A Huntress SOC analyst walks through a real investigation triggered by a vague Microsoft Defender Managed Antivirus alert. The post covers the investigative methodology: collecting Windows Event Logs and Prefetch data, using Chainsaw in both hunt and search modes to parse WEVTXs, correlating Event ID 7045 (service install) with Event ID 4624 (successful authentication) to identify lateral movement, and resolving the offending binary to remcom via malware analysis. The post also emphasizes evidence-based reporting principles — speaking through evidence rather than assumptions, providing actionable recommendations, and avoiding unnecessary technical jargon in partner reports. It closes with a note on analyst confidence and the importance of having a solid investigative process.