dfirhub

Triage Collections

38 pre-built KAPE compound targets for rapid forensic acquisition

Compound targets combine multiple individual targets into a single collection. Use these for comprehensive triage acquisition with a single KAPE command.

all collections (38)

RemoteAdmin

29

Composite target for files related to remote administration tools

by Drew Ervin, Mathias Frank, Andrew Rathbun, Phill Moore

Antivirus

27

Antivirus

by Andrew Rathbun

SANS_Triage

23

SANS Triage Collection

by Mark Hallman

KapeTriage

18

KapeTriage collects most of the files needed for a DFIR Investigation. This Target pulls evidence from File System files, Registry Hives, Event Logs, Scheduled Tasks, Evidence of Execution, SRUM data, SUM data, Cloud metadata, WER, WBEM, Web Browser data (IE/Edge, Chrome, Mozilla history), LNK Files, JumpLists, Notepad unsaved sessions (Win11), 3rd party remote access software logs, 3rd party antivirus software logs, Windows 10/11 Timeline database, and $I Recycle Bin files.

by Scott Downie

WebBrowsers

18

Web browser history, bookmarks, etc.

by Eric Zimmerman

BasicCollection

12

Basic Collection

by Phill Moore

FileExplorerReplacements

12

File Explorer Replacements

by Andrew Rathbun

ProgramExecution

12

Program Execution Triage Collection

by Max Zabuty

MessagingClients

11

Messaging and communication apps

by Gregor Wegberg

CloudStorage_All

8

Cloud Storage Contents and Metadata

by Chad Tilbury and Andrew Rathbun

CloudStorage_Metadata

7

Cloud Storage Metadata

by Chad Tilbury and Andrew Rathbun, Eric Capuano

CombinedLogs

7

Collect Event logs, Trace logs, Windows Firewall, PowerShell console logs, and .NET CLR UsageLogs

by Mike Cary, Mark Hallman added the USBDevicelogs target, Thomas DIOT (Qazeer) added the .NET CLR UsageLogs and PowerShell Transcripts target

FileSystem

6

File system metadata

by Eric Zimmerman

P2PClients

6

P2P Clients

by Andrew Rathbun

ServerTriage

6

A compound target for gathering artifacts common to servers.

by Eric Capuano

EvidenceOfExecution

5

Evidence of execution related files

by Eric Zimmerman

SOFELK

5

SOF-ELK related files of interest

by Tony Knutson and Andrew Rathbun

USBDetective

5

Collects files that can be input into USB Detective for parsing

by Kevin Pagano

VPNClients

5

VPN Clients

by Evangelos Dragonas - Paul CABON CERT Almond

WSL

5

All Windows Subsystem for Linux targets

by Matt Dawson

FTPClients

4

FTP Clients

by Andrew Rathbun

UsenetClients

4

Usenet Clients

by Andrew Rathbun

VirtualBox

4

Runs all VirtualBox modules to collect Virtualbox VM config files, logs and Virtual Hard Disks

by Matt Dawson

WebServers

4

Logs from all known web server applications and supporting services

by Eric Capuano

CloudStorage_OneDriveExplorer

3

OneDrive and other files used with OneDriveExplorer

by Brian Maloney

Exchange

3

Exchange Log Files

by Keith Twombley

IRCClients

3

IRC Clients

by Andrew Rathbun

MiniTimelineCollection

3

MFT, Registry and Event Logs to generate a mini timeline

by Mari DeGrazia

NetworkScanner

3

Network Scanner Tools

by Reece394

RegistryHives

3

System and user related Registry hives

by Eric Zimmerman

TorrentClients

3

Torrent Clients

by Andrew Rathbun

VMware

3

Runs all VMware modules to collect VMware VM config files, logs and Virtual Hard Disks

by Matt Dawson

RecycleBin

2

Recycle Bin DataAndInfo

by Mark Hallman / Joshua Hickman

Sophos

1

Sophos Data

by Drew Ervin, Reece394

Symantec_AV_Logs

1

Symantec AV Logs

by Brian Maloney

LogMeIn

1

LogMeIn Data

by Drew Ervin

ScreenConnect

1

ScreenConnect Data (now known as ConnectWise Control)

by Drew Ervin

VNCLogs

1

VNC Logs

by Phill Moore, Evangelos Dragonas