Microsoft's has released a nice little "Guide" (Multipage Cheat Sheet) to Windows artifacts that you can/should collect during IR.
https://www.microsoft.com/en-us/security/blog/2024/04/23/new-microsoft-incident-response-guide-helps-simplify-cyberthreat-investigations/