Skip to main content

KAPE

Kroll Artifact Parser and Extractor for rapid Windows triage that collects and parses registry, event log, and browser artifacts from live systems.

Technical Architecture & Overview

KAPE is a Windows triage program that collects and parses forensically useful artifacts from live systems or mounted images in minutes. Eric Zimmerman created the tool; Kroll maintains and distributes it. It is free for government, educational, and internal company use; a paid enterprise license is required for third-party networks or paid engagements.

Targeted Technical Use Cases

Rapidly collect registry, event log, browser, file system, and other artifacts from a Windows host, then parse them with built-in and community modules.

Evaluation & Trade-offs

Core Strengths

  • +Large library of community-maintained collection targets and parsing modules.
  • +Processes live systems, mounted images, and Volume Shadow Copy Service data.

Trade-Offs & Limitations

  • -Windows-only host execution.
  • -Requires an enterprise license for commercial paid or third-party network use.

Defensive Security Application

Collect and parse Windows artifacts during an active incident to find lateral movement, persistence, and user activity, then reduce dwell time.

Frequently Asked Questions

What is KAPE?

KAPE is a Windows triage program that collects and parses forensically useful artifacts from live systems or mounted images in minutes. Eric Zimmerman created the tool; Kroll maintains and distributes it. It is free for government, educational, and internal company use; a paid enterprise license is required for third-party networks or paid engagements.

What is KAPE used for?

Rapidly collect registry, event log, browser, file system, and other artifacts from a Windows host, then parse them with built-in and community modules.

What are the strengths of KAPE?
  • +Large library of community-maintained collection targets and parsing modules.
  • +Processes live systems, mounted images, and Volume Shadow Copy Service data.
What are the limitations of KAPE?
  • +Windows-only host execution.
  • +Requires an enterprise license for commercial paid or third-party network use.
How is KAPE used defensively?

Collect and parse Windows artifacts during an active incident to find lateral movement, persistence, and user activity, then reduce dwell time.