After having an incident where a device was registered by a threat actor, I noticed that this was not reflected in the timeline. A timeline missing events easily surfaced in the user's audit log isn't the most valuable. The timeline needs to reflect all surfaced threat actor activity - not omit events that thereby make the timeline inaccurate.
The reason this was omitted is even more concerning: rogue device registrations aren't monitored by ITDR. Not sure why this info isn't monitored by the SOC, but this is a major visibility gap.
The timeline should reflect all events from the IP associated with the threat actor's session, and the SOC should have visibility and utilize info present from user audit log events to surface info like rogue device registrations which apparently aren't monitored