# EIDVault — Windows Event ID Reference

> Windows Event ID reference for cybersecurity and DFIR with investigative context. (iPhone/iPad app by Zachary Burnham.)

- Source: https://appshunter.io/ios/app/eidvault/id6761655272 (this page in markdown: same URL + `.md`)
- Developer: [Zachary Burnham](https://appshunter.io/developer/1890695371)
- Category: Reference, Developer Tools
- Price: Free
- Rating: 5.00/5 from 2 App Store ratings · 1 written reviews indexed
- Age rating: 17+
- Requires: iOS 26.0 · 8 MB
- Languages: English
- Released: 2026-04-14
- Data updated: 2026-06-24
- Monetization: free
- User reviews in markdown: https://appshunter.io/ios/app/eidvault/id6761655272/reviews.md

## What is EIDVault?

EIDVault is a comprehensive reference for Windows® EVTX log channels relevant to cybersecurity and DFIR. Event IDs (EIDs) are enriched with investigative notes, detection rules (KQL, Sigma, and more), and MITRE ATT&CK® mappings for fast, context-rich lookups. The Scenarios tab takes it further - describe an attack technique or investigation scenario and on-device intelligence surfaces the relevant EIDs with context. Share EID details as plain text or formatted Markdown for easy documentation or collaboration.

## Key features

- Windows EVTX log channel reference
- Investigative notes for Event IDs
- Detection rules (KQL, Sigma)
- MITRE ATT&CK mappings
- Scenario-based Event ID lookup
- Shareable EID details (text, Markdown)

## Recent user reviews (1 of 1)

All indexed reviews: https://appshunter.io/ios/app/eidvault/id6761655272/reviews.md

### 5/5 — Wow

*2026-04-15*

Really opened my eyes to the online world

## Frequently asked questions about EIDVault

### What is EIDVault?

EIDVault is a free reference application for Windows Event IDs, designed to assist cybersecurity and DFIR professionals. It provides detailed investigative notes, detection rules, and MITRE ATT&CK mappings for quick analysis of log data.

### Is EIDVault free to use?

Yes, EIDVault is completely free to use. It does not have any in-app purchases or subscription fees, making it an accessible tool for all users.

### What devices does EIDVault support?

EIDVault is available for iPhone and iPad devices. It is optimized for mobile use, allowing for quick lookups on the go.

### How often is EIDVault updated?

The latest version of EIDVault is 1.1.1, which was last updated on May 27, 2026. This indicates a commitment to keeping the reference data current.

### What is the age rating for EIDVault?

EIDVault has an age rating of 17+. This is likely due to the technical and sensitive nature of cybersecurity and digital forensics content.

### Can I share EID information from EIDVault?

Yes, EIDVault allows you to share Event ID details as plain text or formatted Markdown. This feature is useful for documentation and collaboration with team members.

### Does EIDVault have ads?

No, EIDVault does not contain advertisements. As a free application, it focuses on providing a clean and uninterrupted user experience for its reference material.

### How does EIDVault help with incident response?

EIDVault helps with incident response by providing immediate access to context-rich information about Windows Event IDs. The inclusion of investigative notes, detection rules, and MITRE ATT&CK mappings allows for faster identification and analysis of security events.

## Version history (last 3 releases)

### 1.1.1 — 2026-05-27

Privacy Policy link updated

### 1.1 — 2026-05-17

Version 1.1 brings major updates to Scenarios and new ways to share data. Thanks again to everyone for all the feedback!

Scenarios Re-Work
Scenarios (now in experimental preview) has been rebuilt from the ground up with a cleaner interface, more relevant context surfaced per result, and smarter enrichment post-processing. A new bundled dataset of attack tools, techniques, and DFIR definitions is now injected into Scenario prompts automatically. You can also now ask follow-up questions within a Scenario session, with suggestions surfaced via on-device intelligence to guide additional inquiries.

Detection Rules Export
You can now generate baseline Sigma, KQL, or SPL rules directly from Scenario results and export them as files or share inline. Detection rules can also be exported via Apple Shortcuts using App Intents.

MITRE ATT&CK® v19 Support
The dataset has been updated and tested against all framework changes, including updated tactic and technique naming.

Additional Changes
- Plain text has been added as a share/export format alongside the existing Markdown and CSV options
- Data Stats updated to track enrichments via GitHub
- Various stability improvements and UI polish based on beta feedback

### 1.0 — 2026-04-15

No release notes.

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-06-24.*
