The production VMDK still exists in its normal datastore, but it no longer exists in the referenced path.
What do you look for to investigate whether an incident occurred?

The production VMDK still exists in its normal datastore, but it no longer exists in the referenced path.
What do you look for to investigate whether an incident occurred?
Investigation Scenario 🔎
Windows Defender Event ID 5007 shows DisableRealtimeMonitoring changed from 0 to 1, yet MsMpEng.exe appears to still be running.
What do you look for to investigate whether an incident occurred?
Investigation Scenario 🔎
Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred.
What do you examine next to determine who added the credential and whether it was used?
What do you look for next to determine what the user actually opened and whether malicious execution followed?