KAPE and EZ Tools
Collect what answers the question. Prove it arrived. Read what came back.
A triage collection takes ninety seconds and gives you a few gigabytes instead of a few hundred, which is why it is how most Windows investigations now start. What decides whether it was worth taking is everything around it: whether the definition collected what you thought, whether you can prove it, and whether you can read the binary structures that came back and say what they support. This course teaches the whole pipeline as one piece of work. You write and version your own collection definitions, prove a collection against its specification, drive every parser in the suite, and take one endpoint from the collection command to a written finding.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Course Orientation
What this course teaches: how KAPE collects and processes in two separate phases, how to build targets and modules that fit your investigation, which EZ Tool answers which question, and how to read the output well enough to write a defensible finding. Start here.
Phase 1: The Toolkit
When triage collection is the right answer and when it is the wrong one, what KAPE cannot reach, the licensing line that decides whether you may run it at all, how to install EZ Tools so the tools actually launch, how KAPE is laid out on disk and how it finds its own configuration, how to prepare collection media without contaminating the source, and a first verified collection off a live machine.
Show 8 lessonsHide lessons
Phase 2: Running KAPE
The target file format field by field, how paths, masks and recursion combine to select files, what a published triage target actually collects rather than what its name implies, writing and testing a target of your own, shadow copies and containers, and the full target-side switch set with the verification that proves a collection matched its definition.
Show 8 lessonsHide lessons
The module file format and how a definition drives a program, the processing phase and its defaults, what the compound processing module actually runs, writing modules of your own, processing collections somebody else produced, and taking the whole pipeline to a fleet.
Phase 3: Reading the Artifacts
Reading the file system as evidence: what a master file table record holds, the two sets of timestamps and why one of them resists tampering, parsing with MFTECmd, the change journal, the supporting metadata structures, and what the file system can and cannot establish.
Four sources that partially answer what ran on a machine, what each actually proves, why their timestamps mean different things, and how to reconcile them into a defensible statement about execution.
The artifacts that record what a person did rather than what a process did: registry hives and how to read them properly, devices and volumes, shortcut files, jump lists, shellbags, and what user activity evidence actually establishes.
Phase 4: To a Finding
The only artifact written deliberately as a record: parsing event logs, reading authentication and sessions, joining process creation to the session that ran it, persistence and privilege, what a cleared log looks like, and taking one endpoint from a collection command to a written finding.
Phase 0: Course Resources
The licensing position, collection and processing syntax, the artifacts and what each proves, and where each one is silent.
Ordered procedures for a first collection, remote triage, working an inherited collection, and reaching a defensible finding.
Four cases reasoned end to end, including the execution finding that was not one and the absence that was configuration.
A Windows VM you can dirty, public evidence images, and the free reference page that sits alongside this course.
Every command, switch and definition from the course in one task-indexed reference, from building the toolkit and taking a collection to parsing each artifact family and merging the output into one timeline. The working kit you carry out of the course to the next endpoint.
Show 1 lessonHide lessons
Where to check whether anything in this course has changed, the 2026 licensing position and why three published sources disagree about it, the authoritative source for each class of fact, and how the course was research-gated against primary material rather than against the legacy skill.
Course Completion
KAPE and EZ Tools end-of-course exam: one triage collection from a host that no longer exists, three questions from IR, and the discipline of establishing what the evidence can support before answering any of it.
Show 1 lessonHide lessons
Course overview
Most people meet these tools as a command somebody handed them. It works, it produces a directory of CSV files, and the parts that decide whether any of it holds up stay invisible: which definition ran, what it was specified to collect, what it skipped and why, and what each parsed column actually means. A collection that quietly missed the artifact you needed looks exactly like one that worked. So does a parser reading a registry hive whose most recent writes are still sitting in a transaction log.
The last module answers the question the others build toward: given seven modules of parsed output and one afternoon to account for, what can you write down and stand behind.
How this course works
Triage forensics is a decision about what to collect before you know what happened. This course runs the same loop for every artifact class it covers.
1. Collect narrow and fast, or broad and slow. KAPE targets decide this and the decision is irreversible on a host that gets rebuilt. Know what each target set actually reaches.
2. Separate collection from processing. Collect once, process many times. Processing on the live host wastes the one chance you had at the evidence.
3. Parse with the tool built for the artifact. Each Eric Zimmerman tool exists because a format needs it. Reading an artifact with the wrong parser produces plausible output and wrong answers.
4. Corroborate across artifact classes. Execution evidence in one artifact is a lead. The same execution in three artifacts, with consistent timestamps, is a finding.
5. Build the timeline last. A timeline assembled before the artifacts are understood inherits every parsing error in it.
What this course assumes
No minimum experience and no prerequisite course. The Windows artifacts, what each records and why it exists are explained where first used.
What makes it go faster: a Windows machine you can run the tools on and an image or a live system to practice against. Neither is required, and the course provides output for every artifact it examines.
What this course does not cover: memory forensics, malware analysis, and cloud investigation. This is disk triage on Windows, taught deeply, with the tooling that does it fastest.
Who this course is for
Anyone who has to answer a question about a Windows machine. There is no minimum experience and no gatekeeping: every concept is explained at first use, including the file system and registry structures the parsers read, so you can start here whether you have never run a collection or have been running one for years without reading its logs.
What you'll learn
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None. The course explains the file system, registry and execution structures at the point you first need them, and it does not assume you have run either toolset before.
Do I need a lab to follow along?
A Windows machine you own is enough, and the practice throughout is deliberately built on collecting from your own hardware. Working an ordinary day you can already account for is what teaches you what a normal machine looks like, which is the calibration that makes an unusual one recognizable.
What about the licensing? I do paid engagements.
Read this before you buy. The collector's own documentation states that from January 2026 it is no longer available for commercial use, meaning on a third party's network or as part of a paid engagement, while the vendor's marketing page still describes the older position and the Solo Edition agreement contradicts itself inside one document. The course teaches all three positions, says which is current, and gives the arrangement consultants actually use, which is the client's own team collecting and handing over the container.
The second half of that answer is why the course is still worth your time if you consult: the collector and the parsers are licensed differently. The parsers are free and open source with no commercial restriction, so four of the seven modules are unaffected either way.
How current is this?
Written against the 2026 tool line and research-gated against the tools' own documentation rather than against secondary material, which matters here because several widely repeated claims are wrong: one file system structure is listed as coming rather than shipping, and one execution artifact is routinely described as proving execution when it does not.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
The tools themselves carry their own licenses, which are the vendor's to set and change. Nothing in this course grants any right to use them, and the licensing position is covered so that you can check it rather than so that you can rely on our account of it.
Hosts, accounts, cases and parsed output are illustrative and constructed for teaching. Verify against your own collections and against each tool's current help output before relying on any specific behavior.
Ridgeline Cyber is not affiliated with Kroll, Microsoft, or the authors of the tools taught here. Product names are used descriptively.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.