Kage DFIR Toolkit

Open source Windows incident response triage console with timeline, YARA, enrichment and scoring.

ToolSelf-hosted, Open source

Pricing: Free and open source (MIT licence)

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is Kage DFIR Toolkit?

Kage is an open source console for triaging a Windows host during incident response, published on GitHub under the MIT licence. It runs an eleven step chain that collects artefacts with CyLR, builds a timeline with Hayabusa against Sigma rules, optionally scans for YARA matches with THOR Lite, and enriches indicators through VirusTotal and AbuseIPDB. It also captures system context, including local accounts, network sockets matched to their owning processes, disk root anomalies and logging coverage. Each completed step is sealed with a SHA256 hash, and the results feed a risk score built on four capped axes with a separate confidence rating. Reports export as printable HTML or JSON, with an optional AI drafted summary or a local summary when no key is set. It requires Windows 10, 11 or Windows Server, Python 3.10 or later and administrator rights, and a Linux version is described as in progress.

Best for: Incident responders who want a scripted first pass on a suspect Windows host using established open source DFIR tools.

Pros

  • MIT licensed, with eleven steps that can each be replayed on their own
  • Works without API keys, marking enrichment and AI steps as skipped and producing a local summary
  • Demo mode runs the full chain on a synthetic intrusion without touching the host

Things to check

  • Windows only and needs administrator rights; Linux support is in progress
  • Single maintainer; repository created 10 September 2026 with six commits, all on that day

Reported in public reviews and vendor documentation. See sources below.

Key Features

Artefact collection with CyLR, downloaded automatically
Hayabusa timeline correlated against Sigma rules
Optional YARA scanning with THOR Lite
Indicator enrichment through VirusTotal and AbuseIPDB
Network sockets matched to owning processes by PID
Risk score on four capped axes with a separate confidence rating
SHA256 seal for each completed step
Printable HTML report and JSON export

Do you work at Kage DFIR Toolkit? to confirm the details or send us a correction.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Kage DFIR Toolkit? Request a correction.

Key facts

Pricing
Free and open source (MIT licence)
Model
Free, open source
Founded
2026
Cloud
No
Self-hosted
Yes
Open source
Yes