Devices
Brief
Something I learned very early on as a DF/IR consultant was that you're likely never going to run into a perfect environment as an on-call responder. In fact, the best you can hope for is an environment with the default logging, for the OS and applications, and that the logs haven't been cleared. Even then, those two conditions aren't always the case.
Even today, in 2026, I regularly see environments where auditing of successful logins has been disabled, so they don't appear in the Security Event Log.
As such, it's not only important to keep up with what's available from the default installation of an endpoint, and what sources can be used to validate your findings, but also note what's available depending upon the applications installed.
However, what's most important are your analysis goals.
