
KapeFiles
This repository serves as a place for community created Targets and Modules for use with KAPE.

This repository serves as a place for community created Targets and Modules for use with KAPE.

Forensics artefact collection tool for systems running Microsoft Windows

Evtx Log (xml) Browser

Powershell module for VMWare vSphere forensics

🗒️ A [work-in-progress] collection for interview questions for Information Security roles

Composable command-line toolkit for malware triage and binary analysis: decode, decrypt, carve, and extract indicators from malicious files and…

Rapidly Search and Hunt through Windows Forensic Artefacts

Lua-based Wireshark postdissector that decrypts and parses Ubiquiti AirMAX/RouterBoard 802.11 vendor IEs into filterable fields.

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A python script developed to process Windows memory images based on triage type.

Everything related to Linux Forensics

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

A Windows kernel dump C++ parser library with Python 3 bindings.

Expose USB activity on the fly

Visualize the virtual address space of a Windows process on a Hilbert curve.