BigHugger
sk Skill · mukul975

triaging-windows-with-kape

Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping Eric Zimmerman's EZ Tools (PECmd, MFTECmd, RECmd). Use during early incident containment/triage when full disk imaging is impractical but a defensible, parseable Windows artifact set is needed quickly, including at-scale…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
windows-forensicseric-zimmermanartifact-collectionPythondfirtriageincident-responsekapecmddigital-forensics
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python