Investigate threats using Windows Event logs (PowerShell, login activity), firewall, proxy, and WAF logs.