Windows host DFIR triage console that chains artefact collection, Sigma-correlated timelines, YARA scans, socket and account inspection, indicator enrichment, and a calibrated risk score.
Point Kage at a suspect Windows host and it runs the whole triage in one chain: CyLR collects the artefacts, Hayabusa correlates the event logs against Sigma, THOR Lite scans for YARA matches, VirusTotal and AbuseIPDB qualify the indicators, and the AI provider of your choice drafts the write-up. Every stage streams live, seals what it produced, and can be replayed alone.
pip install -r requirements.txt
python -m dfirconsole # → http://127.0.0.1:8787
The overview: eleven sealed steps on the left, the execution log
streaming, and the score broken into its four components.
| OS | Windows 10 / 11 or Windows Server |
| Python | 3.10+ from python.org, installed for all users |
| Rights | Administrator |
| Disk | a few GB free for the collection |
# 1. Extract Kage anywhere — Desktop, C:\Kage, a USB stick, it does not matter
cd C:\Kage
# 2. Install the dependencies
pip install -r requirements.txt
# 3. Check the environment before touching a host
python preflight.py
preflight.py reports what is ready and what is missing.
Workspace : C:\Kage
System : Windows 11
Python : 3.12.3
Dependencies
[ok] module fastapi
[ok] module uvicorn
[ok] module httpx
Rights and disk space
[ok] console running as administrator
[ok] free space: 84.2 GB
Tooling
[!] CyLR in C:\Kage\tools\cylr
→ the "Locate the tooling" step downloads it
[!] THOR Lite
→ optional step — it will simply be skipped
python -m dfirconsole
Or right-click launch.bat → Run as administrator, which handles the
virtualenv, the install and opens the browser for you.
Kage DFIR Toolkit 1.5.0
code C:\Kage\dfirconsole
workspace C:\Kage
open http://127.0.0.1:8787
The workspace is wherever you launched from. Nothing to configure. Tools, evidence and output all land next to the console.
python -m dfirconsole --demo
Demonstration mode builds a synthetic intrusion — malicious attachment, encoded PowerShell, Defender disabled, credential theft, persistence, C2, shadow copies deleted — and runs the entire chain on it. Nothing on your machine is touched. The best way to learn the interface before a real incident.
Launch as administrator, open http://127.0.0.1:8787, and check the status bar
reads live run · Windows and not demonstration mode.
Click Settings:
| Field | Example | Why it matters |
|---|---|---|
| Case reference | INC-2026-0042 | names the report, the log and the archive |
| Analyst | N. Delaunay | appears on the report header |
Leave Workspace folder empty it tracks the launch folder on its own. Click Save.
The left column is the chain of custody. Every step has a checkbox; all are ticked by default except the YARA scan.
For a first run, untick everything except:
☑ Prepare the workspace
☑ Exclude the folder from Defender
☑ Locate the tooling
☑ Update the Sigma rules
Click Run 4 steps. About a minute. This downloads CyLR and Hayabusa and confirms your elevation actually works before anything long begins.
Once those four are sealed, tick the rest:
☑ Collect the artefacts CyLR — a few minutes, several GB
☑ Capture the system context accounts, sockets, disk root, log coverage
☑ Build the timeline Hayabusa correlates against Sigma
☑ Analyse the timeline score, alert families, indicators
Click Run and watch the execution log stream. Each finished step gets a seal — a SHA-256 you can verify later.
| Where | What you get |
|---|---|
| Overview | risk score with its four components, alerts by family |
| Alerts | every alert, filterable by severity and family |
| System | accounts, sockets tied to processes, odd folders, log coverage |
| Indicators | hashes, IPs and domains extracted from the timeline |
Click any table row to open the reading pane: every field, the full command
line, all raw data. ← → to move between items, Esc to close.
With API keys configured:
☑ Enrich the indicators VirusTotal + AbuseIPDB reputation
☑ Write the summary the AI drafts the report
Without keys, both are marked skipped and a local write-up is produced instead — same structure, no network call.
Top right of the dashboard:
💡 Replay a single step: double-click its tag in the left column. Useful when Hayabusa fails but the collection is fine — no need to collect twice.
The YARA scan is the one step Kage cannot set up for you. Nextron requires registration, so the binary cannot be fetched by a script. CyLR and Hayabusa download themselves; THOR does not.
Register and download at
nextron-systems.com/thor-lite.
You receive the scanner and a licence file (.lic) — usually by email.
tools\thor\Kage already created that folder for you at first launch. Copy the archive's contents into it, keeping everything together: