KAPE and EZ Tools

Collect what answers the question. Prove it arrived. Read what came back.

A triage collection takes ninety seconds and gives you a few gigabytes instead of a few hundred, which is why it is how most Windows investigations now start. What decides whether it was worth taking is everything around it: whether the definition collected what you thought, whether you can prove it, and whether you can read the binary structures that came back and say what they support. This course teaches the whole pipeline as one piece of work. You write and version your own collection definitions, prove a collection against its specification, drive every parser in the suite, and take one endpoint from the collection command to a written finding.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 10 CPE Credits

What you'll be able to do

Scope a triage collection against the question you were actually asked, and state in writing what it cannot answer
Read any published target or module definition and say exactly what it will collect or execute before you run it, then write, test and version your own
Prove a collection matched its definition using the specification count, the copy log and the skip reasons, then run the same pipeline across a fleet and on containers somebody else collected
Reconstruct a file's history from the master file table, the change journal and the structures that outlive a deletion
Reconcile four execution sources that disagree, and say which of them establishes that a program ran and which only establishes it was present
Read the registry and user activity artifacts for what an account did, then the event logs for who was logged on and what they started inside that session
Merge every parsed family into one sourced timeline and write a finding that separates what is established from what is only consistent with it
FOR201 | Essentials tier | 7 modules across 4 phases | 10–12 hours at your own pace | 10 CPE credits | Updated July 2026
Course Agenda View Course ModulesHide Course Modules

Course overview

Most people meet these tools as a command somebody handed them. It works, it produces a directory of CSV files, and the parts that decide whether any of it holds up stay invisible: which definition ran, what it was specified to collect, what it skipped and why, and what each parsed column actually means. A collection that quietly missed the artifact you needed looks exactly like one that worked. So does a parser reading a registry hive whose most recent writes are still sitting in a transaction log.

Targets and modules as text files you read, write, test and version, rather than names you pass to a command
The proof step almost nobody runs: what the definition specified against what the copy log says arrived
Four artifact families read for what they support and what they cannot, including the one most references still call execution evidence and is not
The 2026 licensing position, which decides whether you can use half of this toolset in paid work and which most published material predates

The last module answers the question the others build toward: given seven modules of parsed output and one afternoon to account for, what can you write down and stand behind.

Who this course is for

Anyone who has to answer a question about a Windows machine. There is no minimum experience and no gatekeeping: every concept is explained at first use, including the file system and registry structures the parsers read, so you can start here whether you have never run a collection or have been running one for years without reading its logs.

Analysts who escalate endpoint questions and would rather answer them
Incident responders who need a collection standard their team can run without them standing over it
Consultants who receive containers other people collected and have to work from them
Anybody who has run the standard command and wants to know what it did

What you'll learn

Scope a collection against the question you were actually asked, and state in writing what it cannot answer
Read any published definition and say what it will collect or execute before you run it, then write and test your own
Prove a collection matched its specification using the copy log and the skip reasons, and work from a container somebody else took
Reconstruct a file's history from the table, the journal and the structures that outlive a deletion
Reconcile four execution sources that disagree, and know which of them proves a program ran and which does not
Read the registry and user activity artifacts for what an account did, and the event logs for who was logged on and what they started
Merge every parsed family into one sourced timeline and write a finding that separates what is established from what is consistent with it

Key course takeaways

Your own collection and processing definitions, tested against a written expectation and versioned like any other code
A collection record you can hand over: the command, the account, the times with their zone, the destination and the hash
A coverage table per artifact family, written before you read anything, that decides what a silence is worth
A merge that turns six directories of parsed output into one timeline carrying the source of every row
A written finding with its limits stated first, and the wording that keeps intent out of a record that contains only actions

Things you need to know

What are the prerequisites for this course?

None. The course explains the file system, registry and execution structures at the point you first need them, and it does not assume you have run either toolset before.

Do I need a lab to follow along?

A Windows machine you own is enough, and the practice throughout is deliberately built on collecting from your own hardware. Working an ordinary day you can already account for is what teaches you what a normal machine looks like, which is the calibration that makes an unusual one recognizable.

What about the licensing? I do paid engagements.

Read this before you buy. The collector's own documentation states that from January 2026 it is no longer available for commercial use, meaning on a third party's network or as part of a paid engagement, while the vendor's marketing page still describes the older position and the Solo Edition agreement contradicts itself inside one document. The course teaches all three positions, says which is current, and gives the arrangement consultants actually use, which is the client's own team collecting and handing over the container.

The second half of that answer is why the course is still worth your time if you consult: the collector and the parsers are licensed differently. The parsers are free and open source with no commercial restriction, so four of the seven modules are unaffected either way.

How current is this?

Written against the 2026 tool line and research-gated against the tools' own documentation rather than against secondary material, which matters here because several widely repeated claims are wrong: one file system structure is listed as coming rather than shipping, and one execution artifact is routinely described as proving execution when it does not.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

The tools themselves carry their own licenses, which are the vendor's to set and change. Nothing in this course grants any right to use them, and the licensing position is covered so that you can check it rather than so that you can rely on our account of it.

Hosts, accounts, cases and parsed output are illustrative and constructed for teaching. Verify against your own collections and against each tool's current help output before relying on any specific behavior.

Ridgeline Cyber is not affiliated with Kroll, Microsoft, or the authors of the tools taught here. Product names are used descriptively.

Version and changelog

Version 1.0 · July 2026

Initial release as FOR201, replacing the earlier KAPE and EZ Tools short course. Seven modules across the toolkit, collection, processing at scale, the file system, execution and resource use, the registry and user activity, and the event logs, closing with one endpoint worked from the collection command to a written finding. An operational reference and a references module follow the content.

Rebuilt rather than migrated. The earlier version mentioned licensing zero times and the runtime requirement zero times, which are the two things most likely to stop a cybersecurity professional before they parse anything. Four tools absent from it are covered here, and the module balance was set by the investigative question rather than by tool name.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.