The References You Reach for at 2 AM.

Investigation runbooks that walk you through incidents step by step. Triage scorecards that classify alerts in under 5 minutes. KQL queries you copy-paste into Sentinel during a live investigation. Forensic artifact references that tell you exactly where to look. Free, no account required — bookmark them now, use them when it matters.

Investigation & Response

Investigation & Response Tools

When an alert fires, you open these. The runbooks tell you what to check and in what order. The triage scorecard classifies the severity in under 5 minutes. The forensic references tell you exactly which artifact to examine and where to find it. The difference between "I need to think about this" and "I know the next step."

The Tools Give You the Reference. The Courses Teach the Methodology.

Every tool is extracted from a Ridgeline course. The courses add the judgment, context, and operational depth.

Browse All Courses Start a Free Module