To access material, start machines and answer questions login.
In the previous rooms, you learned what Windows is and how to organize a engagement, how to access a compromised network in order to reach the hosts you need, and what key artifacts to look for once you get there. Now it's time to put those artifacts within reach. This room walks through how to actually extract them from a Windows host, and introduces a tool built specifically for that job.
Learning Objectives
- Understand when to collect individual artifacts instead of a full disk or memory image
- Learn how targets and modules work, and how they differ
- Use KAPE through its and its to collect and parse artifacts
- Run a full KAPE acquisition against a remote host over
Prerequisites
- Complete the Introduction to Windows IR room
- Complete the Accessing a Compromised Network room
- Complete the Key Artifacts for DFIR room
Lab Access
DefenseBox is your forensic workstation, with KAPE already installed at C:\Users\DFIRUser\Desktop\DFIR Tools\Artifact Collection\Kape. Click on the Start DefenseBox button to open the machine in split view.
Set up your virtual environment
Let's begin!
Ready to learn Cyber Security?
The KAPE Data Triage room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

