Job Description: Perform live-state memory captures, extract Master File Tables (MFT), and collect forensic system artifacts across Windows, Linux, and macOS endpoints using enterprise tools. Reconstruct complex, multi-stage attack timelines by correlating telemetry across cloud infrastructure