Endpoint detection and response (EDR)
Configure and use tooling to detect suspicious activity.

Windows core
Windows sysinternals
Windows event logs
Sysmon
Osquery basics
Configure and use tooling to detect suspicious activity.
Windows core
Windows sysinternals
Windows event logs
Sysmon
Osquery basics