It began on a device. A process launched, a command executed, a file changed and a connection left the network.
Microsoft Defender for Endpoint gives defenders the telemetry needed to understand what happened on the endpoint, how the attacker moved and what evidence remains.
The Agent Foskett Defender for Endpoint Academy teaches endpoint security the practical way: one device, one process, one investigation and one response action at a time.
Learn Microsoft Defender for Endpoint from the ground up, covering device telemetry, endpoint investigations, EDR, attack surface reduction, vulnerability management, Live Response and practical endpoint threat hunting.
Understand Defender for Endpoint telemetry
Investigate process, file, registry and network activity
Investigate, contain and remediate endpoint threats
Respond with isolation, indicators and Live Response
Defender for Endpoint Academy roadmap
This Academy builds Microsoft Defender for Endpoint knowledge progressively, from platform foundations and device visibility through to telemetry, investigations, attack surface reduction, exposure management and response.
Module 1 — Endpoint FoundationsWhat Defender for Endpoint is, how devices are onboarded, how endpoint telemetry is collected and how alerts connect to Microsoft Defender XDR.
Module 4 — Attack Surface ReductionLearn ASR rules, controlled folder access, network protection, web protection, device control and hardening strategy.
Module 6 — Response ActionsUse device isolation, collect investigation packages, restrict app execution, manage indicators and perform Live Response safely.
🔎 Take your endpoint investigation skills into the SOC. Continue into the new SOC Analyst Academy and use Defender for Endpoint alongside KQL, Microsoft Sentinel, Entra and Security Copilot to triage alerts, investigate incidents, contain compromised devices and make defensible response decisions.
Microsoft Defender for Endpoint Academy Learning Path
A practical endpoint security curriculum organised into structured modules.
The learning path begins with Defender for Endpoint foundations, then moves into endpoint telemetry, investigations, hardening, exposure management and response.
Module 1 — Endpoint FoundationsBuild a solid understanding of Microsoft Defender for Endpoint by learning how devices are onboarded, represented in Device Inventory, investigated through the Device Page and Device Timeline, analysed using alerts, and connected to Microsoft Defender XDR incidents.
Module 2 — Endpoint TelemetryMaster the core Microsoft Defender for Endpoint Advanced Hunting tables by investigating process execution, network communication, file activity, registry changes, authentication events and broader device telemetry used during real-world endpoint investigations.
The Defender for Endpoint Academy builds directly on existing Agent Foskett endpoint investigations and Advanced KQL lessons.
Investigating DeviceProcessEventsUse Defender XDR process telemetry to investigate process execution, parent-child activity, command lines and suspicious endpoint behaviour.
Investigating DeviceNetworkEventsInvestigate network connections, remote IPs, RemoteUrl, ports and process-to-network pivots from endpoint telemetry.
Investigating DeviceFileEventsTrack file creation, modification, deletion, hashes, paths and suspicious file activity across endpoints.
Investigating DeviceRegistryEventsHunt registry changes, persistence mechanisms, run keys and suspicious endpoint configuration changes.
Building a Device TimelineCorrelate process, file, registry, logon and network events into a clear device investigation timeline.
Hunting LOLBinsUse existing hunting content to identify living-off-the-land binaries and suspicious endpoint execution patterns.
Skills this Academy builds
Defender for Endpoint is not only a detection tool. It is an endpoint investigation, hardening, response and exposure management platform.
Endpoint investigationFollow processes, files, registry changes, logons and network connections to understand what happened on a device.
EDR responseKnow when to isolate a device, collect evidence, manage indicators and use Live Response during an active incident.
Attack surface reductionUse ASR, device control and endpoint hardening controls to reduce the opportunities attackers can exploit.
Exposure managementPrioritise vulnerable software, missing patches and weak endpoint configurations with threat and vulnerability management.
Custom detection logicBuild endpoint-focused KQL hunts and custom detections that identify suspicious process and device behaviour.
Enterprise endpoint strategyScale endpoint security across thousands of devices with consistent investigation and response workflows.
Continue your Defender for Endpoint journey Build practical Defender for Endpoint skills across endpoint foundations, telemetry, investigations, incident response, hardening and exposure management.
Endpoint telemetry often shows the attack in motion. Learn to read it properly, and the device will tell you what happened.
Agent Foskett mindsetDo not treat endpoint alerts as isolated events. Build the process tree, follow the timeline, check the network activity and confirm what changed on the device.
SOC Analyst AcademyPut endpoint telemetry into a wider SOC investigation by correlating device evidence with identity, email, cloud and SIEM activity.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD
Microsoft Defender for Endpoint Academy by Agent Foskett
The Agent Foskett Microsoft Defender for Endpoint Academy teaches endpoint security, EDR, device investigations, attack surface reduction, vulnerability management, Live Response and practical Microsoft endpoint defence.
Learn Microsoft Defender for Endpoint security and investigations
This Defender for Endpoint learning path explains device telemetry, process investigations, file activity, registry changes, network events, endpoint response actions, ASR, TVM and enterprise endpoint protection.
Microsoft Defender for Endpoint training for SOC analysts
The Defender for Endpoint Academy builds on the Agent Foskett KQL Academy and Microsoft Sentinel Academy by showing defenders how to investigate device signals, respond to endpoint incidents and harden Microsoft endpoint environments. The SOC Analyst Academy then applies these endpoint skills inside broader alert triage, investigation, containment and escalation workflows.