Microsoft Defender for Endpoint Academy.
The attack did not begin with a dashboard.
It began on a device. A process launched, a command executed, a file changed and a connection left the network.
Microsoft Defender for Endpoint gives defenders the telemetry needed to understand what happened on the endpoint, how the attacker moved and what evidence remains.
The Agent Foskett Defender for Endpoint Academy teaches endpoint security the practical way: one device, one process, one investigation and one response action at a time.
Academy overview
Learn Microsoft Defender for Endpoint from the ground up, covering device telemetry, endpoint investigations, EDR, attack surface reduction, vulnerability management, Live Response and practical endpoint threat hunting.
Defender for Endpoint Academy roadmap
Academy Progress
The Defender for Endpoint Academy now provides a complete practical learning path covering endpoint telemetry, investigations, response, hardening and exposure management.
Microsoft Defender for Endpoint Academy Learning Path
The learning path begins with Defender for Endpoint foundations, then moves into endpoint telemetry, investigations, hardening, exposure management and response.
Related Agent Foskett resources
Skills this Academy will build
Final thought
Microsoft Defender for Endpoint Academy by Agent Foskett
The Agent Foskett Microsoft Defender for Endpoint Academy teaches endpoint security, EDR, device investigations, attack surface reduction, vulnerability management, Live Response and practical Microsoft endpoint defence.
Learn Microsoft Defender for Endpoint security and investigations
This Defender for Endpoint learning path explains device telemetry, process investigations, file activity, registry changes, network events, endpoint response actions, ASR, TVM and enterprise endpoint protection.
Microsoft Defender for Endpoint training for SOC analysts
The Defender for Endpoint Academy builds on the Agent Foskett KQL Academy and Microsoft Sentinel Academy by showing defenders how to investigate device signals, respond to endpoint incidents and harden Microsoft endpoint environments. The SOC Analyst Academy then applies these endpoint skills inside broader alert triage, investigation, containment and escalation workflows.
