kape
Here are 25 public repositories matching this topic...
A curated list of KAPE-related resources
- Updated
Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.
- Updated
- PowerShell
A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools
- Updated
- PowerShell
Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!
- Updated
- PowerShell
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
- Updated
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
- Updated
- PowerShell
A sample VHDX file with multiple verbose examples of forensic and anti-forensics artifacts. Meant to be basic and can be expanded upon. Please add a new issue if you have an idea for something to add.
- Updated
- HTML
A repository of output using KAPE (!EZParser Module) for various publicly available forensic images!
- Updated
Orchestration Software for Incident Response
- Updated
- Python
A collection of powershell scripts that are designed to be ran from a Microsoft Defender for Endpoint Live Response terminal, utilizing open-source tools, such as Kape (Kroll Artifact Parser and Extractor), to forensically acquire and process necessary artifact used in compromise assessments. Additional scripts provide pre-processing automation …
- Updated
- PowerShell
A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.
- Updated
- PowerShell
A short, focused PowerShell script to automate ensuring that all instances of EZ Tools in a given path have updated ancillary files
- Updated
- PowerShell
This repository serves as a place for community created SQLECmd Maps for use with SQLECmd.
- Updated
- C#
A DFIR lab demonstrating rapid forensic triage and artifact collection using Velociraptor and KAPE in response to a Mimikatz alert.
- Updated
Improve this page
Add a description, image, and links to the kape topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the kape topic, visit your repo's landing page and select "manage topics."
