KAPE
KAPE is a free Windows triage tool used to collect and parse forensic artifacts quickly for government, education, and internal company incident responders.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- Windows
- Reviewed
- Last reviewed 6 October 2026
What it is
A collection and processing program from Kroll that pulls the most useful files from a live system or mounted image before a full disk image is finished. It works in two stages: Targets define which files and folders to copy, and Modules run other programs against what was gathered.
What it helps with
- Copying files the operating system has locked, with original timestamps kept
- Sorting parsed output into folders such as EvidenceOfExecution and BrowserHistory
- Keeping evidence collection the same across analysts and machines
- Sending collections to SFTP, Amazon S3, or Azure storage
Who it's for
Incident responders and forensic examiners in government, education, research, or in-house security teams working on systems their organization owns.
Worth knowing
Since January 1, 2026, it is not available for use on a third-party network or as part of a paid engagement. It needs administrator rights and Microsoft .NET 4.5.2 or newer.
Is KAPE open source?
No. The program is closed source, while its Targets and Modules files are public under the MIT license.
Does it replace a full disk image?
No. It grabs the highest-value artifacts first, and you can still image the drive afterward.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.