Security.evtx (The Holy Grail)
The most critical log for tracking adversarial behavior. It records authentication (logons/logoffs), privilege escalation, process creation, and object access. Forensic Note: Many critical events in this log require explicit Group Policy Object (GPO) auditing to be enabled.