Agent skill

Triaging Windows With Kape

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping…

Apache-2.0Auto-check passedSecurity

Install Triaging Windows With Kape

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-windows-with-kape -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills triaging-windows-with-kape --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/triaging-windows-with-kape .claude/skills/triaging-windows-with-kape && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triaging-windows-with-kape
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
941 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping…

  • Works in 9 steps: Sync configurations and update binaries → Inventory available Targets and Modules → Collect a triage target set → …
  • Security work in your project
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Triaging Windows With Kape is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping Eric Zimmerman's EZ Tools (PECmd, MFTECmd, RECmd). Use during early incident containment/triage when full disk imaging is impractical but a defensible, parseable Windows artifact set is needed quickly, including at-scale remote collection.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/triaging-windows-with-kape”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Sync configurations and update binaries
  2. Inventory available Targets and Modules
  3. Collect a triage target set
  4. Include Volume Shadow Copies
  5. Package the collection as a container with hashing
  6. Process the collection with Modules
  7. One-shot collect + parse
  8. Build a batch-mode _kape.cli for fleet deployment
  9. Verify integrity

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • kroll.com
    • ericzimmerman.github.io
    • github.com
    • sans.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triaging Windows With Kape loads about 2.3k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 941 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 941 words, ~2,299 tokens.

Download SKILL.mdSave it as .claude/skills/triaging-windows-with-kape/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
triaging-windows-with-kape
description
Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping Eric Zimmerman's EZ Tools (PECmd, MFTECmd, RECmd). Use during early incident containment/triage when full disk imaging is impractical but a defensible, parseable Windows artifact set is needed quickly, including at-scale remote collection.
domain
cybersecurity
subdomain
digital-forensics
tags
digital-forensics, kape, triage, artifact-collection, incident-response, eric-zimmerman, dfir, windows-forensics
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03
mitre_attack
T1005

Triaging Windows with KAPE

Authorized Use Only: KAPE collects forensic artifacts from systems. Only run KAPE against systems you own or are explicitly authorized in writing to acquire and analyze. Preserve chain of custody and follow your organization's evidence-handling procedures.

Overview

KAPE (Kroll Artifact Parser and Extractor) is a free, Windows-native triage tool authored by Eric Zimmerman and distributed by Kroll. It performs two distinct phases controlled by separate configuration sets:

  • Targets (.tkape files) define what to collect. KAPE uses the raw NTFS file system (via direct volume access) to copy locked/in-use files such as registry hives, $MFT, event logs, prefetch, browser databases, and LNK files without triggering anti-tamper protections. Targets can be chained into "compound" targets (for example KapeTriage, !SANS_Triage) that pull a forensically rich subset in minutes.
  • Modules (.mkape files) define how to process collected (or live) data. Modules wrap external binaries — primarily Eric Zimmerman's tools (PECmd, MFTECmd, RECmd, etc.) — and emit normalized CSV/JSON output. The !EZParser compound module runs the full EZ Tools suite against a target collection.

KAPE ships with both a CLI (kape.exe) and a GUI front end (gkape.exe). Because of its speed, KAPE lets responders prioritize which hosts warrant deep forensic imaging, making it a cornerstone of modern remote/at-scale DFIR triage.

When to Use

  • During the early containment/triage phase of an incident when you need execution, persistence, and account artifacts from one or many hosts quickly.
  • When full disk imaging is impractical (large disks, remote sites, time pressure) but you still need a defensible, parseable artifact set.
  • When automating collection across a fleet via remote execution (PSExec, EDR live response, SOAR) using batch-mode _kape.cli files.
  • When you need to collect from Volume Shadow Copies to recover historical artifact states.

Prerequisites

  • Windows host (KAPE runs on Windows; EZ Tools modules require the .NET runtime bundled with the tools).
  • Download KAPE from the official source (free, registration required): https://www.kroll.com/kape
  • Administrator privileges (required for raw volume access and VSS).
  • Update Targets, Modules, and the bundled binaries:
    cmd
    REM From the KAPE directory, sync community Targets/Modules from GitHub
    kape.exe --sync
    
    REM Download/update the EZ Tools binaries that Modules invoke
    Get-KAPEUpdate.ps1
  • A clean, write-protected destination (external drive or network share) separate from the evidence source.

Objectives

  • Collect a forensically sound triage artifact set from a target volume.
  • Optionally include Volume Shadow Copies for historical recovery.
  • Package output as a VHDX/ZIP container with hashing for chain of custody.
  • Run modules to parse the collection into analyst-ready CSV/JSON.
  • Build a repeatable batch-mode collection for fleet deployment.

MITRE ATT&CK Mapping

IDOfficial Technique NameRelevance to this skill
T1005Data from Local SystemKAPE reads artifacts directly from the local file system; defenders use the same capability to forensically acquire that data for analysis.

KAPE is a defensive DFIR tool. The mapping reflects the data-source artifacts (local file system) that adversary actions leave behind and that KAPE preserves for investigation.

Workflow

1. Sync configurations and update binaries

Always work from current Targets/Modules and EZ Tools binaries so parsers match the latest artifact formats.

cmd
cd C:\KAPE
kape.exe --sync
2. Inventory available Targets and Modules

List what is available before building a collection so you scope precisely.

cmd
REM Show all Targets
kape.exe --tlist

REM Show all Modules
kape.exe --mlist
3. Collect a triage target set

Targets require the three switches --tsource, --target, and --tdest. --tflush clears the destination first. Use a compound target such as KapeTriage for a fast, broad pull.

cmd
kape.exe --tsource C: ^
         --target KapeTriage ^
         --tdest E:\kape_out\HOST01\tdest ^
         --tflush
4. Include Volume Shadow Copies

Add --vss to also process every VSS snapshot on the source volume, recovering historical artifact states.

cmd
kape.exe --tsource C: ^
         --target !SANS_Triage ^
         --tdest E:\kape_out\HOST01\tdest ^
         --vss --tflush
Show full SKILL.md (392 more words)Show less
5. Package the collection as a container with hashing

--vhdx (or --zip) wraps the output into a single mountable/transportable container. --vhdx takes a base name (an identifier), NOT a filename. KAPE writes a console log and copy log you should retain.

cmd
kape.exe --tsource C: ^
         --target KapeTriage ^
         --tdest E:\kape_out\HOST01\tdest ^
         --vhdx HOST01 --tflush --gui
6. Process the collection with Modules

Modules require --module and --mdest. Point --msource at the collected target output and run !EZParser to parse everything into CSV/JSON.

cmd
kape.exe --msource E:\kape_out\HOST01\tdest\C ^
         --mdest E:\kape_out\HOST01\mdest ^
         --module !EZParser ^
         --mflush
7. One-shot collect + parse

You can collect and process in a single invocation by supplying both Target and Module switches.

cmd
kape.exe --tsource C: ^
         --target KapeTriage ^
         --tdest E:\kape_out\HOST01\tdest ^
         --mdest E:\kape_out\HOST01\mdest ^
         --module !EZParser ^
         --tflush --mflush --vss
8. Build a batch-mode _kape.cli for fleet deployment

KAPE reads a _kape.cli file (one argument set per line) placed next to kape.exe and executes each line in sequence — ideal for pushing identical collection via EDR/PSExec. Generate the exact CLI from the GUI's "Copy command line" button, then drop it into _kape.cli.

cmd
REM Contents of _kape.cli (each line = one full KAPE run):
--tsource C: --target KapeTriage --tdest %%d\Disk\%%m --vhdx %%m --zv false

%%d resolves to the KAPE directory and %%m to the machine name, so a single CLI auto-names output per host. Launch by running kape.exe with no arguments.

9. Verify integrity

Confirm KAPE's CopyLog, ConsoleLog, and SkipLog CSVs are present in the target output, and validate the SHA-1 hashes KAPE records for each copied file against the source where possible.

Tools and Resources

ResourcePurposeLink
KAPE downloadOfficial Kroll distribution (free)https://www.kroll.com/kape
KAPE DocumentationMDwiki docs for switches and confighttps://ericzimmerman.github.io/KapeDocs/
KapeFiles repoCommunity Targets and Moduleshttps://github.com/EricZimmerman/KapeFiles
EZ ToolsParsers invoked by KAPE Moduleshttps://ericzimmerman.github.io/
KAPE on SANSBackground, history, methodologyhttps://www.sans.org/tools/kape/

Key Switches

SwitchPhasePurpose
--tsourceTargetSource volume/drive to collect from
--targetTargetTarget or compound target name
--tdestTargetDestination for collected files
--tflushTargetEmpty --tdest before collecting
--vssTargetProcess all Volume Shadow Copies
--vhdx / --zipTargetPackage output into a container (base name)
--moduleModuleModule or compound module name
--msourceModuleSource data for module processing
--mdestModuleDestination for parsed output
--mflushModuleEmpty --mdest before processing
--syncBothUpdate Targets/Modules from GitHub
--tlist / --mlistBothList available Targets / Modules

Validation Criteria

  • KAPE Targets/Modules and EZ Tools binaries synced to current versions
  • Triage target collected with --tsource, --target, --tdest
  • Volume Shadow Copies included where historical state is needed
  • Output packaged as VHDX or ZIP for transport/chain of custody
  • CopyLog/ConsoleLog/SkipLog present and reviewed
  • Modules run (!EZParser) producing CSV/JSON in --mdest
  • File hashes recorded and verified against source
  • Batch _kape.cli validated for fleet deployment where applicable

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/triaging-windows-with-kape of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Triaging Windows With Kape next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triaging Windows With Kape compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triaging Windows With Kape this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Triaging Windows With Kape

What does Triaging Windows With Kape do?

Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping…. Triaging Windows With Kape is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping Eric Zimmerman's EZ Tools (PECmd, MFTECmd, RECmd).

When should I use Triaging Windows With Kape?

Triaging Windows With Kape fits situations like: security work in your project.

How do I install Triaging Windows With Kape in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-windows-with-kape -a claude-code`. Or copy the skill folder (skills/triaging-windows-with-kape in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/triaging-windows-with-kape in your project. Claude Code loads it when a task matches its description.

How do I install Triaging Windows With Kape in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-windows-with-kape -a codex`. Or copy the skill folder (skills/triaging-windows-with-kape in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/triaging-windows-with-kape in your project. Codex loads it when a task matches its description.

Can I use Triaging Windows With Kape in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-windows-with-kape -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triaging-windows-with-kape, .gemini/skills/triaging-windows-with-kape, .github/skills/triaging-windows-with-kape and .opencode/skills/triaging-windows-with-kape in your project.

What does Triaging Windows With Kape need to run?

Going by SKILL.md and its folder, Triaging Windows With Kape needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Triaging Windows With Kape access the network?

SKILL.md names 4 domains. As links in the text: kroll.com, ericzimmerman.github.io, github.com and sans.org. This is read from the text; nothing was executed.

Is Triaging Windows With Kape safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triaging Windows With Kape use?

Triaging Windows With Kape is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triaging Windows With Kape use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Triaging Windows With Kape?

Skills that share tags, products or a category with Triaging Windows With Kape: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triaging Windows With Kape?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.