Repository navigation
Add NirSoft MyLastSearch Module - #1118
Merged
Merged
Conversation
AndrewRathbun
approved these changes
Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds a new LiveResponse module that wraps NirSoft's MyLastSearch to export browser search engine query terms to a CSV. This is a different artifact from visited URLs, which the existing BrowsingHistoryView module already covers.
MyLastSearch's /loadfrom switch is documented to accept explicit history/cache folder paths, which would in theory let it process files KAPE has already collected. In testing, /loadfrom consistently produced a 0-byte CSV with no error against real KAPE-collected files, and even against the live system's own real cache/history folders using the same paths across both PowerShell and cmd.exe, and with multiple argument-passing methods (quoted empty placeholders and PowerShell array splatting, to rule out shell-quoting artifacts). Running MyLastSearch with no /loadfrom argument at all, its default behavior, which auto-detects the live/current user's browser profiles reliably produced real, correct results in every test. This module relies on that default behavior instead, so it must run live against the target system.
Testing: ran it live via kape.exe --msource --mdest --module NirSoft_MyLastSearch --debug against my own machine and got a real CSV back with hundreds of genuine recovered search queries (dated, attributed to Chrome, with the originating URL) — not a synthetic or empty test.
Known limitation: MyLastSearch's CSV export has no header row by default. Adding one requires opening MyLastSearch's own GUI once and enabling Options → "Add Header Line To CSV/Tab-Delimited File" - a persistent per-user setting, not a command-line switch, so it can't be forced from the .mkape file itself. Documented in the module's own comments rather than worked around.
No existing module in the repo covers this tool.
Checklist:
Please replace every instance of
[ ]with[X]OR click on the checkboxes after you submit your PRGUIDfor my Target(s)/Module(s)Miscfolder or created a relevant subfolder with justification--tlist/--mlistand corrected any errorsN/Aunderneath the Documentation header