Repository navigation

#

kape

This repository serves as a place for community created Targets and Modules for use with KAPE.

755
12 天前

A repository of DFIR-related Mind Maps geared towards the visual learners!

527
3 年前

Python 3 Script to parse out iTunes backups

Python
182
2 年前

A curated list of KAPE-related resources

172
4 个月前

Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.

PowerShell
115
2 年前

A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.

98
3 年前

A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools

PowerShell
57
2 个月前

Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!

PowerShell
46
1 年前

A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

41
3 年前

Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE

PowerShell
32
1 年前

A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.

HTML
27
3 年前

A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!

17
1 年前

A collection of powershell scripts that are designed to be ran from a Microsoft Defender for Endpoint Live Response terminal, utilizing open-source tools, such as Kape (Kroll Artifact Parser and Extractor), to forensically acquire and process necessary artifact used in compromise assessments. Additional scripts provide pre-processing automation capabilities and other supporting functions.

PowerShell
11
2 年前
Python
10
2 天前

A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.

PowerShell
10
4 年前

Remote KAPE collection using powershell

PowerShell
9
6 年前

A short, focused PowerShell script to automate ensuring that all instances of EZ Tools in a given path have updated ancillary files

PowerShell
3
1 个月前

ENGLISCH LERNEN · LEARN ENGLISH · APRENDER INGLÉS · APPRENDRE L'ANGLAIS

2
5 年前

DEUTSCH LERNEN · LEARN GERMAN · APRENDER ALEMÁN · APPRENDRE L'ALLEMAND

1
5 年前