daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ez-tools-kape.md (27627B)


      1 ---
      2 title: "Eric Zimmerman Tools & KAPE"
      3 description: "The EZ Tools suite end to end: Get-ZimmermanTools install, KAPE targets and modules for triage collection, every *Cmd parser (MFTECmd, PECmd, LECmd, JLECmd, EvtxECmd, AmcacheParser, AppCompatCacheParser, SBECmd, SrumECmd, WxTCmd, RBCmd, SQLECmd, bstrings) with the artefact and the question it answers, then CSV into Timeline Explorer."
      4 category: dfir
      5 subcategory: "Windows"
      6 tags: [dfir, forensics, windows, ez-tools, kape, triage, timeline, mft, prefetch, evtx, amcache, shimcache, shellbags, lnk, jumplist, srum, registry]
      7 tools: ["KAPE / gkape", "Get-ZimmermanTools", "MFTECmd", "PECmd", "LECmd", "JLECmd", "EvtxECmd", "AmcacheParser", "AppCompatCacheParser", "SBECmd / ShellBags Explorer", "SrumECmd", "WxTCmd", "RBCmd", "SQLECmd", "bstrings", "Timeline Explorer", "Registry Explorer / RECmd", "EZViewer", "MFTExplorer", "Hasher"]
      8 difficulty: advanced
      9 updated: "2026-09-26"
     10 ---
     11 
     12 # Eric Zimmerman Tools & KAPE
     13 
     14 **Eric Zimmerman's tools** ("EZ Tools") are the free, open-source parsers that SANS FOR500 and most DFIR modules are built on: one small command-line tool per Windows artefact, all producing the same flat **CSV** that drops straight into **Timeline Explorer**. **KAPE** (Kroll Artifact Parser and Extractor) is the collector and orchestrator that sits in front of them: it copies the artefacts off a live box or mounted image in minutes (*targets*), then runs the parsers over the copy (*modules*). Learn the pattern once — `tool -f <artefact> --csv <out>` — and you know the whole suite. This card is the install, the KAPE triage command you will run on every case, then each parser with **what it reads** and **what question it answers**.
     15 
     16 > [!info] Where they come from
     17 > Everything here is at [ericzimmerman.github.io](https://ericzimmerman.github.io/#!index.md) (tools) and [kroll.com/kape](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape) (KAPE, free for non-commercial / internal use, registration required). Builds ship for **.NET 6** and **.NET 9**; grab the one matching the runtime on your analysis box. The `.NET 4` builds are gone.
     18 
     19 ## Install and update
     20 
     21 ```powershell
     22 # One script pulls every tool (and keeps them updated — rerun it monthly)
     23 Set-ExecutionPolicy Bypass -Scope Process
     24 iwr https://raw.githubusercontent.com/EricZimmerman/Get-ZimmermanTools/master/Get-ZimmermanTools.ps1 -OutFile Get-ZimmermanTools.ps1
     25 .\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZ -NetVersion 9        # or -NetVersion 6
     26 
     27 # Runtime the tools need
     28 winget install Microsoft.DotNet.DesktopRuntime.9                # GUI tools (Registry/Timeline/ShellBags Explorer)
     29 winget install Microsoft.DotNet.Runtime.9                       # CLI tools
     30 
     31 # KAPE lives separately (download from Kroll, unzip anywhere — it is portable)
     32 #   C:\Tools\KAPE\kape.exe      CLI
     33 #   C:\Tools\KAPE\gkape.exe     GUI that builds the CLI command for you
     34 # Point KAPE at the EZ tools once: copy them into C:\Tools\KAPE\Modules\bin\
     35 Copy-Item C:\Tools\EZ\net9\*.exe C:\Tools\KAPE\Modules\bin\ -Force
     36 # Update KAPE's targets/modules from the community repo
     37 C:\Tools\KAPE\kape.exe --sync
     38 ```
     39 
     40 Add `C:\Tools\EZ\net9` to `PATH` and every example below works as written. Every tool answers `--help`; the `--csv` output flag and `-q` (quiet) are common to almost all.
     41 
     42 > [!tip] Linux / macOS analyst box
     43 > The CLI tools run under the Linux .NET runtime too (`dotnet MFTECmd.dll ...`, or the native builds the script fetches with `-NetVersion 9`). The GUI tools (Timeline Explorer, Registry Explorer) are Windows-only — keep a Windows VM for those, or use `xsv`/`qsv`/`visidata` on the CSVs.
     44 
     45 ## The mental model
     46 
     47 ```text
     48                  collect                          parse                          review
     49  live box  ──►  KAPE --target  ──►  copy of artefacts  ──►  KAPE --module / *Cmd  ──►  CSV  ──►  Timeline Explorer
     50  or image        (files only,        (tree mirrors C:\,     (MFTECmd, PECmd, ...)         (one per artefact)   (filter, tag,
     51                  timestamps kept)     or a VHDX)                                                                  pivot on time)
     52 ```
     53 
     54 | Layer | Tool | Rule of thumb |
     55 |---|---|---|
     56 | Collection | KAPE **targets** (`.tkape`) | *What files to copy.* Compound targets like `!SANS_Triage`, `KapeTriage`, `!BasicCollection` bundle dozens of single targets |
     57 | Processing | KAPE **modules** (`.mkape`) | *What command to run over them.* `!EZParser` runs every EZ tool; other modules wrap Hayabusa, Chainsaw, Plaso, hindsight, etc. |
     58 | Parser | the `*Cmd` tools | One artefact type each, all → CSV/JSON |
     59 | Review | Timeline Explorer | The CSV viewer that understands the EZ column names (timestamps sort, colour, group) |
     60 
     61 ## KAPE
     62 
     63 ### The triage command you will actually run
     64 
     65 ```bat
     66 :: Live box, collecting from C:, output to your USB (E:), then parse everything
     67 kape.exe --tsource C: --tdest E:\case042\tout --target !SANS_Triage --tflush ^
     68          --msource E:\case042\tout --mdest E:\case042\mout --module !EZParser --mflush ^
     69          --gui
     70 
     71 :: Same, but pack the collection into a VHDX (one file, keeps ACLs/timestamps, mounts anywhere)
     72 kape.exe --tsource C: --tdest E:\case042\tout --target KapeTriage --vhdx HOST-042 --zv false
     73 
     74 :: From a mounted image instead of a live box (F: is the mounted E01 / Arsenal Image Mounter letter)
     75 kape.exe --tsource F: --tdest E:\case042\tout --target !SANS_Triage --tflush
     76 
     77 :: Only parse an existing collection (you already ran the target, or someone sent you a triage zip)
     78 kape.exe --msource E:\case042\tout --mdest E:\case042\mout --module !EZParser --mflush
     79 ```
     80 
     81 | Flag | Meaning |
     82 |---|---|
     83 | `--tsource` / `--tdest` | source drive/dir to collect **from**, dir to copy **into** |
     84 | `--target X` | one or more targets, comma separated. `!` prefix = compound |
     85 | `--tflush` | empty `--tdest` first |
     86 | `--vhdx NAME` / `--vhd` / `--zip` | container for the collection instead of a loose tree |
     87 | `--vss` | also pull the same paths out of every Volume Shadow Copy (deleted/overwritten artefacts) |
     88 | `--tdd` | *target de-dupe* on hash when using `--vss` |
     89 | `--msource` / `--mdest` | dir to parse, dir for parser output |
     90 | `--module X` | modules to run; `!EZParser` = all EZ tools |
     91 | `--mef csv\|json\|html` | override module output format |
     92 | `--mvars key:val` | pass variables modules need (e.g. `--mvars computerName:HOST01`) |
     93 | `--gui` | open a window showing progress, leave console log |
     94 | `--debug` / `--trace` | verbose logging |
     95 | `--sync` | update targets/modules from GitHub (KapeFiles repo) |
     96 | `--tlist` / `--mlist` | list available targets / modules (`--tdetail` / `--mdetail` for contents) |
     97 
     98 > [!warning] Footprint and what KAPE is not
     99 > KAPE running on a live box **creates artefacts** (prefetch entry, `kape.exe` in Amcache/ShimCache, a ConsoleHost history line). Note the time you started it and exclude it in the timeline. It also pulls locked files (`$MFT`, hives, `$UsnJrnl`) through raw disk reads — it is not a bit-for-bit image and never will be; if you need one, [image first](/sheets/dfir/disk-imaging).
    100 
    101 ### Targets worth knowing
    102 
    103 | Target | Collects |
    104 |---|---|
    105 | `!SANS_Triage` | The FOR500/FOR508 set: `$MFT`, `$LogFile`, `$UsnJrnl`, registry hives + transaction logs, event logs, Prefetch, Amcache, LNK, Jump Lists, SRUM, WMI repository, scheduled tasks, PowerShell history, browser data, Recycle Bin, `$Extend` ... the 90% case |
    106 | `KapeTriage` | Similar scope, tuned for speed on IR engagements |
    107 | `!BasicCollection` | Lighter: hives, evtx, Prefetch, `$MFT`, LNK, Jump Lists |
    108 | `RegistryHives`, `EventLogs`, `Prefetch`, `LNKFilesAndJumpLists`, `Amcache`, `SRUM`, `WebBrowsers`, `PowerShellConsole`, `ScheduledTasks`, `WMI`, `RecycleBin`, `WindowsTimeline`, `SUM`, `Antivirus`, `RDPLogs`, `$MFT`, `$J`, `$LogFile`, `MemoryFiles` | single-purpose, mix as needed |
    109 | `ServerTriage`, `Exchange`, `IIS`, `MSSQL` | server roles |
    110 | `RemoteAdminTools` | AnyDesk, TeamViewer, ScreenConnect, Atera ... logs (ransomware cases) |
    111 
    112 ```bat
    113 kape.exe --tlist                    :: everything
    114 kape.exe --tdetail !SANS_Triage     :: exactly which .tkape files a compound target includes
    115 type "C:\Tools\KAPE\Targets\Compound\!SANS_Triage.tkape"
    116 ```
    117 
    118 ### Modules worth knowing
    119 
    120 | Module | Runs |
    121 |---|---|
    122 | `!EZParser` | every EZ CLI tool over the matching artefact, one CSV each in `mout\` sub-folders |
    123 | `!EZParser` output dirs | `FileSystem\` (MFTECmd), `ProgramExecution\` (PECmd, Amcache, ShimCache), `EventLogs\` (EvtxECmd), `Registry\` (RECmd batch), `FileFolderAccess\` (LECmd, JLECmd, SBECmd), `SRUMDatabase\`, `WindowsTimeline\`, `RecycleBin\` ... |
    124 | `Hayabusa`, `Chainsaw` | Sigma rule detection over the collected `.evtx` |
    125 | `Plaso_Timeline`, `MFTECmd_$MFT_Bodyfile` → `mactime` | full super-timeline |
    126 | `hindsight`, `BrowsingHistoryView` | browser history |
    127 | `Hasher`, `Sysinternals_Sigcheck`, `DensityScout` | hashing / sig / entropy over collected binaries |
    128 | `LogParser`, `EvtxECmd_RDP` | targeted event-log queries |
    129 
    130 ### gkape (GUI)
    131 
    132 Tick *Use Target options*, pick source/destination, tick targets in the tree (search box top right), tick *Use Module options*, pick `!EZParser`, and read the **command line box at the bottom** — that is the exact CLI it will run. Copy it into your notes; gkape is a command builder, nothing more.
    133 
    134 ## The parsers, one artefact at a time
    135 
    136 Every EZ CLI tool accepts `-f <file>` or `-d <directory>`, `--csv <outdir>` (add `--csvf name.csv` to fix the filename), `--json <outdir>`, `-q` to suppress per-record console output, `--dt "yyyy-MM-dd HH:mm:ss.fffffff"` to change the timestamp format, and `--debug`. Timestamps are **UTC** unless you pass `--tz`. Paths below assume a KAPE collection under `E:\case042\tout\C\`.
    137 
    138 ### MFTECmd — `$MFT`, `$J` (USN journal), `$LogFile`, `$Boot`, `$SDS`
    139 
    140 *Every file that ever existed (until the record is reused), with all eight timestamps.* The backbone of any timeline.
    141 
    142 ```bat
    143 :: Parse the MFT — one row per file/dir, $STANDARD_INFORMATION and $FILE_NAME timestamps side by side
    144 MFTECmd.exe -f "E:\case042\tout\C\$MFT" --csv E:\case042\mout\mft --csvf mft.csv
    145 
    146 :: Include the $FILE_NAME-only timestamps too (timestomp detection) and the resident data / ADS
    147 MFTECmd.exe -f "$MFT" --csv out --fl --at
    148 
    149 :: Bodyfile for mactime / plaso (drive letter for the paths)
    150 MFTECmd.exe -f "$MFT" --body out --bodyf mft.body --bdl C
    151 
    152 :: One entry in full detail (entry number 0x1A5 or decimal), including data runs
    153 MFTECmd.exe -f "$MFT" --de 421
    154 MFTECmd.exe -f "$MFT" --de 421 --dr
    155 
    156 :: USN journal: what happened to files (create/delete/rename/overwrite) with the MFT to resolve full paths
    157 MFTECmd.exe -f "E:\case042\tout\C\$Extend\$J" -m "E:\case042\tout\C\$MFT" --csv out --csvf usn.csv
    158 
    159 :: $LogFile (NTFS transaction log) and $Boot / $SDS (security descriptors)
    160 MFTECmd.exe -f "$LogFile" --csv out
    161 MFTECmd.exe -f "$Boot"    --csv out
    162 MFTECmd.exe -f "$SDS"     --csv out
    163 
    164 :: Pull from volume shadow copies too (needs --vss and admin, live or mounted image)
    165 MFTECmd.exe -f "F:\$MFT" --csv out --vss
    166 ```
    167 
    168 > [!tip] Reading the MFT CSV in Timeline Explorer
    169 > `Created0x10` / `LastModified0x10` etc. are `$STANDARD_INFORMATION` (what Explorer shows, **user-space tools can change these**). `Created0x30` etc. are `$FILE_NAME` (kernel-set, much harder to fake). Filter `SI<FN` = **true** to find files whose visible timestamps predate their filename record — classic **timestomping**. `InUse` = false → deleted but record not yet reused. `HasAds` → alternate data streams; `ZoneIdContents` gives the download URL from `Zone.Identifier`.
    170 
    171 ### PECmd — Prefetch (`C:\Windows\Prefetch\*.pf`)
    172 
    173 *Which executables ran, when (last 8 run times on Win8+), how many times, and which files/volumes they touched in the first ~10 s.*
    174 
    175 ```bat
    176 PECmd.exe -d "E:\case042\tout\C\Windows\Prefetch" --csv out -q
    177 PECmd.exe -f "E:\case042\tout\C\Windows\Prefetch\MIMIKATZ.EXE-1A2B3C4D.pf"
    178 PECmd.exe -d Prefetch --csv out -k "temp,appdata,downloads,users\\public"   :: highlight rows whose loaded files match keywords
    179 PECmd.exe -d Prefetch --csv out --vss                                       :: shadow copies too
    180 PECmd.exe -d Prefetch --json out
    181 ```
    182 
    183 Output is two CSVs: `*_PECmd_Output.csv` (one row per `.pf`: exe, run count, last run + 7 previous, volume serials) and `*_PECmd_Output_Timeline.csv` (one row **per run**, ready to merge into a timeline). Hash in the filename changes with the path the exe ran from — two `CMD.EXE-xxxx.pf` files = cmd launched from two locations. Prefetch is **off by default on servers and SSD-tuned boxes**; check `HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher` before concluding "never ran".
    184 
    185 ### LECmd — LNK shortcut files
    186 
    187 *Files the user opened (Recent), with the target's path, size, timestamps, volume serial, and the MAC address / hostname of the machine the LNK was made on.*
    188 
    189 ```bat
    190 LECmd.exe -d "E:\case042\tout\C\Users\bob\AppData\Roaming\Microsoft\Windows\Recent" --csv out -q
    191 LECmd.exe -d "E:\case042\tout\C\Users" --csv out -q --all       :: every .lnk under every profile (Desktop, Start Menu, ...)
    192 LECmd.exe -f suspicious.lnk --mp                                :: more precise timestamps; also dumps the full structure
    193 LECmd.exe -d Recent --csv out --neb                             :: include LNKs with no TargetIDList/ExtraBlocks (rare edge cases)
    194 ```
    195 
    196 `TargetCreated`/`TargetModified`/`TargetAccessed` are the **target file's** timestamps at LNK creation; `SourceCreated/Modified` are the LNK's own = first/last time the file was opened. `MachineID`/`MacAddress` place a USB-carried LNK on a specific host. Phishing LNKs: check `Arguments` for `powershell -enc`, and `WorkingDirectory`.
    197 
    198 ### JLECmd — Jump Lists (Automatic + Custom Destinations)
    199 
    200 *Per-application recent items — Word documents, RDP hosts (mstsc), Explorer folders — surviving longer than Recent LNKs.*
    201 
    202 ```bat
    203 JLECmd.exe -d "E:\case042\tout\C\Users\bob\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv out -q
    204 JLECmd.exe -d "...\Recent\CustomDestinations" --csv out -q
    205 JLECmd.exe -d Recent --csv out -q --ld                :: include full LNK detail per entry
    206 JLECmd.exe -d Recent --csv out -q --withDir           :: dump the embedded LNKs to disk
    207 JLECmd.exe -f "5f7b5f1e01b83767.automaticDestinations-ms" --fd     :: full dump of one list
    208 ```
    209 
    210 The filename hash is the **AppID**: `5f7b5f1e01b83767` = Quick Access, `9b9cdc69c1c24e2b` = Notepad, `f01b4d95cf55d32a` = Explorer, `1b4dd67f29cb1962` = Windows Explorer pinned. JLECmd resolves the known ones for you (`AppIdDescription` column). RDP jump list (`mstsc.exe`, `{...}`) lists every hostname/IP the user connected to.
    211 
    212 ### EvtxECmd — Event logs (`.evtx`)
    213 
    214 *The normalised event log view: every EVTX in one CSV with a `MapDescription` and a `PayloadData1..6` extraction of the fields that matter (user, IP, process, service name), courtesy of community maps.*
    215 
    216 ```bat
    217 :: Update the maps first — they turn raw XML into "Logon: user X from IP Y"
    218 EvtxECmd.exe --sync
    219 
    220 :: All logs from a collection
    221 EvtxECmd.exe -d "E:\case042\tout\C\Windows\System32\winevt\Logs" --csv out --csvf evtx.csv
    222 
    223 :: Only the IDs you care about, in a date window
    224 EvtxECmd.exe -d Logs --csv out --inc 4624,4625,4634,4648,4672,4688,4698,4720,4732,7045,1102 ^
    225              --sd "2026-09-20 00:00:00" --ed "2026-09-27 00:00:00"
    226 
    227 :: Exclude noise
    228 EvtxECmd.exe -d Logs --csv out --exc 5156,5158,4689
    229 
    230 :: Single log, JSON for jq / SIEM ingestion
    231 EvtxECmd.exe -f Security.evtx --json out
    232 EvtxECmd.exe -f Security.evtx --xml out                 :: original XML per event
    233 
    234 :: Live system (admin)
    235 EvtxECmd.exe -d C:\Windows\System32\winevt\Logs --csv E:\case042\live-evtx --vss
    236 ```
    237 
    238 Key columns: `TimeCreated`, `EventId`, `Channel`, `Computer`, `UserId`, `MapDescription`, `PayloadData1-6` (mapped fields), `RemoteHost`, `ExecutableInfo`, `Payload` (full XML). Sort by time, filter `MapDescription` — this is how you find the 4624 type 10 from the odd IP in minutes. The Event ID table lives in the [Digital Forensics reference](/sheets/dfir/forensics). For Sigma-rule detection over the same files use **Hayabusa** / **Chainsaw** (KAPE modules exist for both).
    239 
    240 ### AmcacheParser — `Amcache.hve`
    241 
    242 *Every executable and driver the system inventoried — full path, **SHA-1 of the first 31 MB**, publisher, compile time, first-seen time. Survives the binary being deleted.*
    243 
    244 ```bat
    245 AmcacheParser.exe -f "E:\case042\tout\C\Windows\appcompat\Programs\Amcache.hve" --csv out
    246 AmcacheParser.exe -f Amcache.hve --csv out -i          :: include only unassociated file entries (executables not tied to an installed program) — the malware view
    247 AmcacheParser.exe -f Amcache.hve --csv out -w known-good.txt   :: whitelist of SHA-1s to drop
    248 AmcacheParser.exe -f Amcache.hve --csv out -b iocs.txt          :: blacklist: flag matches
    249 ```
    250 
    251 Outputs several CSVs: `*_UnassociatedFileEntries` (the interesting one), `*_AssociatedFileEntries`, `*_ProgramEntries`, `*_DriverBinaries`, `*_ShortCuts`, `*_DeviceContainers`/`*_DevicePnps` (USB devices!). `FileKeyLastWriteTimestamp` ≈ first execution / first seen (not exact). Throw the SHA-1 column at VirusTotal.
    252 
    253 ### AppCompatCacheParser — ShimCache (`SYSTEM` hive)
    254 
    255 *Executables that were **present** (and usually run) — path + `$SI` modification time, in insertion order. No run count, no run time, but it records binaries Prefetch never saw (servers).*
    256 
    257 ```bat
    258 AppCompatCacheParser.exe -f "E:\case042\tout\C\Windows\System32\config\SYSTEM" --csv out
    259 AppCompatCacheParser.exe -f SYSTEM --csv out -t         :: sort by insertion order (most recent first) — the "what ran last" view
    260 AppCompatCacheParser.exe -f SYSTEM --csv out -c 1       :: specific ControlSet
    261 AppCompatCacheParser.exe --csv out                      :: live system
    262 ```
    263 
    264 `LastModifiedTimeUTC` is the file's **modification** time, not execution. `CacheEntryPosition` 0 = most recently inserted. Written to the hive only at **shutdown/reboot** — a live box's cache is in memory (Volatility `windows.shimcachemem`). `Executed` flag exists only on Win7/8 formats.
    265 
    266 ### SBECmd / ShellBags Explorer — ShellBags (`NTUSER.DAT`, `UsrClass.dat`)
    267 
    268 *Folders the user browsed in Explorer — including on USB drives, network shares, zip files and paths that no longer exist — with first/last interaction times.*
    269 
    270 ```bat
    271 SBECmd.exe -d "E:\case042\tout\C\Users\bob" --csv out          :: finds NTUSER.DAT + UsrClass.dat under the profile
    272 SBECmd.exe -d "E:\case042\tout\C\Users" --csv out --dedupe     :: all users
    273 SBECmd.exe -l --csv out                                        :: live (current user, admin for others)
    274 SBECmd.exe -d Users\bob --csv out --nl                         :: don't replay transaction logs
    275 ```
    276 
    277 **ShellBags Explorer** (`ShellBagsExplorer.exe`) is the GUI: File → Load offline hive (pick `UsrClass.dat`, then it asks for `NTUSER.DAT`), tree on the left mirrors the folder hierarchy the user saw. `AbsolutePath`, `FirstInteracted`, `LastInteracted`, `MFTEntryNumber`/`SequenceNumber` (pivot back into MFTECmd output). Look for `\\server\share`, `D:\`/`E:\` (removable), `This PC\...` under GUIDs, and folder names like `Tools`, `loot`, `exfil`.
    278 
    279 ### SrumECmd — SRUM (`SRUDB.dat` + `SOFTWARE` hive)
    280 
    281 *Per-application network bytes sent/received, energy and CPU usage in hourly buckets for ~30–60 days. The exfiltration detector.*
    282 
    283 ```bat
    284 SrumECmd.exe -f "E:\case042\tout\C\Windows\System32\sru\SRUDB.dat" -r "E:\case042\tout\C\Windows\System32\config\SOFTWARE" --csv out
    285 :: If the ESE database is dirty (collected live) repair it first:
    286 esentutl.exe /r sru /i /d      (run in a copy of the sru folder)
    287 esentutl.exe /p SRUDB.dat
    288 ```
    289 
    290 CSVs: `*_NetworkUsages` (app, user SID, interface, `BytesSent`/`BytesReceived`, hour), `*_NetworkConnections`, `*_AppResourceUseInfo`, `*_EnergyUsage`, `*_PushNotifications`, `*_vfuprov`. Sort `BytesSent` descending; a 4 GB upload by `rclone.exe` or `powershell.exe` at 03:00 is the story.
    291 
    292 ### WxTCmd — Windows Timeline (`ActivitiesCache.db`)
    293 
    294 *App focus and file-open activity per user (Win10 1803 – 22H2), with start/end times and duration.*
    295 
    296 ```bat
    297 WxTCmd.exe -f "E:\case042\tout\C\Users\bob\AppData\Local\ConnectedDevicesPlatform\L.bob\ActivitiesCache.db" --csv out
    298 ```
    299 
    300 Two CSVs: `*_Activity` (app, `StartTime`, `EndTime`, `Duration`, payload with the document path) and `*_Activity_PackageId`. Disabled by default on Win11.
    301 
    302 ### RBCmd — Recycle Bin (`$Recycle.Bin\<SID>\$I*`)
    303 
    304 *Original path, size and deletion time of every file in the bin (the `$I` metadata file; `$R` is the content).*
    305 
    306 ```bat
    307 RBCmd.exe -d "E:\case042\tout\C\$Recycle.Bin" --csv out -q
    308 RBCmd.exe -f "$IABC123.txt"
    309 ```
    310 
    311 ### SQLECmd — any SQLite (browsers, Teams, Slack, Windows Search, Signal ...)
    312 
    313 *Runs a library of community "maps" (queries) against every SQLite DB it recognises, producing a tidy CSV per map instead of you hand-writing SQL.*
    314 
    315 ```bat
    316 SQLECmd.exe --sync                                              :: update maps
    317 SQLECmd.exe -d "E:\case042\tout\C\Users" --csv out              :: finds and parses everything it has a map for
    318 SQLECmd.exe -f "History" --csv out                              :: Chrome/Edge history
    319 SQLECmd.exe -f places.sqlite --csv out --dedupe                 :: Firefox
    320 ```
    321 
    322 ### bstrings — better `strings`
    323 
    324 *`strings` with regex, Unicode/UTF-16 aware, and built-in patterns for IPs, emails, URLs, GUIDs, MACs, credit cards, bitcoin addresses.*
    325 
    326 ```bat
    327 bstrings.exe -f pagefile.sys --lr ipv4                          :: built-in regex: ipv4, ipv6, email, url, guid, mac, ssn, cc, b64, win_path, unc, reg_path, sid, aeon, bitcoin, xml
    328 bstrings.exe -f mem.raw --ls "Invoke-Mimikatz" -q               :: literal search
    329 bstrings.exe -f mem.raw --lr "https?://[^\s\"']+" -m 8 -x 200   :: custom regex, min/max length
    330 bstrings.exe -f hiberfil.sys --fs iocs.txt -o hits.txt          :: file of strings to search for
    331 bstrings.exe -d E:\case042\tout\C\Users\bob\Downloads --lr email --ro   :: recurse a dir, --ro = show offsets
    332 bstrings.exe -p                                                 :: list built-in patterns
    333 ```
    334 
    335 The Linux/macOS counterpart is in [strings & file triage](/sheets/dfir/strings-file-triage).
    336 
    337 ### The rest of the toolbox
    338 
    339 | Tool | Purpose |
    340 |---|---|
    341 | **RECmd** / **Registry Explorer** | registry hives, batch files, deleted keys, transaction log replay — [own sheet](/sheets/dfir/recmd) |
    342 | **Timeline Explorer** | the CSV viewer — below and in [GUI tools](/sheets/dfir/dfir-gui-tools#timeline-explorer-eric-zimmerman) |
    343 | **MFTExplorer** | GUI hex+tree view of `$MFT`, drill into any record, resident data, data runs |
    344 | **EZViewer** | universal viewer for dozens of file types (images, Office, PDF, hex) without running the real application on evidence |
    345 | **Hasher** | drag-and-drop hashing (MD5/SHA1/SHA256/...) of files, folders, text |
    346 | **RecentFileCacheParser** | `RecentFileCache.bcf` (Win7/2008 pre-Amcache execution evidence) |
    347 | **PECmd** sibling **RBCmd**, **SumECmd** | Recycle Bin (above); `SumECmd` = User Access Logging (`SUM` databases on **servers**: which user/IP hit which role, per day, 2+ years) |
    348 | **SDB Explorer** | shim databases (`.sdb`) — application-compat persistence |
    349 | **iisGeolocate** | GeoIP-enrich IIS logs |
    350 | **VSCMount** | mount every Volume Shadow Copy of a live or attached volume as a folder tree |
    351 | **TimeApp** | tiny clock overlay for screen-recorded live response |
    352 | **XWFIM** | X-Ways forensics installer manager (only if you own X-Ways) |
    353 | **KAPE** module **`!EZParser`** | runs all of the above in the right order over a collection |
    354 
    355 ## Timeline Explorer — reviewing the CSVs
    356 
    357 Open any EZ CSV (or drag several in — each becomes a tab). It recognises the column names and sets types (timestamps sort as time, not text).
    358 
    359 | Action | How |
    360 |---|---|
    361 | Filter a column | type in the **filter row** under the header (`%mimikatz%` wildcard, `>2026-09-20` on time columns) |
    362 | Filter builder | funnel icon bottom-left → boolean expressions across columns |
    363 | Search everything | `Ctrl+F` finds across all columns of the current tab |
    364 | Hide / reorder columns | right-click header → **Column Chooser**, drag to the header to show |
    365 | Group by | drag a header into the band above the grid (group evtx by `EventId`, MFT by `ParentPath`) |
    366 | Tag rows | tick the `Tag` checkbox column, then **Tools → Show only tagged**; tags survive export |
    367 | Conditional colouring | right-click header → **Conditional Formatting** → e.g. `EventId = 4624` green, `= 4625` red |
    368 | Sessions / layouts | **File → Session → Save**; reopens every tab with filters intact |
    369 | Export | **File → Export** → CSV/XLSX/HTML of the *filtered* view — what goes in the report |
    370 | Pivot on a time | copy a timestamp, paste it into the filter row of every other tab with `~` (approx) to see what else happened then |
    371 
    372 > [!tip] The merged-timeline shortcut
    373 > `PECmd`'s `*_Timeline.csv`, `EvtxECmd` output, `MFTECmd`'s CSV and `LECmd` all share a first timestamp column. Open all of them in Timeline Explorer, filter each to the same 15-minute window, and you have a multi-artefact timeline without plaso. When you need the full super-timeline (thousands of files, every artefact) use `MFTECmd --body` + `mactime`, or the KAPE `Plaso_Timeline` module.
    374 
    375 ## Worked triage: from live box to answers in ~30 minutes
    376 
    377 ```bat
    378 :: 1. Collect (USB E:, 3–8 min for a workstation)
    379 kape.exe --tsource C: --tdest E:\c42\tout --target !SANS_Triage --vhdx WS042 --zv false --gui
    380 :: 2. Mount the VHDX read-only (Disk Management → Attach VHD → Read-only, or Arsenal Image Mounter), say it lands on F:
    381 :: 3. Parse everything
    382 kape.exe --msource F: --mdest E:\c42\mout --module !EZParser --gui
    383 :: 4. Detection pass over the event logs while you wait
    384 hayabusa.exe csv-timeline -d F:\C\Windows\System32\winevt\Logs -o E:\c42\hayabusa.csv --no-wizard -p verbose
    385 ```
    386 
    387 Then in Timeline Explorer, in this order:
    388 
    389 1. **`EventLogs\*.csv`** — filter `EventId` in `4624,4625,4648,4672,4688,7045,4698,1102`; note first suspicious logon time **T0** and the account.
    390 2. **`ProgramExecution\*Amcache*UnassociatedFileEntries.csv`** — sort `FileKeyLastWriteTimestamp` ≥ T0; anything under `Users\`, `Temp\`, `ProgramData\`, `Public\` gets its SHA-1 checked.
    391 3. **`ProgramExecution\*PECmd_Output_Timeline.csv`** — same window; confirm execution and get the *exact* run times.
    392 4. **`FileSystem\*MFTECmd*.csv`** — filter `Created0x10` in the window, `ParentPath` for the dirs above; check `SI<FN` for timestomps, `ZoneIdContents` for download origin.
    393 5. **`FileFolderAccess\`** (LECmd/JLECmd/SBECmd) — what did the account open/browse; ShellBags for USB/shares.
    394 6. **`Registry\`** (RECmd batch) — Run keys, services, `UserAssist`, `BAM`, `MountedDevices`, `TypedPaths`.
    395 7. **`SRUMDatabase\*NetworkUsages.csv`** — bytes out per process in the window.
    396 8. Tag rows as you go, `File → Export` the tagged set per tab → the timeline in your report.
    397 
    398 ## Related
    399 
    400 - [Digital Forensics reference](/sheets/dfir/forensics) — the "where is it and what does it prove" table this sheet parses
    401 - [RECmd registry forensics](/sheets/dfir/recmd) — the registry half of the suite
    402 - [Acquisition](/sheets/dfir/disk-imaging) — image first when you can
    403 - [GUI tools](/sheets/dfir/dfir-gui-tools) — Registry Explorer, Timeline Explorer, Autopsy, FTK Imager walkthroughs
    404 - [Volatility 3](/sheets/dfir/volatility) — the memory image KAPE cannot give you