I didn't start in threat investigation. I started in Tier 1 support.
Tier 1 to Tier 2. Then promoted into MSP Escalations based on investigation depth and evidence quality. Now I own the highest-severity enterprise and MSP cases.
What I figured out along the way: support and investigation are the same skill pointed at different questions.
Support asks: how do I make this stop?
Investigation asks: what actually happened, and can I prove it?
The second question is the one I can't stop asking. Every case is a story built from fragments: headers, traces, logs, timestamps that don't line up. The job is figuring out which story the evidence supports, not the one everyone already assumed.
If you read incident postmortems for fun, you already know what I mean.