Thread.
One of the best things about working at @Mandiant is watching seasoned #DFIR pros join the team and then seeing their jaw drop when they see the bad ass tools we have. We get to spend more time analyzing the data than we do collecting and parsing it.
Want to collect authentication records stored locally on every endpoint and build a time bound graph of all network authentications for privileged users? Sure, click here.