Agent Foskett Academy • Defender for Endpoint

Microsoft Defender for Endpoint Academy.

The attack did not begin with a dashboard.

It began on a device. A process launched, a command executed, a file changed and a connection left the network.

Microsoft Defender for Endpoint gives defenders the telemetry needed to understand what happened on the endpoint, how the attacker moved and what evidence remains.

The Agent Foskett Defender for Endpoint Academy teaches endpoint security the practical way: one device, one process, one investigation and one response action at a time.

Agent Foskett Defender for Endpoint Academy learning path
Academy overview

Learn Microsoft Defender for Endpoint from the ground up, covering device telemetry, endpoint investigations, EDR, attack surface reduction, vulnerability management, Live Response and practical endpoint threat hunting.

Understand Defender for Endpoint telemetry
Investigate process, file, registry and network activity
Investigate, contain and remediate endpoint threats
Respond with isolation, indicators and Live Response

Defender for Endpoint Academy roadmap

This Academy builds Microsoft Defender for Endpoint knowledge progressively, from platform foundations and device visibility through to telemetry, investigations, attack surface reduction, exposure management and response.
Module 1 — Endpoint FoundationsWhat Defender for Endpoint is, how devices are onboarded, how endpoint telemetry is collected and how alerts connect to Microsoft Defender XDR.
Module 2 — Device TelemetryUnderstand DeviceInfo, DeviceEvents, DeviceProcessEvents, DeviceFileEvents, DeviceRegistryEvents, DeviceLogonEvents and DeviceNetworkEvents.
Module 3 — Endpoint InvestigationsInvestigate suspicious processes, parent-child relationships, file changes, network connections, registry activity and device timelines.
Module 4 — Attack Surface ReductionLearn ASR rules, controlled folder access, network protection, web protection, device control and hardening strategy.
Module 5 — Threat & Vulnerability ManagementUse TVM to identify exposed software, vulnerable devices, missing patches, weak configurations and security recommendations.
Module 6 — Response ActionsUse device isolation, collect investigation packages, restrict app execution, manage indicators and perform Live Response safely.
🔎 Take your endpoint investigation skills into the SOC.
Continue into the new SOC Analyst Academy and use Defender for Endpoint alongside KQL, Microsoft Sentinel, Entra and Security Copilot to triage alerts, investigate incidents, contain compromised devices and make defensible response decisions.
Open SOC Analyst Academy →

Academy Progress

21 of 21 planned lessons published.
The Defender for Endpoint Academy now provides a complete practical learning path covering endpoint telemetry, investigations, response, hardening and exposure management.

Microsoft Defender for Endpoint Academy Learning Path

A practical endpoint security curriculum organised into structured modules.
The learning path begins with Defender for Endpoint foundations, then moves into endpoint telemetry, investigations, hardening, exposure management and response.
 
Module 1 — Endpoint Foundations ✅ Complete Build a solid understanding of Microsoft Defender for Endpoint by learning how devices are onboarded, represented in Device Inventory, investigated through the Device Page and Device Timeline, analysed using alerts, and connected to Microsoft Defender XDR incidents.
✅ Module 1
Lesson 1 — What is Microsoft Defender for Endpoint? Understand Defender for Endpoint, endpoint detection and response, onboarding, device visibility and how endpoint signals become part of Microsoft Defender XDR investigations.
✅ Module 1
Lesson 2 — Microsoft Defender XDR vs Defender for Endpoint Understand the difference between the wider Defender XDR platform and the endpoint-focused capabilities of Defender for Endpoint, and learn how endpoint telemetry becomes part of cross-domain Microsoft Defender XDR investigations.
✅ Module 1
Lesson 3 — Understanding Device Inventory Learn how Microsoft Defender for Endpoint uses Device Inventory to identify onboarded devices, assess risk and exposure, monitor sensor health, and quickly pivot into endpoint investigations.
✅ Module 1
Lesson 4 — Understanding the Device Page Learn how the Microsoft Defender for Endpoint Device Page brings together device context, alerts, timeline activity, logged-on users, software, vulnerabilities, security recommendations and response actions.
✅ Module 1
Lesson 5 — Understanding the Device Timeline Learn how the Microsoft Defender for Endpoint Device Timeline helps analysts reconstruct attacks by following process, file, network, registry and logon activity in chronological order.
✅ Module 1
Lesson 6 — Understanding Endpoint Alerts Learn how Microsoft Defender for Endpoint creates alerts, interprets severity and evidence, maps detections to MITRE ATT&CK techniques, and connects endpoint activity to Microsoft Defender XDR incidents.
Module 2 — Endpoint Telemetry ✅ Complete Master the core Microsoft Defender for Endpoint Advanced Hunting tables by investigating process execution, network communication, file activity, registry changes, authentication events and broader device telemetry used during real-world endpoint investigations.
📘 Module 2
Lesson 7 — Investigating Process Events Learn how Microsoft Defender for Endpoint records process execution using DeviceProcessEvents, including command lines, parent-child relationships, user context, hashes, integrity levels and suspicious LOLBin activity.
📘 Module 2
Lesson 8 — Investigating DeviceNetworkEvents Learn how Microsoft Defender for Endpoint records network activity using DeviceNetworkEvents, allowing analysts to investigate remote IP addresses, domains, ports, protocols, initiating processes, command-and-control activity, lateral movement and data exfiltration.
📘 Module 2
Lesson 9 — Investigating DeviceFileEvents Learn how Microsoft Defender for Endpoint records file activity using DeviceFileEvents, allowing analysts to investigate file creation, modification, deletion, renaming, hashes, paths, initiating processes, malware staging, ransomware activity and attacker cleanup.
📘 Module 2
Lesson 10 — Investigating DeviceRegistryEvents Learn how Microsoft Defender for Endpoint records registry activity using DeviceRegistryEvents, allowing analysts to investigate registry keys, values, run keys, persistence mechanisms, startup changes, security configuration tampering and suspicious registry modifications.
📘 Module 2
Lesson 11 — Investigating DeviceLogonEvents Learn how Microsoft Defender for Endpoint records authentication activity using DeviceLogonEvents, allowing analysts to investigate interactive, remote interactive, network, batch and service logons, account usage, RDP sessions, suspicious credential activity and lateral movement.
📘 Module 2
Lesson 12 — Investigating DeviceEvents Learn how Microsoft Defender for Endpoint records broader endpoint activity using DeviceEvents, allowing analysts to investigate Defender Antivirus actions, USB activity, SmartScreen, exploit protection, device control, security setting changes and other endpoint telemetry that completes an investigation.
Module 3 — Endpoint Investigations 🚀 In Progress Build practical investigation and incident response skills using Advanced Hunting, Live Response, device isolation, indicators, investigation packages and Microsoft Defender Antivirus remediation actions.
📘 Module 3
Lesson 13 — Advanced Hunting in Defender for Endpoint Learn how to use Advanced Hunting and Kusto Query Language (KQL) to investigate endpoint telemetry, build hunting hypotheses, correlate multiple Defender tables, identify suspicious behaviour and create repeatable threat hunts.
📘 Module 3
Lesson 14 — Live Response Basics Learn how to use Microsoft Defender for Endpoint Live Response to investigate endpoints safely, collect evidence, run approved commands and scripts, and perform controlled incident response while preserving forensic integrity.
📘 Module 3
Lesson 15 — Device Isolation Learn when to isolate a compromised device, understand how isolation affects connectivity and validate successful containment in Microsoft Defender for Endpoint.
📘 Module 3
Lesson 16 — Indicators Learn how to create and manage file, certificate, IP address, URL and domain indicators to allow, audit, warn or block activity in Microsoft Defender for Endpoint.
📘 Module 3
Lesson 17 — Collect Investigation Package Learn how to collect investigation packages, preserve endpoint evidence and support deeper forensic analysis in Microsoft Defender for Endpoint.
📘 Module 3
Lesson 18 — Antivirus Scan and Remediation Actions Learn when to run quick and full antivirus scans, monitor remediation actions and validate endpoint recovery in Microsoft Defender for Endpoint.
Module 4 — Endpoint Hardening & Exposure Management Reduce endpoint attack paths using Attack Surface Reduction, Microsoft Defender Vulnerability Management and practical security recommendations.
📘 Module 4
Lesson 19 — Attack Surface Reduction Basics Learn how Attack Surface Reduction (ASR) rules prevent common attack techniques, safely transition from Audit to Block mode and reduce endpoint attack paths.
📘 Module 4
Lesson 20 — Threat and Vulnerability Management Learn how Microsoft Defender Vulnerability Management identifies vulnerable software, prioritises remediation using exposure and threat intelligence, and helps reduce endpoint risk.
📘 Module 4
Lesson 21 — Security Recommendations Learn how Microsoft Defender security recommendations prioritise remediation using exposure, threat intelligence, affected devices and measurable risk reduction.

Related Agent Foskett resources

The Defender for Endpoint Academy builds directly on existing Agent Foskett endpoint investigations and Advanced KQL lessons.
Investigating DeviceProcessEventsUse Defender XDR process telemetry to investigate process execution, parent-child activity, command lines and suspicious endpoint behaviour.
Investigating DeviceNetworkEventsInvestigate network connections, remote IPs, RemoteUrl, ports and process-to-network pivots from endpoint telemetry.
Investigating DeviceFileEventsTrack file creation, modification, deletion, hashes, paths and suspicious file activity across endpoints.
Investigating DeviceRegistryEventsHunt registry changes, persistence mechanisms, run keys and suspicious endpoint configuration changes.
Building a Device TimelineCorrelate process, file, registry, logon and network events into a clear device investigation timeline.
Hunting LOLBinsUse existing hunting content to identify living-off-the-land binaries and suspicious endpoint execution patterns.

Skills this Academy will build

Defender for Endpoint is not only a detection tool. It is an endpoint investigation, hardening, response and exposure management platform.
Endpoint investigationFollow processes, files, registry changes, logons and network connections to understand what happened on a device.
EDR responseKnow when to isolate a device, collect evidence, manage indicators and use Live Response during an active incident.
Attack surface reductionUse ASR, device control and endpoint hardening controls to reduce the opportunities attackers can exploit.
Exposure managementPrioritise vulnerable software, missing patches and weak endpoint configurations with threat and vulnerability management.
Custom detection logicBuild endpoint-focused KQL hunts and custom detections that identify suspicious process and device behaviour.
Enterprise endpoint strategyScale endpoint security across thousands of devices with consistent investigation and response workflows.
Continue your Defender for Endpoint journey
Twenty-one practical lessons are now available, covering endpoint foundations, telemetry, investigations, incident response, hardening and exposure management.
Start Learning

Final thought

Endpoint telemetry often shows the attack in motion. Learn to read it properly, and the device will tell you what happened.
Agent Foskett mindsetDo not treat endpoint alerts as isolated events. Build the process tree, follow the timeline, check the network activity and confirm what changed on the device.
SOC Analyst AcademyPut endpoint telemetry into a wider SOC investigation by correlating device evidence with identity, email, cloud and SIEM activity.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Defender for Endpoint Academy by Agent Foskett

The Agent Foskett Microsoft Defender for Endpoint Academy teaches endpoint security, EDR, device investigations, attack surface reduction, vulnerability management, Live Response and practical Microsoft endpoint defence.

Learn Microsoft Defender for Endpoint security and investigations

This Defender for Endpoint learning path explains device telemetry, process investigations, file activity, registry changes, network events, endpoint response actions, ASR, TVM and enterprise endpoint protection.

Microsoft Defender for Endpoint training for SOC analysts

The Defender for Endpoint Academy builds on the Agent Foskett KQL Academy and Microsoft Sentinel Academy by showing defenders how to investigate device signals, respond to endpoint incidents and harden Microsoft endpoint environments. The SOC Analyst Academy then applies these endpoint skills inside broader alert triage, investigation, containment and escalation workflows.