Windows Event Forwarding: using windows event forwarding for incident detection and response