Windows produces a lot of noise. L1 is not reciting Event IDs. It is asking: which channel, which account, what time, what sits next to it.
Start with Security (logon, process, account), then System (services), then PowerShell — if the lab policy actually logs scripts.
The ID cheat sheet is in Resources. Windows docs say which channels exist at all. Analysis pattern:
event → context → correlation → hypothesis → check
A lone 4624 is not proof of an incident. It is proof that someone (or something) logged on with a given logon type.