Agent skill

Windows Log Hunter

by ptn1411 in ptn1411/skill

Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill.

No licenceAuto-check: notesSecurity

Install Windows Log Hunter

skills CLI
$ npx skills add ptn1411/skill --skill windows-log-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ptn1411/skill windows-log-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ptn1411/skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/windows-log-hunter .claude/skills/windows-log-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windows-log-hunter
GitHub stars
220
Token cost
~1k tokens
SKILL.md length
388 words
Files
5 (incl. scripts, references)
Skills in repo
22
Repo updated
First seen
Licence
None found

At a glance

Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill.

  • Works in 5 steps: Authorization & Routing → Check environment → Native hunt (no external tools) → …
  • Tasks that involve Security operations
  • SKILL.md covers 0. Authorization & Routing, Engines, Step 0 — Check environment and Step 1 — Native hunt (no…, plus 3 more sections
  • Runs Python and PowerShell scripts from its folder; calls python

What it does

Windows Log Hunter is an agent skill from ptn1411/skill. Blue-team CLI threat hunt over Windows Event Logs. Sweeps high-signal security events (failed logons, new accounts/services, cleared logs, PowerShell, Sysmon) via native PowerShell or Hayabusa/Sigma, and produces a triaged findings report.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/detections.md`, `scripts/hunt_eventlog.py` and `scripts/parse_findings.py`).

It sits in Security, covering Security operations. It works with PowerShell. The repository describes itself as: Bộ công cụ và tập hợp skill hỗ trợ phân tích phần mềm, khôi phục cấu trúc nguồn ở mức cần thiết, rà soát bảo mật, kiểm tra phụ thuộc và xây dựng kế hoạch khắc phục cho các hệ…

When your agent uses it

  • Tasks that involve Security operations

Example prompts

  • “/windows-log-hunter”

Requirements

  • Python 3
  • PowerShell
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, Bash

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Authorization & Routing
  2. Check environment
  3. Native hunt (no external tools)
  4. Hayabusa timeline (optional, deeper)
  5. Read the report

What it can do on your machine

Read from SKILL.md and the folder at commit ce2b65e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python and PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windows Log Hunter loads about 1k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 388 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 388 words (~1,029 tokens).

name
windows-log-hunter
allowed-tools
Read, Write, Edit, Glob, Grep, Bash

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts, references) in windows-log-hunter of ptn1411/skill.

  • SKILL.md
  • references/detections.md
  • scripts/hunt_eventlog.py
  • scripts/native_hunt.ps1
  • scripts/parse_findings.py

Open the folder on GitHubat commit ce2b65e

Compare with similar skills

Windows Log Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windows Log Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windows Log Hunter this skillptn1411/skill220—~1kAutomated safety check: NotesNone
Hunting For Shadow Copy Deletionmukul975/Anthropic-Cybersecurity-Skills34k—~891Automated safety check: PassApache-2.0
Hunting Evtx With Chainsawmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Hunting For Anomalous Powershell Executionmukul975/Anthropic-Cybersecurity-Skills34k—~638Automated safety check: PassApache-2.0
Threat Huntingbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: NotesMIT
Detecting Suspicious Powershell Executionmukul975/Anthropic-Cybersecurity-Skills34k—~923Automated safety check: PassApache-2.0

Similar skills

  • Hunting For Shadow Copy Deletion

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands.

    34k GitHub stars~891 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting Evtx With Chainsaw

    mukul975/Anthropic-Cybersecurity-Skills

    Run Chainsaw against collected Windows EVTX files to hunt with the SigmaHQ rule corpus, built-in detection rules, and high-speed keyword/regex search, plus analyze shimcache, SRUM, and event-log…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting For Anomalous Powershell Execution

    mukul975/Anthropic-Cybersecurity-Skills

    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events.

    34k GitHub stars~638 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Threat Hunting

    briiirussell/cybersecurity-skills

    Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet.

    413 GitHub stars~2.9k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Detecting Suspicious Powershell Execution

    mukul975/Anthropic-Cybersecurity-Skills

    Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft…

    34k GitHub stars~923 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Purple Team Atomic Testing

    mukul975/Anthropic-Cybersecurity-Skills

    Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…

    34k GitHub stars~9.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from ptn1411/skill

All 22 skills in this repo
  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    220 GitHub stars~917 tokensUpdated 18 days ago
    Auto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    220 GitHub stars~830 tokensUpdated 18 days ago
    Auto-check: notes
  • Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis.

    220 GitHub stars~683 tokensUpdated 18 days ago
    Auto-check: notes
  • Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code.

    220 GitHub stars~752 tokensUpdated 18 days ago
    Auto-check: notes
  • Web App Scanner

    ptn1411/skill

    Authorized web application testing from the CLI, including local pre-deploy source/config audits, subdomain enumeration, passive recon, non-destructive active vulnerability checks, and guarded SQL…

    220 GitHub stars~3.2k tokensUpdated 18 days ago
    Auto-check: notes
  • Dotnet Decompiler

    ptn1411/skill

    Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill.

    220 GitHub stars~929 tokensUpdated 18 days ago
    Auto-check: notes

Works with

Categories

Questions about Windows Log Hunter

What does Windows Log Hunter do?

Blue-team CLI threat hunt over Windows Event Logs. An agent skill from ptn1411/skill. Windows Log Hunter is an agent skill from ptn1411/skill. Blue-team CLI threat hunt over Windows Event Logs.

When should I use Windows Log Hunter?

Windows Log Hunter fits situations like: tasks that involve Security operations.

How do I install Windows Log Hunter in Claude Code?

Run `npx skills add ptn1411/skill --skill windows-log-hunter -a claude-code`. Or copy the skill folder (windows-log-hunter in ptn1411/skill) into .claude/skills/windows-log-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Windows Log Hunter in Codex?

Run `npx skills add ptn1411/skill --skill windows-log-hunter -a codex`. Or copy the skill folder (windows-log-hunter in ptn1411/skill) into .agents/skills/windows-log-hunter in your project. Codex loads it when a task matches its description.

Can I use Windows Log Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ptn1411/skill --skill windows-log-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windows-log-hunter, .gemini/skills/windows-log-hunter, .github/skills/windows-log-hunter and .opencode/skills/windows-log-hunter in your project.

What does Windows Log Hunter need to run?

Going by SKILL.md and its folder, Windows Log Hunter needs Python and PowerShell for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3; PowerShell. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, Bash.

Does Windows Log Hunter access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Windows Log Hunter safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Windows Log Hunter use?

No licence was found for Windows Log Hunter or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Windows Log Hunter use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 703 tokens, read only when the agent opens those files.

What are the alternatives to Windows Log Hunter?

Skills that share tags, products or a category with Windows Log Hunter: Hunting For Shadow Copy Deletion (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting Evtx With Chainsaw (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting For Anomalous Powershell Execution (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Threat Hunting (briiirussell/cybersecurity-skills, 413 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windows Log Hunter?

ptn1411 (a GitHub user) maintains it in ptn1411/skill, which has 220 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on September 22, 2026.

Source: ptn1411/skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.