Brad Garnett is the team leader in the Cisco Security Incident Response Services division. He works with organizations around the world. Brad writes about the power of logging in incident response.
PowerShell logging, Sysmon, an EDR solution such as Cisco AMP for Endpoints, and a memory forensics. This multi-layered approach allows for detection and response.
If you want to increase your ability to respond to incidents, you can contact Bred and his team.