Eric Zimmerman on Twitter: "@keydet89 @TheBrewinator @jasonshale really? Use KAPE. This command took 3.1631 seconds to: 1. locate all user hives on c and all VSCs 2. Dedupe based on sha-1 3.
Redscan, A Kroll Business on Twitter: "The Kroll Artifact Parser and Extractor (KAPE) is a configurable triage program that enables fast and efficient collection and parsing of forensically useful artifacts. Learn more
KAPE | Kroll Artifact Parser and Extractor | by Sudeera Seneviratne | Nov, 2020 | Medium