You will also turn investigation findings into technical notes for account-facing teams, actionable feedback for Product and Detection Engineering, new detections, repeatable playbooks, and automation opportunities, as well as validate case findings to be put in use for scalable threat intelligence. Strong knowledge of common forensic artefacts, including event logs, registry data, prefetch, jump lists, shellbags, scheduled tasks, services, browser artefacts, and authentication activity.