KAPE and EZ Tools

Collect what answers the question. Prove it arrived. Read what came back.

A triage collection takes ninety seconds and gives you a few gigabytes instead of a few hundred, which is why it is how most Windows investigations now start. What decides whether it was worth taking is everything around it: whether the definition collected what you thought, whether you can prove it, and whether you can read the binary structures that came back and say what they support. This course teaches the whole pipeline as one piece of work. You write and version your own collection definitions, prove a collection against its specification, drive every parser in the suite, and take one endpoint from the collection command to a written finding.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 12 CPE Credits

What you'll be able to do

✓Scope a triage collection against the question you were actually asked, and state in writing what it cannot answer
✓Read any published target or module definition and say exactly what it will collect or execute before you run it, then write, test and version your own
✓Prove a collection matched its definition using the specification count, the copy log and the skip reasons, then run the same pipeline across a fleet and on containers somebody else collected
✓Reconstruct a file's history from the master file table, the change journal and the structures that outlive a deletion
✓Reconcile four execution sources that disagree, and say which of them establishes that a program ran and which only establishes it was present
✓Read the registry and user activity artifacts for what an account did, then the event logs for who was logged on and what they started inside that session
✓Merge every parsed family into one sourced timeline and write a finding that separates what is established from what is only consistent with it
FOR201 | Essentials tier | 7 modules across 4 phases | 10–12 hours at your own pace | 12 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Course Orientation

Module 0Course OrientationCourse Preview

What this course teaches: how KAPE collects and processes in two separate phases, how to build targets and modules that fit your investigation, which EZ Tool answers which question, and how to read the output well enough to write a defensible finding. Start here.

Phase 1: The Toolkit

Module 1Triage and the Toolkit

When triage collection is the right answer and when it is the wrong one, what KAPE cannot reach, the licensing line that decides whether you may run it at all, how to install EZ Tools so the tools actually launch, how KAPE is laid out on disk and how it finds its own configuration, how to prepare collection media without contaminating the source, and a first verified collection off a live machine.

Show 8 lessonsHide lessons
  1. 1.11.1 What Triage Collection Buys You, and What It Costs
  2. 1.21.2 Licensing, and the Decision It Forces
  3. 1.31.3 Building the EZ Tools Toolkit
  4. 1.41.4 KAPE on Disk
  5. 1.51.5 Collection Media and Destination
  6. 1.61.6 Your First Collection, Verified
  7. 1.7Module Summary
  8. 1.8Check My Knowledge

Phase 2: Running KAPE

Module 2KAPE Collection

The target file format field by field, how paths, masks and recursion combine to select files, what a published triage target actually collects rather than what its name implies, writing and testing a target of your own, shadow copies and containers, and the full target-side switch set with the verification that proves a collection matched its definition.

Show 8 lessonsHide lessons
  1. 2.12.1 The Target File
  2. 2.22.2 Paths, Masks and Recursion
  3. 2.32.3 What a Published Triage Target Actually Collects
  4. 2.42.4 Writing and Testing Your Own Target
  5. 2.52.5 Shadow Copies and Containers
  6. 2.62.6 The Collection Switch Set, and Proving It Worked
  7. 2.7Module Summary
  8. 2.8Check My Knowledge
Module 3KAPE Processing and Scale

The module file format and how a definition drives a program, the processing phase and its defaults, what the compound processing module actually runs, writing modules of your own, processing collections somebody else produced, and taking the whole pipeline to a fleet.

Show 8 lessonsHide lessons
  1. 3.13.1 The Module File
  2. 3.23.2 The Processing Phase
  3. 3.33.3 What the Compound Processing Module Runs
  4. 3.43.4 Writing Your Own Module
  5. 3.53.5 Processing Collections You Did Not Take
  6. 3.63.6 At Scale
  7. 3.7Module Summary
  8. 3.8Check My Knowledge

Phase 3: Reading the Artifacts

Module 4File System

Reading the file system as evidence: what a master file table record holds, the two sets of timestamps and why one of them resists tampering, parsing with MFTECmd, the change journal, the supporting metadata structures, and what the file system can and cannot establish.

Show 8 lessonsHide lessons
  1. 4.14.1 The Master File Table
  2. 4.24.2 The Two Timestamp Sets
  3. 4.34.3 Parsing the Table
  4. 4.44.4 The Change Journal
  5. 4.54.5 The Supporting Structures
  6. 4.64.6 What the File System Proves
  7. 4.7Module Summary
  8. 4.8Check My Knowledge
Module 5Execution and Resource Use

Four sources that partially answer what ran on a machine, what each actually proves, why their timestamps mean different things, and how to reconcile them into a defensible statement about execution.

Show 8 lessonsHide lessons
  1. 5.15.1 What Execution Actually Means
  2. 5.25.2 Prefetch
  3. 5.35.3 ShimCache
  4. 5.45.4 Amcache
  5. 5.55.5 Resource Usage
  6. 5.65.6 Reconciling the Sources
  7. 5.7Module Summary
  8. 5.8Check My Knowledge
Module 6Registry and User Activity

The artifacts that record what a person did rather than what a process did: registry hives and how to read them properly, devices and volumes, shortcut files, jump lists, shellbags, and what user activity evidence actually establishes.

Show 8 lessonsHide lessons
  1. 6.16.1 The Registry as Evidence
  2. 6.26.2 Accounts, Devices and Volumes
  3. 6.36.3 Shortcut Files
  4. 6.46.4 Jump Lists
  5. 6.56.5 Shellbags
  6. 6.66.6 Search, Execution and What It Proves
  7. 6.7Module Summary
  8. 6.8Check My Knowledge

Phase 4: To a Finding

Module 7Event Logs, Timelines and Findings

The only artifact written deliberately as a record: parsing event logs, reading authentication and sessions, joining process creation to the session that ran it, persistence and privilege, what a cleared log looks like, and taking one endpoint from a collection command to a written finding.

Show 8 lessonsHide lessons
  1. 7.17.1 Event Logs as Deliberate Records
  2. 7.27.2 Authentication and Sessions
  3. 7.37.3 What Ran, and Who Ran It
  4. 7.47.4 Persistence and Privilege
  5. 7.57.5 Anti-Forensics and Gaps
  6. 7.67.6 From Collection to Finding
  7. 7.7Module Summary
  8. 7.8Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

The licensing position, collection and processing syntax, the artifacts and what each proves, and where each one is silent.

Show 4 lessonsHide lessons
  1. 1What You May Run, and How to Collect
  2. 2Processing, and the Tools That Do It
  3. 3What Each Artifact Actually Proves
  4. 4From Collection to a Finding You Can Defend
ResourcesCookbooks

Ordered procedures for a first collection, remote triage, working an inherited collection, and reaching a defensible finding.

Show 4 lessonsHide lessons
  1. 1Collecting From a Live Machine
  2. 2Working an Inherited Collection
  3. 3Answering: Did This Program Run
  4. 4Answering: Did This User Take Data
ResourcesWalkthroughs

Four cases reasoned end to end, including the execution finding that was not one and the absence that was configuration.

Show 4 lessonsHide lessons
  1. 1The Execution That Was Not One
  2. 2The Wiped Machine That Was Not Wiped
  3. 3The Departure Nobody Could Prove
  4. 4The Collection That Could Not Answer
ResourcesPlayground

A Windows VM you can dirty, public evidence images, and the free reference page that sits alongside this course.

ResourcesOperational Reference

Every command, switch and definition from the course in one task-indexed reference, from building the toolkit and taking a collection to parsing each artifact family and merging the output into one timeline. The working kit you carry out of the course to the next endpoint.

Show 1 lessonHide lessons
  1. 1KE99.1 Operational Reference
ResourcesReferences & Further Reading

Where to check whether anything in this course has changed, the 2026 licensing position and why three published sources disagree about it, the authoritative source for each class of fact, and how the course was research-gated against primary material rather than against the legacy skill.

Course Completion

CompletionCourse Exam

KAPE and EZ Tools end-of-course exam: one triage collection from a host that no longer exists, three questions from IR, and the discipline of establishing what the evidence can support before answering any of it.

Show 1 lessonHide lessons
  1. 1Course Completion. KAPE and EZ Tools

Course overview

Most people meet these tools as a command somebody handed them. It works, it produces a directory of CSV files, and the parts that decide whether any of it holds up stay invisible: which definition ran, what it was specified to collect, what it skipped and why, and what each parsed column actually means. A collection that quietly missed the artifact you needed looks exactly like one that worked. So does a parser reading a registry hive whose most recent writes are still sitting in a transaction log.

✓ Targets and modules as text files you read, write, test and version, rather than names you pass to a command
✓ The proof step almost nobody runs: what the definition specified against what the copy log says arrived
✓ Four artifact families read for what they support and what they cannot, including the one most references still call execution evidence and is not
✓ The 2026 licensing position, which decides whether you can use half of this toolset in paid work and which most published material predates

The last module answers the question the others build toward: given seven modules of parsed output and one afternoon to account for, what can you write down and stand behind.

How this course works

Triage forensics is a decision about what to collect before you know what happened. This course runs the same loop for every artifact class it covers.

1. Collect narrow and fast, or broad and slow. KAPE targets decide this and the decision is irreversible on a host that gets rebuilt. Know what each target set actually reaches.

2. Separate collection from processing. Collect once, process many times. Processing on the live host wastes the one chance you had at the evidence.

3. Parse with the tool built for the artifact. Each Eric Zimmerman tool exists because a format needs it. Reading an artifact with the wrong parser produces plausible output and wrong answers.

4. Corroborate across artifact classes. Execution evidence in one artifact is a lead. The same execution in three artifacts, with consistent timestamps, is a finding.

5. Build the timeline last. A timeline assembled before the artifacts are understood inherits every parsing error in it.

What this course assumes

No minimum experience and no prerequisite course. The Windows artifacts, what each records and why it exists are explained where first used.

What makes it go faster: a Windows machine you can run the tools on and an image or a live system to practice against. Neither is required, and the course provides output for every artifact it examines.

What this course does not cover: memory forensics, malware analysis, and cloud investigation. This is disk triage on Windows, taught deeply, with the tooling that does it fastest.

Who this course is for

Anyone who has to answer a question about a Windows machine. There is no minimum experience and no gatekeeping: every concept is explained at first use, including the file system and registry structures the parsers read, so you can start here whether you have never run a collection or have been running one for years without reading its logs.

✓ Analysts who escalate endpoint questions and would rather answer them
✓ Incident responders who need a collection standard their team can run without them standing over it
✓ Consultants who receive containers other people collected and have to work from them
✓ Anybody who has run the standard command and wants to know what it did

What you'll learn

✓ Scope a collection against the question you were actually asked, and state in writing what it cannot answer
✓ Read any published definition and say what it will collect or execute before you run it, then write and test your own
✓ Prove a collection matched its specification using the copy log and the skip reasons, and work from a container somebody else took
✓ Reconstruct a file's history from the table, the journal and the structures that outlive a deletion
✓ Reconcile four execution sources that disagree, and know which of them proves a program ran and which does not
✓ Read the registry and user activity artifacts for what an account did, and the event logs for who was logged on and what they started
✓ Merge every parsed family into one sourced timeline and write a finding that separates what is established from what is consistent with it

Key course takeaways

✓ Your own collection and processing definitions, tested against a written expectation and versioned like any other code
✓ A collection record you can hand over: the command, the account, the times with their zone, the destination and the hash
✓ A coverage table per artifact family, written before you read anything, that decides what a silence is worth
✓ A merge that turns six directories of parsed output into one timeline carrying the source of every row
✓ A written finding with its limits stated first, and the wording that keeps intent out of a record that contains only actions

Things you need to know

What are the prerequisites for this course?

None. The course explains the file system, registry and execution structures at the point you first need them, and it does not assume you have run either toolset before.

Do I need a lab to follow along?

A Windows machine you own is enough, and the practice throughout is deliberately built on collecting from your own hardware. Working an ordinary day you can already account for is what teaches you what a normal machine looks like, which is the calibration that makes an unusual one recognizable.

What about the licensing? I do paid engagements.

Read this before you buy. The collector's own documentation states that from January 2026 it is no longer available for commercial use, meaning on a third party's network or as part of a paid engagement, while the vendor's marketing page still describes the older position and the Solo Edition agreement contradicts itself inside one document. The course teaches all three positions, says which is current, and gives the arrangement consultants actually use, which is the client's own team collecting and handing over the container.

The second half of that answer is why the course is still worth your time if you consult: the collector and the parsers are licensed differently. The parsers are free and open source with no commercial restriction, so four of the seven modules are unaffected either way.

How current is this?

Written against the 2026 tool line and research-gated against the tools' own documentation rather than against secondary material, which matters here because several widely repeated claims are wrong: one file system structure is listed as coming rather than shipping, and one execution artifact is routinely described as proving execution when it does not.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

The tools themselves carry their own licenses, which are the vendor's to set and change. Nothing in this course grants any right to use them, and the licensing position is covered so that you can check it rather than so that you can rely on our account of it.

Hosts, accounts, cases and parsed output are illustrative and constructed for teaching. Verify against your own collections and against each tool's current help output before relying on any specific behavior.

Ridgeline Cyber is not affiliated with Kroll, Microsoft, or the authors of the tools taught here. Product names are used descriptively.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.