Canada, BC
(604) 800-9060
TERADRIVEFORENSICS
Glossary

Glossary term

KAPE

KAPE is the Kroll Artifact Parser and Extractor, a Windows triage tool that collects forensic artifacts (event logs, registry hives, browser history, prefetch, and many more) at speed for fast initial analysis.

KAPE was developed by Eric Zimmerman and is now widely used across the digital forensics and incident response community. The tool's strength is breadth and speed: in minutes it can collect a comprehensive set of forensic artifacts from a Windows endpoint, formatted for review.

For incident response, KAPE is often the first tool deployed against affected endpoints to support rapid triage and timeline reconstruction. For computer forensics, KAPE complements full disk imaging by surfacing high-value artifacts quickly while the full image is still being processed.

We use KAPE alongside Magnet AXIOM and EnCase for IR triage and for fast initial review of computer forensic engagements.

Related terms

Need digital evidence handled defensibly?

Book a confidential consultation. Our team will reach out as soon as possible.