Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Kage-DFIR-toolkit — Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator enrichment, and a calibrated risk score. | Kitploit
Tools/GitHubGitHub/karim852/kage-dfir-toolkit
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability AnalysisScripting & AutomationForensicsInformation GatheringMalware AnalysisDigital ForensicsThreat IntelligenceIncident ResponseLog Analysis
2068916 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
karim852/kage-dfir-toolkit

Kage-DFIR-toolkit

Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator enrichment, and a calibrated risk score.

View RepositoryWebsite
Share

KAGE — DFIR Toolkit

---

Point Kage at a suspect Windows host and it runs the whole triage in one chain: CyLR collects the artefacts, Hayabusa correlates the event logs against Sigma, THOR Lite scans for YARA matches, VirusTotal and AbuseIPDB qualify the indicators, and the AI provider of your choice drafts the write-up. Every stage streams live, seals what it produced, and can be replayed alone.

pip install -r requirements.txt
python -m dfirconsole          # → http://127.0.0.1:8787

Kage overview
The overview: eleven sealed steps on the left, the execution log streaming, and the score broken into its four components.


📑 Table of contents

  • Installation
  • Running your first scan
  • Adding THOR Lite manually
  • The chain
  • Risk score
  • Alerts
  • System context
  • Logging & audit
  • YARA
  • Seals
  • Views
  • Configuration
  • CLI reference
  • Troubleshooting
  • Linux version
  • Credits

📦 Installation

Requirements

OSWindows 10 / 11 or Windows Server
Python3.10+ from python.org, installed for all users
RightsAdministrator
Diska few GB free for the collection

Install

# 1. Extract Kage anywhere — Desktop, C:\Kage, a USB stick, it does not matter
cd C:\Kage

# 2. Install the dependencies
pip install -r requirements.txt

# 3. Check the environment before touching a host
python preflight.py

preflight.py reports what is ready and what is missing.

Workspace   : C:\Kage
System      : Windows 11
Python      : 3.12.3

Dependencies
  [ok]   module fastapi
  [ok]   module uvicorn
  [ok]   module httpx

Rights and disk space
  [ok]   console running as administrator
  [ok]   free space: 84.2 GB

Tooling
  [!]    CyLR in C:\Kage\tools\cylr
           → the "Locate the tooling" step downloads it
  [!]    THOR Lite
           → optional step — it will simply be skipped

Launch — as Administrator

python -m dfirconsole

Or right-click launch.bat → Run as administrator, which handles the virtualenv, the install and opens the browser for you.

Kage DFIR Toolkit 1.5.0
  code      C:\Kage\dfirconsole
  workspace C:\Kage
  open      http://127.0.0.1:8787

The workspace is wherever you launched from. Nothing to configure. Tools, evidence and output all land next to the console.

Try it with no risk first

python -m dfirconsole --demo

Demonstration mode builds a synthetic intrusion — malicious attachment, encoded PowerShell, Defender disabled, credential theft, persistence, C2, shadow copies deleted — and runs the entire chain on it. Nothing on your machine is touched. The best way to learn the interface before a real incident.


🚀 Running your first scan

Step 1 — Open the console

Launch as administrator, open http://127.0.0.1:8787, and check the status bar reads live run · Windows and not demonstration mode.

Step 2 — Name the case

Click Settings:

FieldExampleWhy it matters
Case referenceINC-2026-0042names the report, the log and the archive
AnalystN. Delaunayappears on the report header

Leave Workspace folder empty it tracks the launch folder on its own. Click Save.

Step 3 — Warm up before committing

The left column is the chain of custody. Every step has a checkbox; all are ticked by default except the YARA scan.

For a first run, untick everything except:

☑ Prepare the workspace
☑ Exclude the folder from Defender
☑ Locate the tooling
☑ Update the Sigma rules

Click Run 4 steps. About a minute. This downloads CyLR and Hayabusa and confirms your elevation actually works before anything long begins.

Step 4 — Collect and analyse

Once those four are sealed, tick the rest:

☑ Collect the artefacts        CyLR — a few minutes, several GB
☑ Capture the system context   accounts, sockets, disk root, log coverage
☑ Build the timeline           Hayabusa correlates against Sigma
☑ Analyse the timeline         score, alert families, indicators

Click Run and watch the execution log stream. Each finished step gets a seal — a SHA-256 you can verify later.

Step 5 — Read the results

WhereWhat you get
Overviewrisk score with its four components, alerts by family
Alertsevery alert, filterable by severity and family
Systemaccounts, sockets tied to processes, odd folders, log coverage
Indicatorshashes, IPs and domains extracted from the timeline

Click any table row to open the reading pane: every field, the full command line, all raw data. ← → to move between items, Esc to close.

Step 6 — Enrich and conclude (optional)

With API keys configured:

☑ Enrich the indicators    VirusTotal + AbuseIPDB reputation
☑ Write the summary        the AI drafts the report

Without keys, both are marked skipped and a local write-up is produced instead — same structure, no network call.

Step 7 — Export

Top right of the dashboard:

  • Report — printable HTML, thirteen numbered sections, ready for PDF
  • JSON — the complete state, seals included
  • Log — everything the console produced

💡 Replay a single step: double-click its tag in the left column. Useful when Hayabusa fails but the collection is fine — no need to collect twice.


🔦 Adding THOR Lite manually

The YARA scan is the one step Kage cannot set up for you. Nextron requires registration, so the binary cannot be fetched by a script. CyLR and Hayabusa download themselves; THOR does not.

1. Get the archive

Register and download at nextron-systems.com/thor-lite. You receive the scanner and a licence file (.lic) — usually by email.

2. Drop it in tools\thor\

Kage already created that folder for you at first launch. Copy the archive's contents into it, keeping everything together:

Download Tool