Configuring Windows Event Logging For Detection
mukul975/Anthropic-Cybersecurity-Skills
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.
Find Japan events on Walkerplus for a trip window, inspect a known Walkerplus event, or require source-backed free admission or indoor venues.
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mvanhorn/printing-press-library pp-walkerplus --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-skills/pp-walkerplus .claude/skills/pp-walkerplus && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .claude/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplusType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mvanhorn/printing-press-library pp-walkerplus --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .agents/skills && cp -r skills-src/cli-skills/pp-walkerplus .agents/skills/pp-walkerplus && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .agents/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mvanhorn/printing-press-library pp-walkerplus --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/cli-skills/pp-walkerplus .cursor/skills/pp-walkerplus && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .cursor/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mvanhorn/printing-press-library.git --path cli-skills/pp-walkerplus--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mvanhorn/printing-press-library pp-walkerplus --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/cli-skills/pp-walkerplus .gemini/skills/pp-walkerplus && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .gemini/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mvanhorn/printing-press-library pp-walkerplusInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .github/skills && cp -r skills-src/cli-skills/pp-walkerplus .github/skills/pp-walkerplus && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .github/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mvanhorn/printing-press-library pp-walkerplus --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/cli-skills/pp-walkerplus .opencode/skills/pp-walkerplus && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pp-walkerplus" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-walkerplus into .opencode/skills/pp-walkerplus/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-walkerplus", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pp-walkerplusFind Japan events on Walkerplus for a trip window, inspect a known Walkerplus event, or require source-backed free admission or indoor venues.
Pp Walkerplus is an agent skill from mvanhorn/printing-press-library. Find Japan events on Walkerplus for a trip window, inspect a known Walkerplus event, or require source-backed free admission or indoor venues. Use when asked to use Walkerplus or run walkerplus-pp-cli.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Official library of CLIs generated by the CLI Printing Press. Endorsed, tested, and community-contributed. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7638ad4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gonpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pp Walkerplus loads about 2.1k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 842 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mvanhorn/printing-press-library at commit 7638ad4, republished under its Apache-2.0 licence (© mvanhorn). 842 words, ~2,141 tokens.
.claude/skills/pp-walkerplus/SKILL.md (or your agent's skills folder).<!-- GENERATED FILE — DO NOT EDIT.
This file is a verbatim mirror of library/travel/walkerplus/SKILL.md,
regenerated post-merge by tools/generate-skills/. Hand-edits here are
silently overwritten on the next regen. Edit the library/ source instead.
See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->
For a source checkout, use a locally built walkerplus-pp-cli binary with Go 1.26.6 or newer. Catalog installation requires a merged library release. Verify walkerplus-pp-cli --version; if missing, build with go build -o walkerplus-pp-cli ./cmd/walkerplus-pp-cli and make the binary available on PATH. Public Walkerplus HTML is the only runtime source. No credentials, browser, booking, or translation provider is involved. MCP is compiled for stdio only; no HTTP listener is included. When using MCP, inspect truncation metadata and narrow --limit or --select after a bounded result or capture-limit error. CLI JSON error codes remain available; auxiliary diagnostics are separate.
Resolve the travel location and event category through the catalogs. Accepted codes and source slugs map to Japanese source labels. City codes, source slugs and Japanese city names from areas are accepted with the matching prefecture; for example, --prefecture tokyo --city ar0313104 or --city shinjuku.
walkerplus-pp-cli areas --prefecture kyoto
walkerplus-pp-cli categoriesDiscover bounded candidates cheaply. Search reads listings only. Use exact trip dates and inspect coverage before describing completeness.
walkerplus-pp-cli search --prefecture kyoto --category festival --from 2026-10-01 --to 2026-10-31 --limit 5 --max-pages 3Enrich a bounded shortlist when the traveler needs attendance confidence or strict constraints. Keep possible matches separate from confirmed days.
walkerplus-pp-cli shortlist --prefecture kyoto --from 2026-10-10 --to 2026-10-12 --max-details 10 --agent --select id,title_ja,start_date,end_date,location,match,schedule,sources
walkerplus-pp-cli shortlist --prefecture osaka --from 2026-10-11 --to 2026-10-11 --indoor --max-details 10--free requires explicit event admission evidence; --indoor requires unconditional indoor evidence. Both flags mean AND. Optional paid purchases do not make explicitly free admission paid; preserve those caveats. Unknown and conditional source attributes are excluded by strict constraints.
Read the event edition before recommending attendance. Carry schedule exceptions, weather, cancellation, admission and reservation facts into the answer with its source URL.
walkerplus-pp-cli event ar0313e603640 --select id,title_ja,source_url,schedule,hours,admission,reservation_required,reservation_text,weather,cancellation,organizer_urls,sourcesCompletion means every recommendation cites the edition, relevant source dates, match confidence, practical caveats, and coverage limits. If published evidence does not resolve attendance, describe it as possible and direct the traveler to the organizer.
Japanese titles are authoritative. Raw schedule, admission and reservation text, evidence, and source URLs are source facts. Normalized edition_year/date_certainty, parsed recurrence/exclusion lists, admission status, boolean classifications, and match/rank fields are derived conveniences. An overall date envelope is not proof of daily activity. Closure-only rules narrow possible days; explicit occurrences, daily activity or positive recurrence can confirm activity. Approximate seasons, unresolved holiday exceptions, and undisclosed next-year editions never become confirmed dates. --timing starts|ends checks published envelope boundaries.
JSON is compact by default; --agent and --json are compatible. --select/--fields project event fields while retaining query, coverage and provenance. Use schema to discover fields. Unknown scalars are null, collections are empty arrays, diagnostics are stderr.
Default caps are 10 returned events, 3 listing pages, and 10 detail candidates. Shortlist returns only detail-inspected candidates; reaching --max-details can leave fewer results than --limit. Detail selection checks listing-supported location/category matches before candidates with missing facts, using --sort within each group; returned results use --sort. Widen --max-pages and --max-details deliberately within hard limits; an empty bounded scan does not establish absence. Coverage gives sampled routes, counts, continuation, cache hits and incomplete reasons. Resolving an additional city performs at most one prefecture catalog lookup outside the --max-pages event-page budget; catalog_requests/catalog_routes record it, and request_count includes it. Native month/day routes have no year selector; exact local filtering cannot manufacture a future edition.
Use --refresh when a source recheck is needed. sources provide fetch time and cache age; publisher update text is separate. Every custom command accepts --dry-run for offline validation.
walkerplus-pp-cli doctor --dry-run --json
walkerplus-pp-cli event --dry-run --agentUsage errors exit 2, missing event 3, fetch/parser failure 5, exhausted rate limiting 7. Source failure emits JSON error rather than empty success. Read README.md for build, cache, troubleshooting and live verification details.
Use the installer section below when Walkerplus is available in the Printing Press catalog. For a source checkout or when catalog installation is unavailable, build and verify locally using the instructions above.
This skill drives the walkerplus-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:
$HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows:npx -y @mvanhorn/printing-press-library install walkerplus --cli-onlywalkerplus-pp-cli --version$PATH for the agent/runtime that will invoke this skill.If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer). This installs into $GOPATH/bin (default $HOME/go/bin), so add that directory to $PATH instead:
go install github.com/mvanhorn/printing-press-library/library/travel/walkerplus/cmd/walkerplus-pp-cli@latestIf --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds.
Build a bounded shortlist from Walkerplus while preserving Japanese event titles and uncertainty. Inspect details before committing travel time.
These capabilities aren't available in any other tool for this API.
shortlist — Find exact-edition trip candidates with schedule confidence, constraints and explainable ranking.
Use for a bounded event shortlist tailored to trip dates and practical constraints.
walkerplus-pp-cli shortlist --prefecture kyoto --from 2026-10-10 --to 2026-10-12 --max-pages 1 --max-details 3 --limit 3walkerplus-pp-cli shortlist --prefecture kyoto --from 2026-10-10 --to 2026-10-12 --limit 5Enrich bounded candidates and explain schedule confidence.
walkerplus-pp-cli search --prefecture tokyo --from 2026-10-01 --to 2026-10-07 --agent --select id,title_ja,source_urlKeep event output small while retaining coverage metadata.
walkerplus-pp-cli event ar0313e603640Read source schedule, access, pricing and reservation facts.
Public Walkerplus HTML; no API key or login required.
Run walkerplus-pp-cli doctor to verify setup.
© mvanhorn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in cli-skills/pp-walkerplus of mvanhorn/printing-press-library.
Open the folder on GitHubat commit 7638ad4
Pp Walkerplus next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pp Walkerplus this skillmvanhorn/printing-press-library | 2.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Windows Event Logging For Detectionmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Extracting Windows Event Logs Artifactsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Windows Event Logs In Splunkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Windows Desktop E2Eaffaan-m/ECC | 274k | 1 repos | ~7.6k | Automated safety check: Pass | MIT | |
| Windows Desktop E2Eaffaan-m/ECC | 274k | — | ~5.5k | Automated safety check: Pass | MIT |
mukul975/Anthropic-Cybersecurity-Skills
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.
mukul975/Anthropic-Cybersecurity-Skills
Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
mukul975/Anthropic-Cybersecurity-Skills
Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to…
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
wshobson/agents
Designs event stores for event-sourced systems: requirements, a comparison of EventStoreDB, PostgreSQL, Kafka, DynamoDB and Marten, and stream and versioning practices.
mvanhorn/printing-press-library
Desktop automation through the real Rust agent-desktop CLI, published in Printing Press through a small bridge.
mvanhorn/printing-press-library
Search, browse, and download Google Fonts from the terminal via the gfonts CLI.
mvanhorn/printing-press-library
The free, offline Trigger phrases: search 1688 for, find a factory on 1688 for, wholesale price on 1688 for, who is the cheapest supplier on 1688 for, compare 1688 suppliers for, use 1688, run 1688.
mvanhorn/printing-press-library
Inspect known Activity Japan plan IDs or URLs, compare dated prices and sessions, check language-sitemap coverage, and hand off to canonical booking pages.
mvanhorn/printing-press-library
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc...
mvanhorn/printing-press-library
macOS screen capture, window recording, GIF conversion, and agent evidence bundles from the terminal.
Find Japan events on Walkerplus for a trip window, inspect a known Walkerplus event, or require source-backed free admission or indoor venues. Pp Walkerplus is an agent skill from mvanhorn/printing-press-library. Find Japan events on Walkerplus for a trip window, inspect a known Walkerplus event, or require source-backed free admission or indoor venues.
Pp Walkerplus fits situations like: asked to use Walkerplus; run walkerplus-pp-cli.
Run `npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a claude-code`. Or copy the skill folder (cli-skills/pp-walkerplus in mvanhorn/printing-press-library) into .claude/skills/pp-walkerplus in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a codex`. Or copy the skill folder (cli-skills/pp-walkerplus in mvanhorn/printing-press-library) into .agents/skills/pp-walkerplus in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvanhorn/printing-press-library --skill pp-walkerplus -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pp-walkerplus, .gemini/skills/pp-walkerplus, .github/skills/pp-walkerplus and .opencode/skills/pp-walkerplus in your project.
Going by SKILL.md and its folder, Pp Walkerplus needs the command-line tools its instructions call (go and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pp Walkerplus is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pp Walkerplus: Configuring Windows Event Logging For Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Extracting Windows Event Logs Artifacts (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Windows Event Logs In Splunk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Windows Desktop E2E (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mvanhorn (a GitHub user) maintains it in mvanhorn/printing-press-library, which has 2,053 GitHub stars. The repository holds 505 skills in this directory. The repository was last updated on October 6, 2026.
Source: mvanhorn/printing-press-library on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.