Testlab
Windows core
Windows sysinternals
Windows event logs
Sysmon
Osquery basics
Configure and use tooling to detect suspicious activity.