kape
Here are 30 public repositories matching this topic...
A curated list of KAPE-related resources
-
Updated
May 1, 2025
Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.
-
Updated
Nov 28, 2023 - PowerShell
A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools
-
Updated
Jun 24, 2025 - PowerShell
Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!
-
Updated
Jan 9, 2026 - PowerShell
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
-
Updated
Jul 18, 2022
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
-
Updated
May 25, 2024 - PowerShell
A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.
-
Updated
Jan 2, 2023 - HTML
Rust DFIR tool that massively parses cross-platform evidence, even deleted logs, into a lateral movement timeline and graph database.
-
Updated
May 21, 2026 - Rust
A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!
-
Updated
Aug 31, 2024
Orchestration Software for Incident Response
-
Updated
Sep 3, 2026 - Python
DFIR Presentations
-
Updated
Apr 24, 2026
A collection of powershell scripts that are designed to be ran from a Microsoft Defender for Endpoint Live Response terminal, utilizing open-source tools, such as Kape (Kroll Artifact Parser and Extractor), to forensically acquire and process necessary artifact used in compromise assessments. Additional scripts provide pre-processing automation …
-
Updated
Apr 26, 2023 - PowerShell
A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.
-
Updated
May 28, 2021 - PowerShell
A short, focused PowerShell script to automate ensuring that all instances of EZ Tools in a given path have updated ancillary files
-
Updated
Jul 10, 2025 - PowerShell
DFIR artifact catalog (6,554 artifacts, LOL/LOFL binaries, abusable sites) plus the normalized report vocabulary the SecurityRonin analyzer fleet shares — offline Rust library + 4n6query CLI
-
Updated
Sep 6, 2026 - Rust
Add this topic to your repo
To associate your repository with the kape topic, visit your repo's landing page and select "manage topics."