Skip to content
hackingtools.ai

KAPE

KAPE is a free Windows triage tool used to collect and parse forensic artifacts quickly for government, education, and internal company incident responders.

0

0 upvotes · 0 downvotes

No ratings yet

Pricing
Free
Platforms
Windows
Reviewed
Last reviewed 6 October 2026

What it is

A collection and processing program from Kroll that pulls the most useful files from a live system or mounted image before a full disk image is finished. It works in two stages: Targets define which files and folders to copy, and Modules run other programs against what was gathered.

What it helps with

- Copying files the operating system has locked, with original timestamps kept
- Sorting parsed output into folders such as EvidenceOfExecution and BrowserHistory
- Keeping evidence collection the same across analysts and machines
- Sending collections to SFTP, Amazon S3, or Azure storage

Who it's for

Incident responders and forensic examiners in government, education, research, or in-house security teams working on systems their organization owns.

Worth knowing

Since January 1, 2026, it is not available for use on a third-party network or as part of a paid engagement. It needs administrator rights and Microsoft .NET 4.5.2 or newer.

Is KAPE open source?
No. The program is closed source, while its Targets and Modules files are public under the MIT license.

Does it replace a full disk image?
No. It grabs the highest-value artifacts first, and you can still image the drive afterward.

Discussion & reviews

0 comments

Your rating (optional)

0/4,000

No contributions yet. Be the first to review or comment.

← Back to directory