All Projects → EricZimmerman → KapeFiles

EricZimmerman / KapeFiles

Licence: MIT License
This repository serves as a place for community created Targets and Modules for use with KAPE.

Projects that are alternatives of or similar to KapeFiles

DFIRRegex
A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.
Stars: ✭ 33 (-89.07%)
Mutual labels:  kape
LinuxCatScale
Incident Response collection and processing scripts with automated reporting scripts
Stars: ✭ 143 (-52.65%)
Mutual labels:  triage
iTunes Backup Reader
Python 3 Script to parse out iTunes backups
Stars: ✭ 108 (-64.24%)
Mutual labels:  kape
uac
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
Stars: ✭ 260 (-13.91%)
Mutual labels:  triage
AppmemDumper
Forensics triage tool relying on Volatility and Foremost
Stars: ✭ 22 (-92.72%)
Mutual labels:  triage
TriFlow
TriFlow: Triaging Android Applications using Speculative Information Flows
Stars: ✭ 12 (-96.03%)
Mutual labels:  triage
sensible-github-labels
Github labels for teams that like workflows and structure
Stars: ✭ 121 (-59.93%)
Mutual labels:  triage
EventTranscript.db-Research
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
Stars: ✭ 33 (-89.07%)
Mutual labels:  kape
Octobox
📮Untangle your GitHub Notifications
Stars: ✭ 4,137 (+1269.87%)
Mutual labels:  triage

Logo

KAPE Files

Community-created Targets and Modules for use with KAPE
Download KAPE · Report a Bug · Request Feature

QUICK START

KAPE is an efficient and highly configurable triage program that will target essentially any device or storage location, find forensically useful artifacts, and parse them within a few minutes. KAPE can be downloaded HERE.

For thorough documentation, go HERE!! This URL will always be the latest documentation.

It is also possible to attend KAPE training from Kroll instructors. Details can be found HERE!!

NOTE: We have clarified KAPE usage permissions for commercial applications. See details here.

Downloading KapeFiles for KAPE

To download the latest files, click the "Sync with GitHub" button in gkape.exe or run kape.exe --sync

Contributing

This repository serves as a place for community-created Targets and Modules for use with KAPE.

Please send PRs should you come up with new Targets or Modules for inclusion in the project!

Ongoing Projects

  • Targets/Modules To Do List - Development roadmap for KAPE Targets and Modules. Please feel free to contribute by adding ideas or by finishing tasks in the To Do column. Any help is appreciated!

Targets

If you need help with creating Targets, check out this guide. Also consult the Target Guide, Target Template, Compound Target Guide or Compound Target Template to ensure the Target(s) follow the same format.

Modules

If you need help with creating Modules, please consult the Module Guide, Module Template, Compound Module Guide or Compound Module Template to ensure the Module(s) follow the same format.

Be sure to point the BinaryUrl property to the download location in Module files!

All other info including requirements, etc. should be documented at the end of the Module in comment blocks.

NOTE: BEFORE INITIATING A PR, PLEASE ENSURE YOU HAVE COMPLETED THE STEPS LISTED WITHIN THE PULL REQUEST TEMPLATE PRIOR TO SUBMISSION!

Eric Zimmerman

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].