Kroll Artifact Parser And Extractor (KAPE)

Kroll's Artifact Parser and Extractor (KAPE) – created by Kroll senior director and three-time Forensic 4:cast DFIR Investigator of the Year Eric Zimmerman – lets forensic teams collect and process forensically useful artifacts within minutes. Get more information on KAPE, access training materials or book a live session with a Kroll expert here.

Download KAPE

Book Your Spot in the KAPE Intensive Training and Certification Virtual Session. Register Now.

With KAPE, you can find and prioritize the most critical systems to your case and collect key artifacts before imaging. This means no longer having to wait until full system images are gathered and then wading through data where typically less than 10% will have any forensic value.

"The gist of [KAPE] is that in as little as half an hour, we can go from disk imaging to substantive analysis of filesystem, shell, execution, event, and registry data."
Troy Larson, Microsoft


Purpose–Built to Expedite and Optimize Forensic Investigations

Predefined, continually updated targets and modules
Predefined, Continually Updated Targets and Modules
Actionable intelligence in minutes
Actionable Intelligence in Minutes
Standardize forensic processes
Standardize Forensic Processes
DFIR Investigator of the Year
Developed by 3x Forensic 4:cast DFIR Investigator of the Year
How KAPE Works

Introducing KAPE

Over 60 Predefined Targets and 90 Modules
Over 60 Predefined Targets and 90 Modules

KAPE has two primary phases – target collection and module execution:

  • Targets are essentially collections of file and directory specifications.
  • Modules are used to run programs, which can target anything, including files collected via targets as well as any other kinds of programs you may want to run on a system from a live response perspective.

KAPE gives you access to targets and modules for the most common operations required in forensic exams, helping investigators gather a wider range of artifacts in a fraction of the time, enriching evidentiary libraries.

Over 60 Predefined Targets and 90 Modules
Grouping Artifacts Expedites Triage
Grouping Artifacts Expedites Triage

KAPE focuses on collecting and processing relevant data quickly, grouping artifacts in categorized directories such as EvidenceOfExecution, BrowserHistory and AccountUsage. Grouping things by category means an examiner no longer needs to know how to process prefetch, shimcache, amcache, userassist, etc., as they relate to evidence of execution artifacts.

Grouping Artifacts Expedites Triage
Standardize Forensic Processes
Standardize Forensic Processes

When handling an incident, forensic examiners are tasked with knowing which artifacts to collect, where they may reside, and how to collect the data without damaging the evidence or chain of custody. With KAPE, forensic examiners have a solution to find, collect and process forensic artifacts in a way that standardizes forensic engagements by leveraging a wider range of extracted artifacts. KAPE can also help facilitate the onboarding and training of new investigators by standardizing and scaling artifact pulls.

Standardize Forensic Processes
Live KAPE Training with Kroll Experts
Live KAPE Training with Kroll Experts

Eric Zimmerman and a team of Kroll experts structured a hands-on course to lead forensic examiners to KAPE mastery, enabling federal agents, law enforcement personnel, first responders, digital forensic analysts and incident response team members to:

  • Understand the myriad applications of KAPE targets and modules
  • Explore the capabilities of KAPE’s graphical interface
  • Run a hands-on investigation lab to produce actionable intelligence in 15 minutes or less
  • Browse KAPE Training packages
Live KAPE Training with Kroll Experts

Virtual KAPE Training and Certification Events

KAPE Events

Kroll is now offering KAPE Virtual Intensive Training and Certification programs online. See below for a list of the upcoming events, more will be announced soon:

  • North America: April 13, June 20, September 26, December 7, 2023
  • EMEA: June 8 2023, October 5, 2023 

Register now

KAPE Events
Continually Evolving Dynamic Solution 

Kroll works on some of the most complex and highest profile cyber incidents in the world and performs digital forensics and evidence collection for thousands of companies. This unique frontline insight from our experts is enhanced by input from the global DFIR community to actively contribute to the development of KAPE. To learn more:

Clarifying KAPE Usage Permission
  • KAPE is free for any local, state, federal or international government agency.
  • KAPE is free for educational and research use.
  • KAPE is free for internal company use.
  • KAPE requires a enterprise license when used on a third-party network and/or as part of a paid engagement.

Read more about KAPE enterprise licenses here.

Download KAPE
This field is required
This field is required
This field is required
This field is required
This field is required A valid email address is required
Please select an Option
This field is required
We will use this information to respond to your inquiry and process your data in accordance with our privacy policy.

Increased Cyber Resilience with a Cyber Risk Retainer

Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.

See all servicesStay Ahead with Kroll


Valuation of businesses, assets and alternative investments for financial reporting, tax and other purposes.

Compliance and Regulation

End-to-end governance, advisory and monitorship solutions to detect, mitigate and remediate security, legal, compliance and regulatory risk.

Corporate Finance and Restructuring

Middle Market M&A, Strategic Advisory, Debt Advisory and Private Capital Markets, Restructuring and Insolvency Services, Financial Due Diligence, Fairness Opinions, Solvency Opinions and ESOP/ERISA Advisory.

Cyber Risk

Incident response, digital forensics, breach notification, managed detection services, penetration testing, cyber assessments and advisory.

Environmental, Social and Governance

Advisory and technology solutions, including policies and procedures, screening and due diligence, disclosures and reporting and investigations, value creation, and monitoring.

Investigations and Disputes

World-wide expert services and tech-enabled advisory through all stages of diligence, forensic investigation, litigation, disputes and testimony.

Business Services

Expert provider of complex administrative solutions for capital events globally. Our services include claims and noticing administration, debt restructuring and liability management services, agency and trustee services and more.


KAPE Quarterly Update – Q4 2022

Feb 06, 2023

by Eric ZimmermanAndrew Rathbun


Live from Davos – Cyber in 2023: Geopolitical and Economic Risks

Jan 16, 2023

by Jason N. SmolanoffMegan  Greene


Q3 2022 Threat Landscape: Insider Threat, The Trojan Horse of 2022

Nov 08, 2022

by Laurie IaconoKeith Wojcieszek George Glass

Incident Response

State of Incident Response: APAC

Oct 31, 2022

Press Release

Kroll Responder Recognized in 2023 Gartner Market Guide for Managed Detection and Response Services for the Third Consecutive Year

Mar 23, 2023


Kroll Launches Cyber Partner Program Delivering Lifetime Returns

Feb 28, 2023


Kroll Named an MDR “Champion” by Bloor Research

Feb 27, 2023

Press Release

Gartner Names Kroll a Representative Vendor for Managed Security Incident and Event Management

Jan 09, 2023


Kroll at RSA Conference 2023

Conference Conference Apr 24 - Apr 27, 2023 | Conference


KAPE Intensive Training and Certification

Online Event Online Event Apr 13 - Dec 07, 2023 | Online Event