ez-tools-kape.md (27627B)
1 --- 2 title: "Eric Zimmerman Tools & KAPE" 3 description: "The EZ Tools suite end to end: Get-ZimmermanTools install, KAPE targets and modules for triage collection, every *Cmd parser (MFTECmd, PECmd, LECmd, JLECmd, EvtxECmd, AmcacheParser, AppCompatCacheParser, SBECmd, SrumECmd, WxTCmd, RBCmd, SQLECmd, bstrings) with the artefact and the question it answers, then CSV into Timeline Explorer." 4 category: dfir 5 subcategory: "Windows" 6 tags: [dfir, forensics, windows, ez-tools, kape, triage, timeline, mft, prefetch, evtx, amcache, shimcache, shellbags, lnk, jumplist, srum, registry] 7 tools: ["KAPE / gkape", "Get-ZimmermanTools", "MFTECmd", "PECmd", "LECmd", "JLECmd", "EvtxECmd", "AmcacheParser", "AppCompatCacheParser", "SBECmd / ShellBags Explorer", "SrumECmd", "WxTCmd", "RBCmd", "SQLECmd", "bstrings", "Timeline Explorer", "Registry Explorer / RECmd", "EZViewer", "MFTExplorer", "Hasher"] 8 difficulty: advanced 9 updated: "2026-09-26" 10 --- 11 12 # Eric Zimmerman Tools & KAPE 13 14 **Eric Zimmerman's tools** ("EZ Tools") are the free, open-source parsers that SANS FOR500 and most DFIR modules are built on: one small command-line tool per Windows artefact, all producing the same flat **CSV** that drops straight into **Timeline Explorer**. **KAPE** (Kroll Artifact Parser and Extractor) is the collector and orchestrator that sits in front of them: it copies the artefacts off a live box or mounted image in minutes (*targets*), then runs the parsers over the copy (*modules*). Learn the pattern once — `tool -f <artefact> --csv <out>` — and you know the whole suite. This card is the install, the KAPE triage command you will run on every case, then each parser with **what it reads** and **what question it answers**. 15 16 > [!info] Where they come from 17 > Everything here is at [ericzimmerman.github.io](https://ericzimmerman.github.io/#!index.md) (tools) and [kroll.com/kape](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape) (KAPE, free for non-commercial / internal use, registration required). Builds ship for **.NET 6** and **.NET 9**; grab the one matching the runtime on your analysis box. The `.NET 4` builds are gone. 18 19 ## Install and update 20 21 ```powershell 22 # One script pulls every tool (and keeps them updated — rerun it monthly) 23 Set-ExecutionPolicy Bypass -Scope Process 24 iwr https://raw.githubusercontent.com/EricZimmerman/Get-ZimmermanTools/master/Get-ZimmermanTools.ps1 -OutFile Get-ZimmermanTools.ps1 25 .\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZ -NetVersion 9 # or -NetVersion 6 26 27 # Runtime the tools need 28 winget install Microsoft.DotNet.DesktopRuntime.9 # GUI tools (Registry/Timeline/ShellBags Explorer) 29 winget install Microsoft.DotNet.Runtime.9 # CLI tools 30 31 # KAPE lives separately (download from Kroll, unzip anywhere — it is portable) 32 # C:\Tools\KAPE\kape.exe CLI 33 # C:\Tools\KAPE\gkape.exe GUI that builds the CLI command for you 34 # Point KAPE at the EZ tools once: copy them into C:\Tools\KAPE\Modules\bin\ 35 Copy-Item C:\Tools\EZ\net9\*.exe C:\Tools\KAPE\Modules\bin\ -Force 36 # Update KAPE's targets/modules from the community repo 37 C:\Tools\KAPE\kape.exe --sync 38 ``` 39 40 Add `C:\Tools\EZ\net9` to `PATH` and every example below works as written. Every tool answers `--help`; the `--csv` output flag and `-q` (quiet) are common to almost all. 41 42 > [!tip] Linux / macOS analyst box 43 > The CLI tools run under the Linux .NET runtime too (`dotnet MFTECmd.dll ...`, or the native builds the script fetches with `-NetVersion 9`). The GUI tools (Timeline Explorer, Registry Explorer) are Windows-only — keep a Windows VM for those, or use `xsv`/`qsv`/`visidata` on the CSVs. 44 45 ## The mental model 46 47 ```text 48 collect parse review 49 live box ──► KAPE --target ──► copy of artefacts ──► KAPE --module / *Cmd ──► CSV ──► Timeline Explorer 50 or image (files only, (tree mirrors C:\, (MFTECmd, PECmd, ...) (one per artefact) (filter, tag, 51 timestamps kept) or a VHDX) pivot on time) 52 ``` 53 54 | Layer | Tool | Rule of thumb | 55 |---|---|---| 56 | Collection | KAPE **targets** (`.tkape`) | *What files to copy.* Compound targets like `!SANS_Triage`, `KapeTriage`, `!BasicCollection` bundle dozens of single targets | 57 | Processing | KAPE **modules** (`.mkape`) | *What command to run over them.* `!EZParser` runs every EZ tool; other modules wrap Hayabusa, Chainsaw, Plaso, hindsight, etc. | 58 | Parser | the `*Cmd` tools | One artefact type each, all → CSV/JSON | 59 | Review | Timeline Explorer | The CSV viewer that understands the EZ column names (timestamps sort, colour, group) | 60 61 ## KAPE 62 63 ### The triage command you will actually run 64 65 ```bat 66 :: Live box, collecting from C:, output to your USB (E:), then parse everything 67 kape.exe --tsource C: --tdest E:\case042\tout --target !SANS_Triage --tflush ^ 68 --msource E:\case042\tout --mdest E:\case042\mout --module !EZParser --mflush ^ 69 --gui 70 71 :: Same, but pack the collection into a VHDX (one file, keeps ACLs/timestamps, mounts anywhere) 72 kape.exe --tsource C: --tdest E:\case042\tout --target KapeTriage --vhdx HOST-042 --zv false 73 74 :: From a mounted image instead of a live box (F: is the mounted E01 / Arsenal Image Mounter letter) 75 kape.exe --tsource F: --tdest E:\case042\tout --target !SANS_Triage --tflush 76 77 :: Only parse an existing collection (you already ran the target, or someone sent you a triage zip) 78 kape.exe --msource E:\case042\tout --mdest E:\case042\mout --module !EZParser --mflush 79 ``` 80 81 | Flag | Meaning | 82 |---|---| 83 | `--tsource` / `--tdest` | source drive/dir to collect **from**, dir to copy **into** | 84 | `--target X` | one or more targets, comma separated. `!` prefix = compound | 85 | `--tflush` | empty `--tdest` first | 86 | `--vhdx NAME` / `--vhd` / `--zip` | container for the collection instead of a loose tree | 87 | `--vss` | also pull the same paths out of every Volume Shadow Copy (deleted/overwritten artefacts) | 88 | `--tdd` | *target de-dupe* on hash when using `--vss` | 89 | `--msource` / `--mdest` | dir to parse, dir for parser output | 90 | `--module X` | modules to run; `!EZParser` = all EZ tools | 91 | `--mef csv\|json\|html` | override module output format | 92 | `--mvars key:val` | pass variables modules need (e.g. `--mvars computerName:HOST01`) | 93 | `--gui` | open a window showing progress, leave console log | 94 | `--debug` / `--trace` | verbose logging | 95 | `--sync` | update targets/modules from GitHub (KapeFiles repo) | 96 | `--tlist` / `--mlist` | list available targets / modules (`--tdetail` / `--mdetail` for contents) | 97 98 > [!warning] Footprint and what KAPE is not 99 > KAPE running on a live box **creates artefacts** (prefetch entry, `kape.exe` in Amcache/ShimCache, a ConsoleHost history line). Note the time you started it and exclude it in the timeline. It also pulls locked files (`$MFT`, hives, `$UsnJrnl`) through raw disk reads — it is not a bit-for-bit image and never will be; if you need one, [image first](/sheets/dfir/disk-imaging). 100 101 ### Targets worth knowing 102 103 | Target | Collects | 104 |---|---| 105 | `!SANS_Triage` | The FOR500/FOR508 set: `$MFT`, `$LogFile`, `$UsnJrnl`, registry hives + transaction logs, event logs, Prefetch, Amcache, LNK, Jump Lists, SRUM, WMI repository, scheduled tasks, PowerShell history, browser data, Recycle Bin, `$Extend` ... the 90% case | 106 | `KapeTriage` | Similar scope, tuned for speed on IR engagements | 107 | `!BasicCollection` | Lighter: hives, evtx, Prefetch, `$MFT`, LNK, Jump Lists | 108 | `RegistryHives`, `EventLogs`, `Prefetch`, `LNKFilesAndJumpLists`, `Amcache`, `SRUM`, `WebBrowsers`, `PowerShellConsole`, `ScheduledTasks`, `WMI`, `RecycleBin`, `WindowsTimeline`, `SUM`, `Antivirus`, `RDPLogs`, `$MFT`, `$J`, `$LogFile`, `MemoryFiles` | single-purpose, mix as needed | 109 | `ServerTriage`, `Exchange`, `IIS`, `MSSQL` | server roles | 110 | `RemoteAdminTools` | AnyDesk, TeamViewer, ScreenConnect, Atera ... logs (ransomware cases) | 111 112 ```bat 113 kape.exe --tlist :: everything 114 kape.exe --tdetail !SANS_Triage :: exactly which .tkape files a compound target includes 115 type "C:\Tools\KAPE\Targets\Compound\!SANS_Triage.tkape" 116 ``` 117 118 ### Modules worth knowing 119 120 | Module | Runs | 121 |---|---| 122 | `!EZParser` | every EZ CLI tool over the matching artefact, one CSV each in `mout\` sub-folders | 123 | `!EZParser` output dirs | `FileSystem\` (MFTECmd), `ProgramExecution\` (PECmd, Amcache, ShimCache), `EventLogs\` (EvtxECmd), `Registry\` (RECmd batch), `FileFolderAccess\` (LECmd, JLECmd, SBECmd), `SRUMDatabase\`, `WindowsTimeline\`, `RecycleBin\` ... | 124 | `Hayabusa`, `Chainsaw` | Sigma rule detection over the collected `.evtx` | 125 | `Plaso_Timeline`, `MFTECmd_$MFT_Bodyfile` → `mactime` | full super-timeline | 126 | `hindsight`, `BrowsingHistoryView` | browser history | 127 | `Hasher`, `Sysinternals_Sigcheck`, `DensityScout` | hashing / sig / entropy over collected binaries | 128 | `LogParser`, `EvtxECmd_RDP` | targeted event-log queries | 129 130 ### gkape (GUI) 131 132 Tick *Use Target options*, pick source/destination, tick targets in the tree (search box top right), tick *Use Module options*, pick `!EZParser`, and read the **command line box at the bottom** — that is the exact CLI it will run. Copy it into your notes; gkape is a command builder, nothing more. 133 134 ## The parsers, one artefact at a time 135 136 Every EZ CLI tool accepts `-f <file>` or `-d <directory>`, `--csv <outdir>` (add `--csvf name.csv` to fix the filename), `--json <outdir>`, `-q` to suppress per-record console output, `--dt "yyyy-MM-dd HH:mm:ss.fffffff"` to change the timestamp format, and `--debug`. Timestamps are **UTC** unless you pass `--tz`. Paths below assume a KAPE collection under `E:\case042\tout\C\`. 137 138 ### MFTECmd — `$MFT`, `$J` (USN journal), `$LogFile`, `$Boot`, `$SDS` 139 140 *Every file that ever existed (until the record is reused), with all eight timestamps.* The backbone of any timeline. 141 142 ```bat 143 :: Parse the MFT — one row per file/dir, $STANDARD_INFORMATION and $FILE_NAME timestamps side by side 144 MFTECmd.exe -f "E:\case042\tout\C\$MFT" --csv E:\case042\mout\mft --csvf mft.csv 145 146 :: Include the $FILE_NAME-only timestamps too (timestomp detection) and the resident data / ADS 147 MFTECmd.exe -f "$MFT" --csv out --fl --at 148 149 :: Bodyfile for mactime / plaso (drive letter for the paths) 150 MFTECmd.exe -f "$MFT" --body out --bodyf mft.body --bdl C 151 152 :: One entry in full detail (entry number 0x1A5 or decimal), including data runs 153 MFTECmd.exe -f "$MFT" --de 421 154 MFTECmd.exe -f "$MFT" --de 421 --dr 155 156 :: USN journal: what happened to files (create/delete/rename/overwrite) with the MFT to resolve full paths 157 MFTECmd.exe -f "E:\case042\tout\C\$Extend\$J" -m "E:\case042\tout\C\$MFT" --csv out --csvf usn.csv 158 159 :: $LogFile (NTFS transaction log) and $Boot / $SDS (security descriptors) 160 MFTECmd.exe -f "$LogFile" --csv out 161 MFTECmd.exe -f "$Boot" --csv out 162 MFTECmd.exe -f "$SDS" --csv out 163 164 :: Pull from volume shadow copies too (needs --vss and admin, live or mounted image) 165 MFTECmd.exe -f "F:\$MFT" --csv out --vss 166 ``` 167 168 > [!tip] Reading the MFT CSV in Timeline Explorer 169 > `Created0x10` / `LastModified0x10` etc. are `$STANDARD_INFORMATION` (what Explorer shows, **user-space tools can change these**). `Created0x30` etc. are `$FILE_NAME` (kernel-set, much harder to fake). Filter `SI<FN` = **true** to find files whose visible timestamps predate their filename record — classic **timestomping**. `InUse` = false → deleted but record not yet reused. `HasAds` → alternate data streams; `ZoneIdContents` gives the download URL from `Zone.Identifier`. 170 171 ### PECmd — Prefetch (`C:\Windows\Prefetch\*.pf`) 172 173 *Which executables ran, when (last 8 run times on Win8+), how many times, and which files/volumes they touched in the first ~10 s.* 174 175 ```bat 176 PECmd.exe -d "E:\case042\tout\C\Windows\Prefetch" --csv out -q 177 PECmd.exe -f "E:\case042\tout\C\Windows\Prefetch\MIMIKATZ.EXE-1A2B3C4D.pf" 178 PECmd.exe -d Prefetch --csv out -k "temp,appdata,downloads,users\\public" :: highlight rows whose loaded files match keywords 179 PECmd.exe -d Prefetch --csv out --vss :: shadow copies too 180 PECmd.exe -d Prefetch --json out 181 ``` 182 183 Output is two CSVs: `*_PECmd_Output.csv` (one row per `.pf`: exe, run count, last run + 7 previous, volume serials) and `*_PECmd_Output_Timeline.csv` (one row **per run**, ready to merge into a timeline). Hash in the filename changes with the path the exe ran from — two `CMD.EXE-xxxx.pf` files = cmd launched from two locations. Prefetch is **off by default on servers and SSD-tuned boxes**; check `HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher` before concluding "never ran". 184 185 ### LECmd — LNK shortcut files 186 187 *Files the user opened (Recent), with the target's path, size, timestamps, volume serial, and the MAC address / hostname of the machine the LNK was made on.* 188 189 ```bat 190 LECmd.exe -d "E:\case042\tout\C\Users\bob\AppData\Roaming\Microsoft\Windows\Recent" --csv out -q 191 LECmd.exe -d "E:\case042\tout\C\Users" --csv out -q --all :: every .lnk under every profile (Desktop, Start Menu, ...) 192 LECmd.exe -f suspicious.lnk --mp :: more precise timestamps; also dumps the full structure 193 LECmd.exe -d Recent --csv out --neb :: include LNKs with no TargetIDList/ExtraBlocks (rare edge cases) 194 ``` 195 196 `TargetCreated`/`TargetModified`/`TargetAccessed` are the **target file's** timestamps at LNK creation; `SourceCreated/Modified` are the LNK's own = first/last time the file was opened. `MachineID`/`MacAddress` place a USB-carried LNK on a specific host. Phishing LNKs: check `Arguments` for `powershell -enc`, and `WorkingDirectory`. 197 198 ### JLECmd — Jump Lists (Automatic + Custom Destinations) 199 200 *Per-application recent items — Word documents, RDP hosts (mstsc), Explorer folders — surviving longer than Recent LNKs.* 201 202 ```bat 203 JLECmd.exe -d "E:\case042\tout\C\Users\bob\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv out -q 204 JLECmd.exe -d "...\Recent\CustomDestinations" --csv out -q 205 JLECmd.exe -d Recent --csv out -q --ld :: include full LNK detail per entry 206 JLECmd.exe -d Recent --csv out -q --withDir :: dump the embedded LNKs to disk 207 JLECmd.exe -f "5f7b5f1e01b83767.automaticDestinations-ms" --fd :: full dump of one list 208 ``` 209 210 The filename hash is the **AppID**: `5f7b5f1e01b83767` = Quick Access, `9b9cdc69c1c24e2b` = Notepad, `f01b4d95cf55d32a` = Explorer, `1b4dd67f29cb1962` = Windows Explorer pinned. JLECmd resolves the known ones for you (`AppIdDescription` column). RDP jump list (`mstsc.exe`, `{...}`) lists every hostname/IP the user connected to. 211 212 ### EvtxECmd — Event logs (`.evtx`) 213 214 *The normalised event log view: every EVTX in one CSV with a `MapDescription` and a `PayloadData1..6` extraction of the fields that matter (user, IP, process, service name), courtesy of community maps.* 215 216 ```bat 217 :: Update the maps first — they turn raw XML into "Logon: user X from IP Y" 218 EvtxECmd.exe --sync 219 220 :: All logs from a collection 221 EvtxECmd.exe -d "E:\case042\tout\C\Windows\System32\winevt\Logs" --csv out --csvf evtx.csv 222 223 :: Only the IDs you care about, in a date window 224 EvtxECmd.exe -d Logs --csv out --inc 4624,4625,4634,4648,4672,4688,4698,4720,4732,7045,1102 ^ 225 --sd "2026-09-20 00:00:00" --ed "2026-09-27 00:00:00" 226 227 :: Exclude noise 228 EvtxECmd.exe -d Logs --csv out --exc 5156,5158,4689 229 230 :: Single log, JSON for jq / SIEM ingestion 231 EvtxECmd.exe -f Security.evtx --json out 232 EvtxECmd.exe -f Security.evtx --xml out :: original XML per event 233 234 :: Live system (admin) 235 EvtxECmd.exe -d C:\Windows\System32\winevt\Logs --csv E:\case042\live-evtx --vss 236 ``` 237 238 Key columns: `TimeCreated`, `EventId`, `Channel`, `Computer`, `UserId`, `MapDescription`, `PayloadData1-6` (mapped fields), `RemoteHost`, `ExecutableInfo`, `Payload` (full XML). Sort by time, filter `MapDescription` — this is how you find the 4624 type 10 from the odd IP in minutes. The Event ID table lives in the [Digital Forensics reference](/sheets/dfir/forensics). For Sigma-rule detection over the same files use **Hayabusa** / **Chainsaw** (KAPE modules exist for both). 239 240 ### AmcacheParser — `Amcache.hve` 241 242 *Every executable and driver the system inventoried — full path, **SHA-1 of the first 31 MB**, publisher, compile time, first-seen time. Survives the binary being deleted.* 243 244 ```bat 245 AmcacheParser.exe -f "E:\case042\tout\C\Windows\appcompat\Programs\Amcache.hve" --csv out 246 AmcacheParser.exe -f Amcache.hve --csv out -i :: include only unassociated file entries (executables not tied to an installed program) — the malware view 247 AmcacheParser.exe -f Amcache.hve --csv out -w known-good.txt :: whitelist of SHA-1s to drop 248 AmcacheParser.exe -f Amcache.hve --csv out -b iocs.txt :: blacklist: flag matches 249 ``` 250 251 Outputs several CSVs: `*_UnassociatedFileEntries` (the interesting one), `*_AssociatedFileEntries`, `*_ProgramEntries`, `*_DriverBinaries`, `*_ShortCuts`, `*_DeviceContainers`/`*_DevicePnps` (USB devices!). `FileKeyLastWriteTimestamp` ≈ first execution / first seen (not exact). Throw the SHA-1 column at VirusTotal. 252 253 ### AppCompatCacheParser — ShimCache (`SYSTEM` hive) 254 255 *Executables that were **present** (and usually run) — path + `$SI` modification time, in insertion order. No run count, no run time, but it records binaries Prefetch never saw (servers).* 256 257 ```bat 258 AppCompatCacheParser.exe -f "E:\case042\tout\C\Windows\System32\config\SYSTEM" --csv out 259 AppCompatCacheParser.exe -f SYSTEM --csv out -t :: sort by insertion order (most recent first) — the "what ran last" view 260 AppCompatCacheParser.exe -f SYSTEM --csv out -c 1 :: specific ControlSet 261 AppCompatCacheParser.exe --csv out :: live system 262 ``` 263 264 `LastModifiedTimeUTC` is the file's **modification** time, not execution. `CacheEntryPosition` 0 = most recently inserted. Written to the hive only at **shutdown/reboot** — a live box's cache is in memory (Volatility `windows.shimcachemem`). `Executed` flag exists only on Win7/8 formats. 265 266 ### SBECmd / ShellBags Explorer — ShellBags (`NTUSER.DAT`, `UsrClass.dat`) 267 268 *Folders the user browsed in Explorer — including on USB drives, network shares, zip files and paths that no longer exist — with first/last interaction times.* 269 270 ```bat 271 SBECmd.exe -d "E:\case042\tout\C\Users\bob" --csv out :: finds NTUSER.DAT + UsrClass.dat under the profile 272 SBECmd.exe -d "E:\case042\tout\C\Users" --csv out --dedupe :: all users 273 SBECmd.exe -l --csv out :: live (current user, admin for others) 274 SBECmd.exe -d Users\bob --csv out --nl :: don't replay transaction logs 275 ``` 276 277 **ShellBags Explorer** (`ShellBagsExplorer.exe`) is the GUI: File → Load offline hive (pick `UsrClass.dat`, then it asks for `NTUSER.DAT`), tree on the left mirrors the folder hierarchy the user saw. `AbsolutePath`, `FirstInteracted`, `LastInteracted`, `MFTEntryNumber`/`SequenceNumber` (pivot back into MFTECmd output). Look for `\\server\share`, `D:\`/`E:\` (removable), `This PC\...` under GUIDs, and folder names like `Tools`, `loot`, `exfil`. 278 279 ### SrumECmd — SRUM (`SRUDB.dat` + `SOFTWARE` hive) 280 281 *Per-application network bytes sent/received, energy and CPU usage in hourly buckets for ~30–60 days. The exfiltration detector.* 282 283 ```bat 284 SrumECmd.exe -f "E:\case042\tout\C\Windows\System32\sru\SRUDB.dat" -r "E:\case042\tout\C\Windows\System32\config\SOFTWARE" --csv out 285 :: If the ESE database is dirty (collected live) repair it first: 286 esentutl.exe /r sru /i /d (run in a copy of the sru folder) 287 esentutl.exe /p SRUDB.dat 288 ``` 289 290 CSVs: `*_NetworkUsages` (app, user SID, interface, `BytesSent`/`BytesReceived`, hour), `*_NetworkConnections`, `*_AppResourceUseInfo`, `*_EnergyUsage`, `*_PushNotifications`, `*_vfuprov`. Sort `BytesSent` descending; a 4 GB upload by `rclone.exe` or `powershell.exe` at 03:00 is the story. 291 292 ### WxTCmd — Windows Timeline (`ActivitiesCache.db`) 293 294 *App focus and file-open activity per user (Win10 1803 – 22H2), with start/end times and duration.* 295 296 ```bat 297 WxTCmd.exe -f "E:\case042\tout\C\Users\bob\AppData\Local\ConnectedDevicesPlatform\L.bob\ActivitiesCache.db" --csv out 298 ``` 299 300 Two CSVs: `*_Activity` (app, `StartTime`, `EndTime`, `Duration`, payload with the document path) and `*_Activity_PackageId`. Disabled by default on Win11. 301 302 ### RBCmd — Recycle Bin (`$Recycle.Bin\<SID>\$I*`) 303 304 *Original path, size and deletion time of every file in the bin (the `$I` metadata file; `$R` is the content).* 305 306 ```bat 307 RBCmd.exe -d "E:\case042\tout\C\$Recycle.Bin" --csv out -q 308 RBCmd.exe -f "$IABC123.txt" 309 ``` 310 311 ### SQLECmd — any SQLite (browsers, Teams, Slack, Windows Search, Signal ...) 312 313 *Runs a library of community "maps" (queries) against every SQLite DB it recognises, producing a tidy CSV per map instead of you hand-writing SQL.* 314 315 ```bat 316 SQLECmd.exe --sync :: update maps 317 SQLECmd.exe -d "E:\case042\tout\C\Users" --csv out :: finds and parses everything it has a map for 318 SQLECmd.exe -f "History" --csv out :: Chrome/Edge history 319 SQLECmd.exe -f places.sqlite --csv out --dedupe :: Firefox 320 ``` 321 322 ### bstrings — better `strings` 323 324 *`strings` with regex, Unicode/UTF-16 aware, and built-in patterns for IPs, emails, URLs, GUIDs, MACs, credit cards, bitcoin addresses.* 325 326 ```bat 327 bstrings.exe -f pagefile.sys --lr ipv4 :: built-in regex: ipv4, ipv6, email, url, guid, mac, ssn, cc, b64, win_path, unc, reg_path, sid, aeon, bitcoin, xml 328 bstrings.exe -f mem.raw --ls "Invoke-Mimikatz" -q :: literal search 329 bstrings.exe -f mem.raw --lr "https?://[^\s\"']+" -m 8 -x 200 :: custom regex, min/max length 330 bstrings.exe -f hiberfil.sys --fs iocs.txt -o hits.txt :: file of strings to search for 331 bstrings.exe -d E:\case042\tout\C\Users\bob\Downloads --lr email --ro :: recurse a dir, --ro = show offsets 332 bstrings.exe -p :: list built-in patterns 333 ``` 334 335 The Linux/macOS counterpart is in [strings & file triage](/sheets/dfir/strings-file-triage). 336 337 ### The rest of the toolbox 338 339 | Tool | Purpose | 340 |---|---| 341 | **RECmd** / **Registry Explorer** | registry hives, batch files, deleted keys, transaction log replay — [own sheet](/sheets/dfir/recmd) | 342 | **Timeline Explorer** | the CSV viewer — below and in [GUI tools](/sheets/dfir/dfir-gui-tools#timeline-explorer-eric-zimmerman) | 343 | **MFTExplorer** | GUI hex+tree view of `$MFT`, drill into any record, resident data, data runs | 344 | **EZViewer** | universal viewer for dozens of file types (images, Office, PDF, hex) without running the real application on evidence | 345 | **Hasher** | drag-and-drop hashing (MD5/SHA1/SHA256/...) of files, folders, text | 346 | **RecentFileCacheParser** | `RecentFileCache.bcf` (Win7/2008 pre-Amcache execution evidence) | 347 | **PECmd** sibling **RBCmd**, **SumECmd** | Recycle Bin (above); `SumECmd` = User Access Logging (`SUM` databases on **servers**: which user/IP hit which role, per day, 2+ years) | 348 | **SDB Explorer** | shim databases (`.sdb`) — application-compat persistence | 349 | **iisGeolocate** | GeoIP-enrich IIS logs | 350 | **VSCMount** | mount every Volume Shadow Copy of a live or attached volume as a folder tree | 351 | **TimeApp** | tiny clock overlay for screen-recorded live response | 352 | **XWFIM** | X-Ways forensics installer manager (only if you own X-Ways) | 353 | **KAPE** module **`!EZParser`** | runs all of the above in the right order over a collection | 354 355 ## Timeline Explorer — reviewing the CSVs 356 357 Open any EZ CSV (or drag several in — each becomes a tab). It recognises the column names and sets types (timestamps sort as time, not text). 358 359 | Action | How | 360 |---|---| 361 | Filter a column | type in the **filter row** under the header (`%mimikatz%` wildcard, `>2026-09-20` on time columns) | 362 | Filter builder | funnel icon bottom-left → boolean expressions across columns | 363 | Search everything | `Ctrl+F` finds across all columns of the current tab | 364 | Hide / reorder columns | right-click header → **Column Chooser**, drag to the header to show | 365 | Group by | drag a header into the band above the grid (group evtx by `EventId`, MFT by `ParentPath`) | 366 | Tag rows | tick the `Tag` checkbox column, then **Tools → Show only tagged**; tags survive export | 367 | Conditional colouring | right-click header → **Conditional Formatting** → e.g. `EventId = 4624` green, `= 4625` red | 368 | Sessions / layouts | **File → Session → Save**; reopens every tab with filters intact | 369 | Export | **File → Export** → CSV/XLSX/HTML of the *filtered* view — what goes in the report | 370 | Pivot on a time | copy a timestamp, paste it into the filter row of every other tab with `~` (approx) to see what else happened then | 371 372 > [!tip] The merged-timeline shortcut 373 > `PECmd`'s `*_Timeline.csv`, `EvtxECmd` output, `MFTECmd`'s CSV and `LECmd` all share a first timestamp column. Open all of them in Timeline Explorer, filter each to the same 15-minute window, and you have a multi-artefact timeline without plaso. When you need the full super-timeline (thousands of files, every artefact) use `MFTECmd --body` + `mactime`, or the KAPE `Plaso_Timeline` module. 374 375 ## Worked triage: from live box to answers in ~30 minutes 376 377 ```bat 378 :: 1. Collect (USB E:, 3–8 min for a workstation) 379 kape.exe --tsource C: --tdest E:\c42\tout --target !SANS_Triage --vhdx WS042 --zv false --gui 380 :: 2. Mount the VHDX read-only (Disk Management → Attach VHD → Read-only, or Arsenal Image Mounter), say it lands on F: 381 :: 3. Parse everything 382 kape.exe --msource F: --mdest E:\c42\mout --module !EZParser --gui 383 :: 4. Detection pass over the event logs while you wait 384 hayabusa.exe csv-timeline -d F:\C\Windows\System32\winevt\Logs -o E:\c42\hayabusa.csv --no-wizard -p verbose 385 ``` 386 387 Then in Timeline Explorer, in this order: 388 389 1. **`EventLogs\*.csv`** — filter `EventId` in `4624,4625,4648,4672,4688,7045,4698,1102`; note first suspicious logon time **T0** and the account. 390 2. **`ProgramExecution\*Amcache*UnassociatedFileEntries.csv`** — sort `FileKeyLastWriteTimestamp` ≥ T0; anything under `Users\`, `Temp\`, `ProgramData\`, `Public\` gets its SHA-1 checked. 391 3. **`ProgramExecution\*PECmd_Output_Timeline.csv`** — same window; confirm execution and get the *exact* run times. 392 4. **`FileSystem\*MFTECmd*.csv`** — filter `Created0x10` in the window, `ParentPath` for the dirs above; check `SI<FN` for timestomps, `ZoneIdContents` for download origin. 393 5. **`FileFolderAccess\`** (LECmd/JLECmd/SBECmd) — what did the account open/browse; ShellBags for USB/shares. 394 6. **`Registry\`** (RECmd batch) — Run keys, services, `UserAssist`, `BAM`, `MountedDevices`, `TypedPaths`. 395 7. **`SRUMDatabase\*NetworkUsages.csv`** — bytes out per process in the window. 396 8. Tag rows as you go, `File → Export` the tagged set per tab → the timeline in your report. 397 398 ## Related 399 400 - [Digital Forensics reference](/sheets/dfir/forensics) — the "where is it and what does it prove" table this sheet parses 401 - [RECmd registry forensics](/sheets/dfir/recmd) — the registry half of the suite 402 - [Acquisition](/sheets/dfir/disk-imaging) — image first when you can 403 - [GUI tools](/sheets/dfir/dfir-gui-tools) — Registry Explorer, Timeline Explorer, Autopsy, FTK Imager walkthroughs 404 - [Volatility 3](/sheets/dfir/volatility) — the memory image KAPE cannot give you