars) and Intelligence Requirements Builder (TracecatHQ/tracecat, 3.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
EricZimmerman (a GitHub user) maintains it in EricZimmerman/evtx, which has 376 GitHub stars. The repository was last updated on June 17, 2026.
Source: EricZimmerman/evtx on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.