Skip to content

Add NirSoft MyLastSearch Module - #1118

Merged
AndrewRathbun merged 3 commits into
EricZimmerman:masterfrom
Gear-I:MyLastSearch_Module
Sep 15, 2026
Merged

AndrewRathbun merged 3 commits into
EricZimmerman:masterfrom
Gear-I:MyLastSearch_Module

Conversation

@Gear-I

@Gear-I Gear-I commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds a new LiveResponse module that wraps NirSoft's MyLastSearch to export browser search engine query terms to a CSV. This is a different artifact from visited URLs, which the existing BrowsingHistoryView module already covers.
MyLastSearch's /loadfrom switch is documented to accept explicit history/cache folder paths, which would in theory let it process files KAPE has already collected. In testing, /loadfrom consistently produced a 0-byte CSV with no error against real KAPE-collected files, and even against the live system's own real cache/history folders using the same paths across both PowerShell and cmd.exe, and with multiple argument-passing methods (quoted empty placeholders and PowerShell array splatting, to rule out shell-quoting artifacts). Running MyLastSearch with no /loadfrom argument at all, its default behavior, which auto-detects the live/current user's browser profiles reliably produced real, correct results in every test. This module relies on that default behavior instead, so it must run live against the target system.

Testing: ran it live via kape.exe --msource --mdest --module NirSoft_MyLastSearch --debug against my own machine and got a real CSV back with hundreds of genuine recovered search queries (dated, attributed to Chrome, with the originating URL) — not a synthetic or empty test.

Known limitation: MyLastSearch's CSV export has no header row by default. Adding one requires opening MyLastSearch's own GUI once and enabling Options → "Add Header Line To CSV/Tab-Delimited File" - a persistent per-user setting, not a command-line switch, so it can't be forced from the .mkape file itself. Documented in the module's own comments rather than worked around.

No existing module in the repo covers this tool.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

  • I have generated a unique GUID for my Target(s)/Module(s)
  • I have placed the Target(s)/Module(s) in an appropriate subfolder in Targets or Modules. If one doesn't exist, I have either added it to the Misc folder or created a relevant subfolder with justification
  • I have set or updated the version of my Target(s)/Module(s)
  • I have verified that KAPE parses the Target(s)/Module(s) successfully via kape.exe, using --tlist/--mlist and corrected any errors
  • I have validated my Target(s)/Module(s) against test data and verified they are working as intended
  • I have made an attempt to document the artifacts within the Target(s) or Module(s) I am submitting. If documentation doesn't exist, I have placed N/A underneath the Documentation header
  • For Targets, I have consulted either the Target Guide, Target Template, Compound Target Guide, or Compound Target Template to ensure my Target(s) follow the same format
  • For Modules, I have consulted either the Module Guide, Module Template, Compound Module Guide, or Compound Module Template to ensure my Module(s) follow the same format

@AndrewRathbun AndrewRathbun self-assigned this Sep 15, 2026
@AndrewRathbun AndrewRathbun added the enhancement New feature or request label Sep 15, 2026
@AndrewRathbun
AndrewRathbun merged commit ead8085 into EricZimmerman:master Sep 15, 2026
1 check passed
@Gear-I
Gear-I deleted the MyLastSearch_Module branch September 15, 2026 20:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants