Skip to main content

KAPE Data Triage

Learn KAPE, a targeted Windows artifact collection tool for incident response.

Back to all walkthroughs
Room Icon

KAPE Data Triage

Max room.

Learn KAPE, a targeted Windows artifact collection tool for incident response.

medium

60 min

145

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

In the previous rooms, you learned what Windows is and how to organize a engagement, how to access a compromised network in order to reach the hosts you need, and what key artifacts to look for once you get there. Now it's time to put those artifacts within reach. This room walks through how to actually extract them from a Windows host, and introduces a tool built specifically for that job.

Learning Objectives

  • Understand when to collect individual artifacts instead of a full disk or memory image
  • Learn how targets and modules work, and how they differ
  • Use KAPE through its and its to collect and parse artifacts
  • Run a full KAPE acquisition against a remote host over

Prerequisites

Lab Access

DefenseBox is your forensic workstation, with KAPE already installed at C:\Users\DFIRUser\Desktop\DFIR Tools\Artifact Collection\Kape. Click on the Start DefenseBox button to open the machine in split view.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the DefenseBox, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Defender machine
Status:Off
Answer the questions below

Let's begin!