logo

KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet

ID: 1f4c3593-08a9-5561-a963-cf00f7d823de

STIX ID: report--1f4c3593-08a9-5561-a963-cf00f7d823de

Feed Name: Black Hills Infosec Blog

Date Published: 2026-07-15

Date Updated: 2026-07-20

Author: BHIS

...
...

This article provides a concise tutorial on using Kroll Artifact Parser and Extractor (KAPE) to extract Windows forensic artifacts into a VHDX container and parse key artifacts (Master File Table, USN Journal, Event Logs) into analyzable formats (CSV/JSON), with practical tips for incident responders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.