Skip to content

KAPE Hands-on Labs

Choose a lab

Choose the Interactive Lab for a short, guided browser exercise. Try the Full Lab after reviewing the tool guide and preparing an isolated, authorised environment.

How to use these labs

Start with the browser-based route to practise the workflow and evidence decisions without touching a real system. Use the Full Lab only in an isolated, authorised environment, and compare its outcome with the corresponding tool guide.

Interactive Lab

Browser-based · 15–25 min

gkape Interactive Lab

No installation

Practise a guided KAPE workflow in a safe browser simulation with immediate feedback.

gkape v1.3.0.2Case SUSA-021 · training simulation
Current taskConfirm the authorised sourceEnter the Windows volume supplied in the case brief.
  1. 1Source
  2. 2Destination
  3. 3Target
  4. 4Execute
  5. 5Review
FileToolsUse Target options

Target options

Targets (double-click to edit a Target)
NameFolderDescription
Container

Module options

NameCategoryDescription

Modules remain disabled until the collection-only workflow is understood.

Current command line.\kape.exe --tsource [source] --tdest [destination] --target [target] --gui
Enter the authorised source to begin.Targets selected: 0 · Modules selected: 0

Full Lab

Self-hosted · Setup: 30–45 min · Core exercise: 45–75 min

KAPE Full Lab

Windows VM and separate evidence volume required

Hands-on Windows triage proof of concept

Scope it. Collect it. Explain it.

Collect a focused triage set from an authorised Windows training VM, verify the expected artefacts and document a conclusion that remains tied to its source.

⏱ Setup: 30–45 min · Core exercise: 45–75 min◆ Guided beginner✓ Evidence required

Outcome-led, not screenshot-copying

The Full Lab supplies a case question, safety boundary and evidence checklist. Use the preserved guide to operate gkape, but record your own paths, version, times, warnings and results.

Safety boundary

Use only an owned or explicitly authorised endpoint. Record the live-system changes caused by collection.

Evidence

an authorised Windows lab endpoint and a written collection question

Success evidence

targeted output whose source, time, tool version, and integrity are recorded

Optional extension

Add a comparison

After the core succeeds, repeat the same focused task with one controlled change and explain the difference without widening the authorised scope.

Full Lab scenario

Case SUSA-021: a user reports that a suspicious archive was opened on an authorised Windows training VM. Your task is to collect a defensible !SANS_Triage set to a separate evidence volume, confirm that key execution, Registry, event-log and filesystem artefacts were returned, and write a bounded triage note. Do not claim that collection alone proves compromise.

01

Activity 1: Build the environment

  1. Create or restore an isolated Windows training VM and record its hostname, time zone, clock state and clean snapshot name.
  2. Attach a separate working volume as D: and create D:\SUSA-021\KAPE. Confirm it has sufficient free space.
  3. Install KAPE by following Install and open KAPE. Record the KAPE version and checksum or provenance of the archive.
  4. Create one harmless test file in the user Downloads folder and record its name, path, SHA-256 value and creation time.
Milestone 1Safe collection boundary readyThe VM, source, destination, tool version, time context and snapshot are recorded before gkape is executed.

02

Activity 2: Collect the triage set

  1. Open gkape and set Target source to C:\.
  2. Set Target destination to D:\SUSA-021\KAPE; do not write the collection into the KAPE program folder or back onto source evidence.
  3. Leave Modules disabled and select only the !SANS_Triage compound Target.
  4. Review the generated command and selected .tkape definition. Capture the settings in your case notes, then execute the collection.
  5. Retain execution messages and errors. Record start and finish times and do not silently discard inaccessible artefacts.
Milestone 2Attributable triage output returnedThe destination contains identifiable output linked to the source, selected Target, KAPE version and collection time.

03

Activity 3: Review and report

  1. Confirm that the collection contains Windows event logs, Registry hives, $MFT or related filesystem metadata and relevant user-profile material.
  2. Locate evidence associated with the controlled test file where the selected Target supports it. Record missing coverage as a limitation.
  3. Preserve the .tkape definition, execution record and an integrity hash for the retained output or packaged evidence set.
  4. Write a concise finding with observation, interpretation, confidence and limitations. Explain what the triage set establishes and what would require disk, memory or additional endpoint evidence.
  5. Remove the harmless test file and restore the disposable VM when finished.
Milestone 3Triage note ready for reviewAnother beginner can reproduce the collection, locate the same artefact groups and understand the supported conclusion and limitations.

Full Lab evidence checklist

This checklist applies to the self-hosted Full Lab. If you completed the Interactive Lab, retain its browser evidence summary instead.

  • Core completion

    Required to demonstrate a safe, attributable triage collection.

  • Good analyst practice

    Supplementary records that improve reproducibility and review quality.

0 of 10 recorded Mark each item when you have saved the evidence.

Troubleshooting

Symptom First check
Targets list is empty Confirm the complete KAPE folder was extracted and the Targets directory is present.
Execute remains unavailable Confirm source, destination and at least one Target are selected.
Output is incomplete Review access errors, Target scope, source path and free destination space.
Expected artefact is absent Confirm the selected .tkape definition covers it and record the gap as a limitation.

Clean up

Protect retained evidence and notes, remove harmless training material, detach the working volume and restore disposable snapshots when appropriate.