KAPE
KAPE (Kroll Artifact Parser and Extractor) is a triage collection tool. Essential for rapid evidence collection and processing.
DOWNLOAD#
# https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape
BASIC CONCEPTS#
TARGETS#
Define what to collect File paths, registry keys, etc. .tkape files
MODULES#
Define how to process collected data Execute external tools .mkape files
WORKFLOW#
1. Run Targets (collect) 2. Run Modules (process)
COMMAND LINE#
BASIC SYNTAX#
kape.exe --tsource SOURCE --tdest DEST --target TARGET kape.exe --msource SOURCE --mdest DEST --module MODULE
TARGET COLLECTION#
COLLECT EVIDENCE#
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage
COMMON TARGETS#
!SANS_Triage Comprehensive collection !BasicCollection Essential artifacts EventLogs Windows Event Logs FileSystem MFT, $J, $LogFile Registry All registry hives Prefetch Prefetch files WebBrowsers All browser artifacts Antivirus AV logs RecycleBin Recycle bin contents LNKFiles Shortcut files Amcache Amcache.hve SRUM SRUM database PowerShell PowerShell logs
TARGET OPTIONS#
--tsource PATH Source drive/path --tdest PATH Destination path --target TARGET Target name(s) --tlist List available targets --tdetail TARGET Target details --tvars key:value Target variables --tflush Clear target dest first
EXAMPLES#
# SANS triage collection kape.exe --tsource C: --tdest E:\Case001 --target !SANS_Triage # Specific targets kape.exe --tsource C: --tdest E:\Evidence --target EventLogs,Registry,Prefetch # Network share destination kape.exe --tsource C: --tdest \\server\share\Case001 --target !SANS_Triage
MODULE PROCESSING#
PROCESS EVIDENCE#
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser
COMMON MODULES#
!EZParser Eric Zimmerman tools !PowerForensics PowerForensics parsing !KAPE Built-in processing EventLogExplorer Parse event logs PECmd Parse prefetch LECmd Parse LNK files JLECmd Parse jump lists MFTECmd Parse MFT Registry Explorer Parse registry AmcacheParser Parse amcache SrumECmd Parse SRUM SQLECmd Parse SQLite DBs
MODULE OPTIONS#
--msource PATH Source path --mdest PATH Destination path --module MODULE Module name(s) --mlist List available modules --mdetail MODULE Module details --mvars key:value Module variables --mflush Clear module dest first
EXAMPLES#
# Process with EZ tools kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser # Specific modules kape.exe --msource E:\Evidence --mdest E:\Processed --module PECmd,MFTECmd,Registry Explorer
COMBINED WORKFLOW#
COLLECT AND PROCESS#
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser
FULL COMMAND#
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser --zip CaseName --zv true
USEFUL OPTIONS#
OUTPUT#
--zip NAME Create zip archive --zv true Add variable to zip name --vss Process VSS copies --vhdx Create VHDX container --scs NAME SFTP connection string --scp NAME Copy to S3 bucket
LOGGING#
--debug Debug output --trace Trace output --gui Show progress GUI --ul PATH User-defined log path
PERFORMANCE#
--tdd true Deduplicate files --fat true Force admin token --sync Sync with GitHub
VOLUME SHADOW COPIES#
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss
GUI MODE#
# Run kape.exe with gkape.exe for GUI
CUSTOM TARGETS#
TARGET FILE FORMAT#
# .tkape file (YAML)
Description: Custom target description
Author: Your Name
Version: 1.0
Id: GUID-here
RecreateDirectories: true
Targets:
-
Name: Custom Artifact
Category: Custom
Path: C:\Path\To\Artifact
FileMask: '*.log'
Comment: Description
CUSTOM MODULES#
MODULE FILE FORMAT#
# .mkape file (YAML)
Description: Custom module description
Author: Your Name
Version: 1.0
Id: GUID-here
ExportFormat: csv
Processors:
-
Executable: tool.exe
CommandLine: -f %sourceFile% -o %destinationDirectory%
ExportFormat: csv
COMMON SCENARIOS#
INCIDENT RESPONSE#
kape.exe --tsource C: --tdest E:\IR_Case --target !SANS_Triage --mdest E:\IR_Processed --module !EZParser --vss --zip IR_Evidence
MALWARE ANALYSIS#
kape.exe --tsource C: --tdest E:\Malware --target Prefetch,Amcache,FileSystem --mdest E:\Parsed --module PECmd,AmcacheParser,MFTECmd
LATERAL MOVEMENT#
kape.exe --tsource C: --tdest E:\LM --target EventLogs,Registry --mdest E:\Parsed --module EventLogExplorer,RegistryExplorer
REMOTE COLLECTION#
# Via PsExec or similar psexec \\TARGET -c kape.exe --tsource C: --tdest \\SERVER\share --target !SANS_Triage
ARTIFACTS COLLECTED#
EXECUTION#
Prefetch Amcache SRUM ShimCache UserAssist
PERSISTENCE#
Registry Run Keys Scheduled Tasks Services Startup Folders
FILE SYSTEM#
$MFT $UsnJrnl $LogFile Recycle Bin
ACCOUNTS#
SAM SECURITY NTUSER.DAT UsrClass.dat
NETWORK#
SRUM Network History WiFi Profiles
BROWSER#
Chrome History/Cache Firefox History/Cache Edge History/Cache IE History/Cache
LOGS#
Windows Event Logs PowerShell Logs IIS Logs
QUICK REFERENCE#
# Collect kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage # Process kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser # Collect and process kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser # With VSS and zip kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss --zip CaseName # List targets/modules kape.exe --tlist kape.exe --mlist
KAPE CHEATSHEET
===============
Source: https://cheatsheet.johlem.net
KAPE (Kroll Artifact Parser and Extractor) is a triage collection tool.
Essential for rapid evidence collection and processing.
DOWNLOAD
--------
# https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape
BASIC CONCEPTS
==============
TARGETS
-------
Define what to collect
File paths, registry keys, etc.
.tkape files
MODULES
-------
Define how to process collected data
Execute external tools
.mkape files
WORKFLOW
--------
1. Run Targets (collect)
2. Run Modules (process)
COMMAND LINE
============
BASIC SYNTAX
------------
kape.exe --tsource SOURCE --tdest DEST --target TARGET
kape.exe --msource SOURCE --mdest DEST --module MODULE
TARGET COLLECTION
=================
COLLECT EVIDENCE
----------------
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage
COMMON TARGETS
--------------
!SANS_Triage Comprehensive collection
!BasicCollection Essential artifacts
EventLogs Windows Event Logs
FileSystem MFT, $J, $LogFile
Registry All registry hives
Prefetch Prefetch files
WebBrowsers All browser artifacts
Antivirus AV logs
RecycleBin Recycle bin contents
LNKFiles Shortcut files
Amcache Amcache.hve
SRUM SRUM database
PowerShell PowerShell logs
TARGET OPTIONS
--------------
--tsource PATH Source drive/path
--tdest PATH Destination path
--target TARGET Target name(s)
--tlist List available targets
--tdetail TARGET Target details
--tvars key:value Target variables
--tflush Clear target dest first
EXAMPLES
--------
# SANS triage collection
kape.exe --tsource C: --tdest E:\Case001 --target !SANS_Triage
# Specific targets
kape.exe --tsource C: --tdest E:\Evidence --target EventLogs,Registry,Prefetch
# Network share destination
kape.exe --tsource C: --tdest \\server\share\Case001 --target !SANS_Triage
MODULE PROCESSING
=================
PROCESS EVIDENCE
----------------
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser
COMMON MODULES
--------------
!EZParser Eric Zimmerman tools
!PowerForensics PowerForensics parsing
!KAPE Built-in processing
EventLogExplorer Parse event logs
PECmd Parse prefetch
LECmd Parse LNK files
JLECmd Parse jump lists
MFTECmd Parse MFT
Registry Explorer Parse registry
AmcacheParser Parse amcache
SrumECmd Parse SRUM
SQLECmd Parse SQLite DBs
MODULE OPTIONS
--------------
--msource PATH Source path
--mdest PATH Destination path
--module MODULE Module name(s)
--mlist List available modules
--mdetail MODULE Module details
--mvars key:value Module variables
--mflush Clear module dest first
EXAMPLES
--------
# Process with EZ tools
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser
# Specific modules
kape.exe --msource E:\Evidence --mdest E:\Processed --module PECmd,MFTECmd,Registry Explorer
COMBINED WORKFLOW
=================
COLLECT AND PROCESS
-------------------
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser
FULL COMMAND
------------
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser --zip CaseName --zv true
USEFUL OPTIONS
==============
OUTPUT
------
--zip NAME Create zip archive
--zv true Add variable to zip name
--vss Process VSS copies
--vhdx Create VHDX container
--scs NAME SFTP connection string
--scp NAME Copy to S3 bucket
LOGGING
-------
--debug Debug output
--trace Trace output
--gui Show progress GUI
--ul PATH User-defined log path
PERFORMANCE
-----------
--tdd true Deduplicate files
--fat true Force admin token
--sync Sync with GitHub
VOLUME SHADOW COPIES
--------------------
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss
GUI MODE
--------
# Run kape.exe with gkape.exe for GUI
CUSTOM TARGETS
==============
TARGET FILE FORMAT
------------------
# .tkape file (YAML)
Description: Custom target description
Author: Your Name
Version: 1.0
Id: GUID-here
RecreateDirectories: true
Targets:
-
Name: Custom Artifact
Category: Custom
Path: C:\Path\To\Artifact
FileMask: '*.log'
Comment: Description
CUSTOM MODULES
==============
MODULE FILE FORMAT
------------------
# .mkape file (YAML)
Description: Custom module description
Author: Your Name
Version: 1.0
Id: GUID-here
ExportFormat: csv
Processors:
-
Executable: tool.exe
CommandLine: -f %sourceFile% -o %destinationDirectory%
ExportFormat: csv
COMMON SCENARIOS
================
INCIDENT RESPONSE
-----------------
kape.exe --tsource C: --tdest E:\IR_Case --target !SANS_Triage --mdest E:\IR_Processed --module !EZParser --vss --zip IR_Evidence
MALWARE ANALYSIS
----------------
kape.exe --tsource C: --tdest E:\Malware --target Prefetch,Amcache,FileSystem --mdest E:\Parsed --module PECmd,AmcacheParser,MFTECmd
LATERAL MOVEMENT
----------------
kape.exe --tsource C: --tdest E:\LM --target EventLogs,Registry --mdest E:\Parsed --module EventLogExplorer,RegistryExplorer
REMOTE COLLECTION
-----------------
# Via PsExec or similar
psexec \\TARGET -c kape.exe --tsource C: --tdest \\SERVER\share --target !SANS_Triage
ARTIFACTS COLLECTED
===================
EXECUTION
---------
Prefetch
Amcache
SRUM
ShimCache
UserAssist
PERSISTENCE
-----------
Registry Run Keys
Scheduled Tasks
Services
Startup Folders
FILE SYSTEM
-----------
$MFT
$UsnJrnl
$LogFile
Recycle Bin
ACCOUNTS
--------
SAM
SECURITY
NTUSER.DAT
UsrClass.dat
NETWORK
-------
SRUM
Network History
WiFi Profiles
BROWSER
-------
Chrome History/Cache
Firefox History/Cache
Edge History/Cache
IE History/Cache
LOGS
----
Windows Event Logs
PowerShell Logs
IIS Logs
QUICK REFERENCE
---------------
# Collect
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage
# Process
kape.exe --msource E:\Evidence --mdest E:\Processed --module !EZParser
# Collect and process
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --mdest E:\Processed --module !EZParser
# With VSS and zip
kape.exe --tsource C: --tdest E:\Evidence --target !SANS_Triage --vss --zip CaseName
# List targets/modules
kape.exe --tlist
kape.exe --mlist
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.