Kuiper is a centralized digital forensics investigation platform that enables parsing, searching, visualization, and collaborative analysis of collected evidences to streamline incident response workflows.
Digital Forensics Investigation Platform
Kuiper is designed for digital investigation teams and individual analysts to efficiently manage and analyze forensic artifacts collected from multiple machines. It centralizes evidence processing and collaboration, enabling faster and more accurate incident response by providing a unified platform for parsing, searching, timeline visualization, and rule-based detection.
Kuiper requires a centralized server setup to fully leverage its collaborative and processing capabilities; ensure that all team members access the platform via the web interface to maintain consistency. Using trusted parsers bundled with Kuiper improves accuracy and reduces discrepancies in artifact analysis. Integration with evidence collection tools like Hoarder and KAPE is recommended for streamlined workflows.
Ensure system meets requirements specified in the README
Clone the repository from https://github.com/DFIRKuiper/Kuiper
Follow the installation guide under section 4.1 Installation in the README
Set up the Kuiper server on a centralized machine
Configure necessary dependencies and environment variables as per documentation
Start the Kuiper service to enable web interface access
Create a new investigation case
Initialize a case that contains a list of scoped machines for investigation
Upload bulk evidence files
Upload multiple artifact files collected from scoped machines via tools like Hoarder or KAPE
Start parsing artifacts concurrently
Process uploaded evidence files for selected or all machines simultaneously
Browse and search parsed artifacts
Navigate through and query the parsed evidence across all machines within a case
Define detection rules
Create rules to automate alerts for suspicious activities such as encoded PowerShell commands or suspicious binaries
Tag artifacts and build timelines
Collaborate with team members by tagging evidence and visualizing events in a timeline format