~ cd /home/m4shl3
KapeParser icon

KapeParser

A Windows desktop application for parsing KAPE triage collections — pick a source, run the parsers, browse organized per-artifact output.

KapeParser.exe KapeResultsBrowser.exe

Overview

What it does

KapeParser replaces a legacy console script with a GUI workflow. Point it at a triage source — a mounted VHDX, a zip archive, or an already-extracted directory — choose which parsers to run, and get organized, searchable CSV and JSON output without leaving the tool.

The project is split into two executables sharing one distribution folder: KapeParser configures a case and runs the parsing pipeline with live per-stage progress; KapeResultsBrowser is a standalone companion for browsing parsed output from any past case, independent of the main tool.

Features

Any evidence source

Mounted VHDX, zip archive, or extracted directory — detected from any drive letter, not just C.

Batch queueing

Queue multiple sources; each is processed sequentially as its own case.

Automatic case naming

Named from the parsed registry's ComputerName, with a manual override when there is no registry to read.

DEFLATE64 zip support

Handles Windows' own "Compress to Zip" method, with a 7-Zip fallback and a tar fallback beyond that.

Configurable ESE repair

Ask, always, or never repair SRUM and Windows Search databases collected in a dirty-shutdown state.

Fast, searchable results

Per-case tabs, JSON syntax highlighting, and a DuckDB-backed CSV viewer with filtering and highlighted search.

Screenshots

KapeParser — Case Setup
KapeParser — Case Setup
Results Browser
Results Browser

Download

Full package

Includes the Tools\ folder — ready to run without a separate download step.

Password : 123

Download — Full Package (v1.2)