Skip to content

KAPE Integration

IRFlow Timeline automatically detects and pre-configures display settings for output from KAPE and Eric Zimmerman's (EZ) tools, giving you an optimized view from the moment you open a file.

How Auto-Detection Works

When you open a CSV or XLSX file, IRFlow Timeline analyzes the column headers to identify the source tool. If a known profile matches, it automatically applies:

  • Column ordering — most relevant columns first
  • Pinned columns — key columns stay visible during horizontal scrolling
  • Hidden columns — noise columns are hidden by default
  • Auto-color column — a column is selected for automatic palette coloring

Supported Profiles

EZ Tools

ProfileToolKey Columns
MFTECmdMFT parserFileName, ParentPath, Extension, FileSize, Created, Modified
EvtxECmdEvent log parserTimeCreated, EventId, Channel, Computer, PayloadData1-6
PECmdPrefetch parserExecutableName, RunCount, LastRun, Volume
LECmdLNK file parserSourceFile, TargetPath, Arguments, WorkingDirectory
AmcacheParser (Files)Amcache filesFullPath, SHA1, FileSize, CompileTime
AmcacheParser (Programs)Amcache programsName, Version, Publisher, InstallDate
RECmdRegistry parserHivePath, Key, ValueName, ValueData, LastWriteTimestamp
SBECmdShellBags parserAbsolutePath, ShellType, LastWriteTime, MFTEntry
SrumECmdSRUM parserExeInfo, AppId, NetworkUsage, ForegroundTime
AppCompatcacheShimcachePath, LastModifiedTime, Executed
JLECmdJump ListsFileName, Arguments, TargetPath, CreatedOn

Timeline Formats

ProfileDescriptionKey Columns
ForensicTimelineGeneric forensic timelinedatetime, timestamp_desc, source, sourcetype, message
Plaso SuperTimelinePlaso psort outputdatetime, source, sourcetype, type, display_name, message
MacTimeBodyfile mactimeDate, Size, Type, Mode, UID, GID, File Name
KapeMiniTimelineKAPE mini timelineDate, Time, Source, Type, Short, Desc
PsortTimelinePlaso psort CSVdate, time, timezone, source, sourcetype, type, user, host

Security Tools

ProfileToolKey Columns
Hayabusa (Standard)Windows detectionTimestamp, RuleTitle, Level, Computer, Channel
Hayabusa (Verbose)Detailed detectionTimestamp, RuleTitle, Level, Details, ExtraFieldInfo
ChainsawDetection rulestimestamp, name, level, computer, status
BrowsingHistoryViewBrowser historyURL, Title, Visit Time, Browser

Miscellaneous

ProfileDescription
KAPE Copy LogKAPE collection log

Customizing After Detection

Auto-detection sets a starting point, but you can always customize:

  • Show hidden columns via the Column Manager
  • Unpin columns via Cmd+Click
  • Change column order via drag-and-drop
  • Override color rules in the Color Rules editor

Your customizations are preserved when saving a session.

Manual Profile Application

If auto-detection doesn't trigger (e.g., modified column names), you can't currently force a profile. The detection relies on exact column header matching.

Best Practice

When exporting from EZ Tools, use the default column configurations to ensure IRFlow Timeline recognizes the output format. Custom column selections may prevent auto-detection.

Built for the DFIR community.