The References You Reach for at 2 AM.
Investigation runbooks that walk you through incidents step by step. Triage scorecards that classify alerts in under 5 minutes. KQL queries you copy-paste into Sentinel during a live investigation. Forensic artifact references that tell you exactly where to look. Free, no account required — bookmark them now, use them when it matters.
Investigation & Response Tools
When an alert fires, you open these. The runbooks tell you what to check and in what order. The triage scorecard classifies the severity in under 5 minutes. The forensic references tell you exactly which artifact to examine and where to find it. The difference between "I need to think about this" and "I know the next step."
Detection & Endpoint Tools
When you need a KQL query that answers a specific question, an ASR rule deployment guide that won't break production, or a PowerShell one-liner for live response — these are the references that save you from writing it from scratch under pressure.
The Tools Give You the Reference. The Courses Teach the Methodology.
Every tool is extracted from a Ridgeline course. The courses add the judgment, context, and operational depth.