KAPE and EZ Tools
Collect what answers the question. Prove it arrived. Read what came back.
A triage collection takes ninety seconds and gives you a few gigabytes instead of a few hundred, which is why it is how most Windows investigations now start. What decides whether it was worth taking is everything around it: whether the definition collected what you thought, whether you can prove it, and whether you can read the binary structures that came back and say what they support. This course teaches the whole pipeline as one piece of work. You write and version your own collection definitions, prove a collection against its specification, drive every parser in the suite, and take one endpoint from the collection command to a written finding.
What you'll be able to do
Course overview
Most people meet these tools as a command somebody handed them. It works, it produces a directory of CSV files, and the parts that decide whether any of it holds up stay invisible: which definition ran, what it was specified to collect, what it skipped and why, and what each parsed column actually means. A collection that quietly missed the artifact you needed looks exactly like one that worked. So does a parser reading a registry hive whose most recent writes are still sitting in a transaction log.
The last module answers the question the others build toward: given seven modules of parsed output and one afternoon to account for, what can you write down and stand behind.
Who this course is for
Anyone who has to answer a question about a Windows machine. There is no minimum experience and no gatekeeping: every concept is explained at first use, including the file system and registry structures the parsers read, so you can start here whether you have never run a collection or have been running one for years without reading its logs.
What you'll learn
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None. The course explains the file system, registry and execution structures at the point you first need them, and it does not assume you have run either toolset before.
Do I need a lab to follow along?
A Windows machine you own is enough, and the practice throughout is deliberately built on collecting from your own hardware. Working an ordinary day you can already account for is what teaches you what a normal machine looks like, which is the calibration that makes an unusual one recognizable.
What about the licensing? I do paid engagements.
Read this before you buy. The collector's own documentation states that from January 2026 it is no longer available for commercial use, meaning on a third party's network or as part of a paid engagement, while the vendor's marketing page still describes the older position and the Solo Edition agreement contradicts itself inside one document. The course teaches all three positions, says which is current, and gives the arrangement consultants actually use, which is the client's own team collecting and handing over the container.
The second half of that answer is why the course is still worth your time if you consult: the collector and the parsers are licensed differently. The parsers are free and open source with no commercial restriction, so four of the seven modules are unaffected either way.
How current is this?
Written against the 2026 tool line and research-gated against the tools' own documentation rather than against secondary material, which matters here because several widely repeated claims are wrong: one file system structure is listed as coming rather than shipping, and one execution artifact is routinely described as proving execution when it does not.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
The tools themselves carry their own licenses, which are the vendor's to set and change. Nothing in this course grants any right to use them, and the licensing position is covered so that you can check it rather than so that you can rely on our account of it.
Hosts, accounts, cases and parsed output are illustrative and constructed for teaching. Verify against your own collections and against each tool's current help output before relying on any specific behavior.
Ridgeline Cyber is not affiliated with Kroll, Microsoft, or the authors of the tools taught here. Product names are used descriptively.
Version and changelog
Version 1.0 · July 2026
Initial release as FOR201, replacing the earlier KAPE and EZ Tools short course. Seven modules across the toolkit, collection, processing at scale, the file system, execution and resource use, the registry and user activity, and the event logs, closing with one endpoint worked from the collection command to a written finding. An operational reference and a references module follow the content.
Rebuilt rather than migrated. The earlier version mentioned licensing zero times and the runtime requirement zero times, which are the two things most likely to stop a cybersecurity professional before they parse anything. Four tools absent from it are covered here, and the module balance was set by the investigative question rather than by tool name.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.