A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.
-
Updated
May 28, 2021 - PowerShell
A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.
A collection of powershell scripts that are designed to be ran from a Microsoft Defender for Endpoint Live Response terminal, utilizing open-source tools, such as Kape (Kroll Artifact Parser and Extractor), to forensically acquire and process necessary artifact used in compromise assessments. Additional scripts provide pre-processing automation …
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
Various PowerShells scripts I've made (or others have made) to automate some of the boring stuff in my everyday DFIR journey!
A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhance the output of those tools
Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.
Add a description, image, and links to the kape topic page so that developers can more easily learn about it.
To associate your repository with the kape topic, visit your repo's landing page and select "manage topics."