← All cheat sheets

KAPE

Plain-text reference · 7 KB. Read it, search it (Ctrl-F) or print it.

KAPE (Kroll Artifact Parser and Extractor) is a triage collection tool.
Essential for rapid evidence collection and processing.

DOWNLOAD#

# https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape

BASIC CONCEPTS#


            

TARGETS#

Define what to collect
File paths, registry keys, etc.
.tkape files

MODULES#

Define how to process collected data
Execute external tools
.mkape files

WORKFLOW#

1. Run Targets (collect)
2. Run Modules (process)

COMMAND LINE#


            

BASIC SYNTAX#

kape.exe --tsource SOURCE --tdest DEST --target TARGET
kape.exe --msource SOURCE --mdest DEST --module MODULE

TARGET COLLECTION#


            

COLLECT EVIDENCE#

kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage

COMMON TARGETS#

!SANS_Triage            Comprehensive collection
!BasicCollection        Essential artifacts
EventLogs               Windows Event Logs
FileSystem              MFT, $J, $LogFile
Registry                All registry hives
Prefetch                Prefetch files
WebBrowsers             All browser artifacts
Antivirus               AV logs
RecycleBin              Recycle bin contents
LNKFiles                Shortcut files
Amcache                 Amcache.hve
SRUM                    SRUM database
PowerShell              PowerShell logs

TARGET OPTIONS#

--tsource PATH          Source drive/path
--tdest PATH            Destination path
--target TARGET         Target name(s)
--tlist                 List available targets
--tdetail TARGET        Target details
--tvars key:value       Target variables
--tflush                Clear target dest first

EXAMPLES#

# SANS triage collection
kape.exe --tsource C: --tdest E:\Case001 --target !SANS_Triage

# Specific targets
kape.exe --tsource C: --tdest E:\Evidence --target EventLogs,Registry,Prefetch

# Network share destination
kape.exe --tsource C: --tdest \\server\share\Case001 --target !SANS_Triage

MODULE PROCESSING#


            

PROCESS EVIDENCE#

kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser

COMMON MODULES#

!EZParser               Eric Zimmerman tools
!PowerForensics         PowerForensics parsing
!KAPE                   Built-in processing
EventLogExplorer        Parse event logs
PECmd                   Parse prefetch
LECmd                   Parse LNK files
JLECmd                  Parse jump lists
MFTECmd                 Parse MFT
Registry Explorer       Parse registry
AmcacheParser           Parse amcache
SrumECmd                Parse SRUM
SQLECmd                 Parse SQLite DBs

MODULE OPTIONS#

--msource PATH          Source path
--mdest PATH            Destination path
--module MODULE         Module name(s)
--mlist                 List available modules
--mdetail MODULE        Module details
--mvars key:value       Module variables
--mflush                Clear module dest first

EXAMPLES#

# Process with EZ tools
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser

# Specific modules
kape.exe --msource E:\Evidence --mdest E:\Processed --module PECmd,MFTECmd,Registry Explorer

COMBINED WORKFLOW#


            

COLLECT AND PROCESS#

kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser

FULL COMMAND#

kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser --zip CaseName --zv true

USEFUL OPTIONS#


            

OUTPUT#

--zip NAME              Create zip archive
--zv true               Add variable to zip name
--vss                   Process VSS copies
--vhdx                  Create VHDX container
--scs NAME              SFTP connection string
--scp NAME              Copy to S3 bucket

LOGGING#

--debug                 Debug output
--trace                 Trace output
--gui                   Show progress GUI
--ul PATH               User-defined log path

PERFORMANCE#

--tdd true              Deduplicate files
--fat true              Force admin token
--sync                  Sync with GitHub

VOLUME SHADOW COPIES#

kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss

GUI MODE#

# Run kape.exe with gkape.exe for GUI

CUSTOM TARGETS#


            

TARGET FILE FORMAT#

# .tkape file (YAML)
Description: Custom target description
Author: Your Name
Version: 1.0
Id: GUID-here
RecreateDirectories: true
Targets:
  -
    Name: Custom Artifact
    Category: Custom
    Path: C:\Path\To\Artifact
    FileMask: '*.log'
    Comment: Description

CUSTOM MODULES#


            

MODULE FILE FORMAT#

# .mkape file (YAML)
Description: Custom module description
Author: Your Name
Version: 1.0
Id: GUID-here
ExportFormat: csv
Processors:
  -
    Executable: tool.exe
    CommandLine: -f %sourceFile% -o %destinationDirectory%
    ExportFormat: csv

COMMON SCENARIOS#


            

INCIDENT RESPONSE#

kape.exe --tsource C: --tdest E:\IR_Case --target !SANS_Triage --mdest E:\IR_Processed --module !EZParser --vss --zip IR_Evidence

MALWARE ANALYSIS#

kape.exe --tsource C: --tdest E:\Malware --target Prefetch,Amcache,FileSystem --mdest E:\Parsed --module PECmd,AmcacheParser,MFTECmd

LATERAL MOVEMENT#

kape.exe --tsource C: --tdest E:\LM --target EventLogs,Registry --mdest E:\Parsed --module EventLogExplorer,RegistryExplorer

REMOTE COLLECTION#

# Via PsExec or similar
psexec \\TARGET -c kape.exe --tsource C: --tdest \\SERVER\share --target !SANS_Triage

ARTIFACTS COLLECTED#


            

EXECUTION#

Prefetch
Amcache
SRUM
ShimCache
UserAssist

PERSISTENCE#

Registry Run Keys
Scheduled Tasks
Services
Startup Folders

FILE SYSTEM#

$MFT
$UsnJrnl
$LogFile
Recycle Bin

ACCOUNTS#

SAM
SECURITY
NTUSER.DAT
UsrClass.dat

NETWORK#

SRUM
Network History
WiFi Profiles

BROWSER#

Chrome History/Cache
Firefox History/Cache
Edge History/Cache
IE History/Cache

LOGS#

Windows Event Logs
PowerShell Logs
IIS Logs

QUICK REFERENCE#

# Collect
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage

# Process
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser

# Collect and process
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser

# With VSS and zip
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss --zip CaseName

# List targets/modules
kape.exe --tlist
kape.exe --mlist

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.