Skip to content

Collect a triage set

Source

Record the authorised volume or mounted-image identifier, access mode, hostname and relevant time context.

Destination

Use separate storage with sufficient space; record the path and confirm it is not source evidence.

Scope

Review the selected compound Target and define the expected artefact groups before execution.

Configure the collection

Open gkape. Set Target source to C:\ when the authorised live system or mounted evidence is available there. Set Target destination to a separate working location such as G:\images.

Uncheck Flush unless your documented workflow specifically requires it, then select !SANS_Triage as the Target.

Screenshot: Configure the Target source, Target destination and !SANS_Triage target

Verify before execution

Confirm the source, destination, authority and available destination space. A reversed or mistyped path can collect from the wrong source or place new data on evidence you intended to preserve.

Understand the selected Target

!SANS_Triage is a bundled compound Target that collects a broad set of useful Windows triage artefacts. Review C:\Tools\KAPE\Targets\Compound\!SANS_Triage.tkape to understand its scope before execution.

Screenshot: Review the selected !SANS_Triage compound target

Compound Targets may change between KAPE versions. Record the version and keep a copy of the selected .tkape definition with important case material.

Execute the collection

Review the Current command line, then click Execute. KAPE begins collecting the selected artefacts. The duration depends on source size, storage speed, selected Target and access permissions.

Screenshot: Click Execute to begin collecting artefacts

Retain warnings and errors. A completed interface does not guarantee that every requested artefact was accessible or copied.

Read the generated command

The command preview is the most concise record of the configured source, destination and Target. Compare it with your notes before selecting Execute. If the command contains an unexpected path, Target, Module or option, return to the interface and correct the configuration rather than editing the record afterwards.

Review the collected evidence

In the destination folder, the triage output should include material such as:

  • Users\: user profiles and browser history
  • Windows\System32\config\: Registry hives
  • $MFT: Master File Table data for filesystem analysis
  • Windows\Event Logs\: Windows .evtx files

Screenshot: Review Windows Event Log output in the triage collection

Screenshot: Review the collected triage folder structure

Record the source, destination, selected Target, start and finish times, KAPE version, output size, notable errors and the expected folders that were actually present. Hash retained output or a packaged evidence container where that is part of your laboratory or organisational procedure.

Collected

Identify which expected source artefacts are present and link them to the recorded source and Target.

Not collected

Retain permission, lock, path, free-space and execution errors; do not translate failure into absence.

Derived later

Keep parser output separate from collected material and record the Module, executable and command that created it.

Interpret the triage set

The presence of an artefact means the selected Target returned it from the recorded source. It does not by itself establish user intent, execution or compromise. Correlate timestamps and identifiers across Registry, event-log, filesystem and user-activity evidence, and state which relevant sources were outside the Target's coverage.

Completion check

You are ready to continue when another analyst can identify the authorised source, reproduce the Target selection, locate the collected artefacts and understand any omissions or warnings.

Review checkpointThe output contains Registry hives and `$MFT`, but no event logs, and gkape reported an access error. What conclusion is supported?