All Artifacts
Browse 340 KAPE forensic artifact targets
Antivirus 28
view allApps 144
view allBrowsers 23
view allCompound 34
view allBasicCollection
collectionBasic Collection
SANS_Triage
collectionSANS Triage Collection
Antivirus
collectionAntivirus
CloudStorage_All
collectionCloud Storage Contents and Metadata
CloudStorage_Metadata
collectionCloud Storage Metadata
CloudStorage_OneDriveExplorer
collectionOneDrive and other files used with OneDriveExplorer
P2P 17
view allWindows 94
view allAVG
AVG Antivirus Data
Avast
Avast Antivirus Data
AviraAVLogs
Avira Logs
Bitdefender
Bitdefender Antivirus Data
Combofix
ComboFix Antivirus Data
CrowdStrikeFalcon
CrowdStrike Falcon
Cybereason
Cybereason Sensor/Detection Logs
Cylance
Cylance Antivirus Logs
ESET
ESET Antivirus Data
Emsisoft
Emsisoft Antivirus Logs
FSecure
F-Secure Antivirus Data
HitmanPro
HitmanPro Antivirus Data
Malwarebytes
Malwarebytes Data
McAfee
McAfee Log Files
McAfee_ePO
McAfee ePO Log Files
MicrosoftSafetyScanner
Microsoft Safety Scanner
RogueKiller
RogueKiller Anti-Malware (by Adlice Software)
SUPERAntiSpyware
SUPERAntiSpyware Data
SecureAge
SecureAge Antivirus Logs
SentinelOne
Sentinel One Logs
Sophos
Sophos Data
Symantec_AV_Logs
Symantec AV Logs
TotalAV
TotalAV Antivirus Data
TrendMicro
Trend Micro Data
VIPRE
VIPRE Data
Webroot
Webroot Antivirus
WinDefendDetectionHist
Windows Defender Threat DetectionHistory files
WindowsDefender
Windows Defender Data
1Password
1Password Password Manager
4KVideoDownloader
4K Video Downloader
AceText
AceText
AcronisTrueImage
Acronis True Image
Action1
Action1 Application Logs
AdvancedIPScanner
Advanced IP Scanner Artifacts
AdvancedPortScanner
Advanced Port Scanner Artifacts
AgentRansack
Agent Ransack - Free File Searching Utility
Ammyy
Ammyy Data
AnyDesk
AnyDesk
AsperaConnect
Aspera Connect Log Files
AteraAgent
AteraAgent
BoxDrive_Metadata
Box Cloud Storage Metadata
BoxDrive_UserFiles
Box Cloud Storage Files
ChatGPT
A Target to collect files related to ChatGPT Desktop
CiscoJabber
Jabber
ClipboardMaster
ClipboardMaster
ConfluenceLogs
Confluence Log Files
DWAgent
DWAgent Log Files
DirectoryOpus
Directory Opus
Discord
Discord Cache and LevelDB Files
DoubleCommander
Double Commander
Dropbox_Metadata
Dropbox Cloud Storage Metadata
Dropbox_UserFiles
Dropbox Cloud Storage Files
EFCommander
EF Commander
Evernote
Evernote
Everything (VoidTools)
Everything (VoidTools)
FastStoneImageViewer
FastStone Image Viewer
Fences
Fences
FileZillaClient
FileZilla XML and SQLite Log Files
FileZillaServer
FileZilla Server Logs
FortiClientVPN
Forti Client VPN
FreeCommander
FreeCommander XE
FreeDownloadManager
Free Download Manager
FreeFileSync
FreeFileSync
GoogleDriveBackupSync_UserFiles
Google Backup and Sync Storage Files
GoogleDrive_Metadata
Google Drive Metadata
GoogleEarth
Google Earth
HeidiSQL
HeidiSQL
HexChat
HexChat
IDrive
IDrive Backup Artifacts
ISLOnline
ISLOnline Remote Access Tool
ITarian
ITarian RMM
IceChat
IceChat
ImgBurn
ImgBurn
IrfanView
IrfanView
JDownloader2
JDownloader 2
JavaWebCache
Java WebStart Cache - (IDX Files)
Kaseya
Kaseya Data
Keepass
Keepass
KeepassXC
KeepassXC
Level
Level.io Application Logs
LogMeIn
LogMeIn Data
MacriumReflect
Macrium Reflect
Mattermost
Mattermost
MediaMonkey
MediaMonkey
Megasync
MegaSync Data Collection
MeshAgent
MeshAgent log and configuration files
MicrosoftAzureCopy
Microsoft Azure Copy
MicrosoftOneNote
Microsoft OneNote
MicrosoftStickyNotes
Microsoft Sticky Notes
MicrosoftTeams
Microsoft Teams
MicrosoftToDo
Microsoft To Do
MidnightCommander
Midnight Commander
MobaXTerm
MobaXTerm
MouseWithoutBorders
Mouse Without Borders
MstyDatabase
Msty is a UI to interact with large language models (LLMs)
MultiCommander
Multi Commander
Nessus
Nessus
NetMonitorforEmployeesProfessional
Net Monitor for Employees Pro
Notepad++
Notepad++ Backups, recently searched/replaced terms and recently opened documents
Notion
Notion Note-Taking App
OneCommander
One Commander
OneDrive_Metadata
Microsoft OneDrive Storage Metadata
OneDrive_UserFiles
Microsoft OneDrive Storage Files
OpenSSHClient
OpenSSH Client config, known hosts and keys
OpenSSHServer
OpenSSH Server Config and Logs
OpenVPNClient
OpenVPN Client Config and Log
OutlookPSTOST
Outlook PST and OST files
PDQDeploy
PDQ Deploy database
PaloAlto
Palo Alto Networks GlobalProtect VPN logs
PeaZip
PeaZip
ProtonVPN
ProtonVPN
PulseSecure
Pulse Secure
Q-Dir
Q-Dir
QFinderPro (QNAP)
QFinderPro (QNAP)
QlikSense
Qlik Sense
RDCMan
A Target to collect files that are related to RDCMan
Radmin
Radmin Server/Viewer Logs and Chats
RcloneConf
Rclone config file
Remcos
Remcos RAT
RemoteDesktopManager
A Target to collect files that are related to Remote Desktop Manager from Devolutions
RemoteUtilities_app
Remote Utilities
Robo-FTP
Robo-FTP
RustDesk
RustDesk
ScreenConnect
ScreenConnect Data (now known as ConnectWise Control)
Session
Session Desktop
ShareX
ShareX
SiemensTIA
Copy Siemens TIA Settings
Signal
Signal (Please view this tkape file for documentation on decryption!)
SimpleHelp
SimpleHelp Remote Access Client
Skype
Skype
Slack
Slack
Snagit
Snagit
SoftPerfectNetscan
Soft Perfect Network Scanner Output
SpeedCommander
SpeedCommander
Splashtop
Splashtop
Steam
Steam
SublimeText
Sublime Text 2/3/4 Auto Save Session
SugarSync
SugarSync
SumatraPDF
SumatraPDF
SupremoRemoteDesktop
Supremo Remote Desktop Control Logs
Syncthing
Syncthing Configuration and Logs
TablacusExplorer
Tablacus Explorer
TeamViewerLogs
TeamViewer Logs
Telegram
Telegram Desktop
TeraCopy
TeraCopy log history
Thunderbird
Mozilla Thunderbird Email Client
TotalCommander
Total Commander
TreeSize
TreeSize - Scan History
UEMS
UEMS Manage Engine Agent
Ultraviewer
UltraViewer
VLC Media Player
VLC Media Player
VMwareInventory
VMware - Virtual Machine Inventory
VMwareMemory
VMware - Virtual Machine Memory
VNCLogs
VNC Logs
Viber
ViberPC Messaging App
VirtualBoxConfig
Collects VirtualBox configuration files
VirtualBoxLogs
Collects VirtualBox log files
VirtualBoxMemory
VirtualBox - Memory
VisualStudioCode
Visual Studio Code artifacts
WhatsApp Local Files
WhatsApp_Media
WhatsApp Shared Media Files
WinSCP
WinSCP
WindowsYourPhone
Windows Your Phone
XYplorer
XYplorer
Xeox
Xeox Application Logs
ZScaler
Zscaler Logs
ZohoAssist
Zoho Assist artifacts
Zoom
Zoom client artifacts
iTunesBackup
iTunes Backups
mIRC
mIRC
mRemoteNG
mRemoteNG
pCloudDatabase
pCloud Database
360SecureBrowser
360 Secure Browser
Arc
Arc Browser
BraveBrowser
Brave Browser
BrowserCache
Browser Caches
Chrome
Chrome
ChromeExtension_Metadata
Chrome Browser Extension Metadata
ChromeExtensions
Chrome Extension Files
ChromeFileSystem
Chrome HTML5 File System Contents
CocCoc
CocCoc Browser
Edge
Edge
EdgeChromium
Microsoft Edge Chromium Artifacts
EdgeChromiumExtensions
Edge Chromium Extension Files
Firefox
Firefox
InternetExplorer
Internet Explorer
Opera
Opera
PrismaAccessBrowser
Prisma Access Browser
PuffinSecureBrowser
Puffin Secure Browser
QQBrowser
QQ Browser
Supermium
Supermium
UCBrowser
UCBrowser
Vivaldi
Vivaldi Artifacts
WaveBrowser
WaveBrowser
Yandex
Yandex Artifacts
BasicCollection
Basic Collection
SANS_Triage
SANS Triage Collection
Antivirus
Antivirus
CloudStorage_All
Cloud Storage Contents and Metadata
CloudStorage_Metadata
Cloud Storage Metadata
CloudStorage_OneDriveExplorer
OneDrive and other files used with OneDriveExplorer
CombinedLogs
Collect Event logs, Trace logs, Windows Firewall, PowerShell console logs, and .NET CLR UsageLogs
EvidenceOfExecution
Evidence of execution related files
Exchange
Exchange Log Files
FTPClients
FTP Clients
FileExplorerReplacements
File Explorer Replacements
FileSystem
File system metadata
IRCClients
IRC Clients
KapeTriage
KapeTriage collects most of the files needed for a DFIR Investigation. This Target pulls evidence from File System files, Registry Hives, Event Logs, Scheduled Tasks, Evidence of Execution, SRUM data, SUM data, Cloud metadata, WER, WBEM, Web Browser data (IE/Edge, Chrome, Mozilla history), LNK Files, JumpLists, Notepad unsaved sessions (Win11), 3rd party remote access software logs, 3rd party antivirus software logs, Windows 10/11 Timeline database, and $I Recycle Bin files.
MessagingClients
Messaging and communication apps
MiniTimelineCollection
MFT, Registry and Event Logs to generate a mini timeline
NetworkScanner
Network Scanner Tools
P2PClients
P2P Clients
ProgramExecution
Program Execution Triage Collection
RecycleBin
Recycle Bin DataAndInfo
RegistryHives
System and user related Registry hives
RemoteAdmin
Composite target for files related to remote administration tools
SOFELK
SOF-ELK related files of interest
SQLiteDatabases
SQLDatabases Target for use with SQLECmd Module
ServerTriage
A compound target for gathering artifacts common to servers.
TorrentClients
Torrent Clients
USBDetective
Collects files that can be input into USB Detective for parsing
UsenetClients
Usenet Clients
VMware
Runs all VMware modules to collect VMware VM config files, logs and Virtual Hard Disks
VPNClients
VPN Clients
VirtualBox
Runs all VirtualBox modules to collect Virtualbox VM config files, logs and Virtual Hard Disks
WSL
All Windows Subsystem for Linux targets
WebBrowsers
Web browser history, bookmarks, etc.
WebServers
Logs from all known web server applications and supporting services
BitTorrent
BitTorrent
DC++
DC++
Freenet
Freenet
FrostWire
FrostWire
Gigatribe
Gigatribe Files
NZBGet
NZBGet
NewsbinPro
Newsbin Pro
Newsleecher
Newsleecher
Nicotine++
Nicotine++
SABnbzd
SABnbzd
Shareaza
Shareaza
Soulseek
Soulseek
Torrents
Torrent Files
Usenet
Usenet (NZB) Files
eMule
eMule
qBittorrent
qBittorrent
uTorrent
uTorrent
$Bitmap
$Bitmap
$Boot
$Boot
$J
$J
$LogFile
$LogFile
$MFT
$MFT
$MFTMirr
$MFTMirr
$SDS
$SDS
$T
$T
ActiveDirectoryNTDS
Active Directory NTDS
ActiveDirectorySysvol
Active Directory Sysvol
Amcache
Amcache.hve
AppCompatPCA
AppCompat PCA Folder
AppXPackages
AppXPackages
ApplicationEvents
Windows Application Event Log
BCD
Boot Configuration Files
BITS
Microsoft BITS (Background Intelligent Transer Service) persistent files
CapabilityAccessManager
Capability Access Manager database
CertUtil
Certutil
Drivers
Windows Drivers
EncapsulationLogging
EncapsulationLogging
EventLogs-RDP
Collect Win7+ RDP related Event logs
EventLogs
Event logs
EventTraceLogs
Event Trace Logs
EventTranscriptDB
EventTranscript.db (and other files related to Telemetry and Diagnostic Data)
ExchangeClientAccess
Exchange Client Access Log Files
ExchangeCve-2021-26855
Exchange Server Vulnerability *.Compiled Files
ExchangeSetupLog
Exchange Setup Log
ExchangeTransport
Exchange Transport Log Files
GroupPolicy
Current Group Policy Enforcement
HostsFile
Hosts file
IISConfiguration
IIS
IconCacheDB
IconCache.db files
JumpLists
Jump lists
LNKFilesAndJumpLists
LNK Files and jump lists
LinuxOnWindowsProfileFiles
Linux on Windows Profile Files
LogFiles
LogFiles (includes SUM)
MOF
MOF files (WMI)
MemoryFiles
Memory Files
MicrosoftOfficeBackstage
Microsoft Office Backstage
NETCLRUsageLogs
.NET CLR UsageLogs
Notepad
A Target to collect files that are currently open in Notepad (Windows 11+)
OfficeAutosave
Office Autosave
OfficeDiagnostics
Office Diagnostics
OfficeDocumentCache
Office Document Cache
PerfLogs
Perflogs Folder Copy
PowerShell7Config
PowerShell 7 Runtime Config
PowerShellTranscripts
PowerShell Transcripts
Prefetch
Prefetch files
ProgramData
ProgramData Folder Copy
PushNotification
Windows Push Notification Service
QuickAssist
Microsoft Quick Assist/Remote Help
RDPCache
RDP Cache Files
RDPJumplist
RDP Jumplist Files
RDPLogs
RDP Logs
RecentFileCache
RecentFileCache
RecentFolders
Recent Folders LNK files
RecycleBin_DataFiles
Recycle Bin Data Files
RecycleBin_InfoFiles
Recycle Bin Info Files
RegistryHivesMSIXApps
MSIX/APPX App Hives
RegistryHivesOther
Other Registry Hives
RegistryHivesSystem
System level/related Registry hives
RegistryHivesUser
User Related Registry hives
RoamingProfile
User Related Registry Hives, LNK files, etc
SCCMClientLogs
SCCM Client Log Files
SDB
Shim SDB FIles
SRUM
System Resource Usage Monitor (SRUM) Data
SUM
SUM Database
ScheduledTasks
Scheduled tasks (*.job and XML)
SignatureCatalog
Obtain detached signature catalog files
SnipAndSketch
Snip & Sketch Cached Images
SnippingTool
SnippingTools screenshots
StartupFolders
Startup Folders
StartupInfo
StartupInfo XML Files
Syscache
syscache.hve
ThumbCache
Thumbcache DB
USBDevicesLogs
USB devices log files
UsersFolders
Users folders Dump
VirtualDisks
Virtual Disks
WBEM
Web-Based Enterprise Management (WBEM)
WER
Windows Error Reporting
WindowsApp
WindowsApp Logs
WindowsCopilotRecall
Windows Copilot+ Recall
WindowsFirewall
Windows Firewall Logs
WindowsHello
Windows Hello
WindowsIndexSearch
Windows Index Search
WindowsNetwork
Windows Networks settings
WindowsNotificationsDB
Windows 10 Notification DB
WindowsOSUpgradeArtifacts
Windows OS Upgrade Artifacts
WindowsPowerDiagnostics
Windows Power Diagnostics
WindowsServerDNSAndDHCP
Windows Server DNS and DHCP log files
WindowsTelemetryDiagnosticsLegacy
Legacy Windows Telemetry and Diagnostics files (*.rbs)
WindowsTimeline
ActivitiesCache.db collector
WindowsUpdate
Windows Update Logs
XPRestorePoints
XP Restore Points - System Volume Information directory