Collect a triage set¶
Record the authorised volume or mounted-image identifier, access mode, hostname and relevant time context.
Use separate storage with sufficient space; record the path and confirm it is not source evidence.
Review the selected compound Target and define the expected artefact groups before execution.
Configure the collection¶
Open gkape. Set Target source to C:\ when the authorised live system or
mounted evidence is available there. Set Target destination to a separate
working location such as G:\images.
Uncheck Flush unless your documented workflow specifically requires it,
then select !SANS_Triage as the Target.
Verify before execution
Confirm the source, destination, authority and available destination space. A reversed or mistyped path can collect from the wrong source or place new data on evidence you intended to preserve.
Understand the selected Target¶
!SANS_Triage is a bundled compound Target that collects a broad set of useful
Windows triage artefacts. Review
C:\Tools\KAPE\Targets\Compound\!SANS_Triage.tkape to understand its scope
before execution.
Compound Targets may change between KAPE versions. Record the version and keep
a copy of the selected .tkape definition with important case material.
Execute the collection¶
Review the Current command line, then click Execute. KAPE begins collecting the selected artefacts. The duration depends on source size, storage speed, selected Target and access permissions.
Retain warnings and errors. A completed interface does not guarantee that every requested artefact was accessible or copied.
Read the generated command¶
The command preview is the most concise record of the configured source, destination and Target. Compare it with your notes before selecting Execute. If the command contains an unexpected path, Target, Module or option, return to the interface and correct the configuration rather than editing the record afterwards.
Review the collected evidence¶
In the destination folder, the triage output should include material such as:
Users\: user profiles and browser historyWindows\System32\config\: Registry hives$MFT: Master File Table data for filesystem analysisWindows\Event Logs\: Windows.evtxfiles
Record the source, destination, selected Target, start and finish times, KAPE version, output size, notable errors and the expected folders that were actually present. Hash retained output or a packaged evidence container where that is part of your laboratory or organisational procedure.
Identify which expected source artefacts are present and link them to the recorded source and Target.
Retain permission, lock, path, free-space and execution errors; do not translate failure into absence.
Keep parser output separate from collected material and record the Module, executable and command that created it.
Interpret the triage set¶
The presence of an artefact means the selected Target returned it from the recorded source. It does not by itself establish user intent, execution or compromise. Correlate timestamps and identifiers across Registry, event-log, filesystem and user-activity evidence, and state which relevant sources were outside the Target's coverage.
Completion check¶
You are ready to continue when another analyst can identify the authorised source, reproduce the Target selection, locate the collected artefacts and understand any omissions or warnings.




