Agent Foskett Academy • Defender for Endpoint

Microsoft Defender for Endpoint Academy.

The attack did not begin with a dashboard.

It began on a device. A process launched, a command executed, a file changed and a connection left the network.

Microsoft Defender for Endpoint gives defenders the telemetry needed to understand what happened on the endpoint, how the attacker moved and what evidence remains.

The Agent Foskett Defender for Endpoint Academy teaches endpoint security the practical way: one device, one process, one investigation and one response action at a time.

Agent Foskett Defender for Endpoint Academy learning path
Academy overview

Learn Microsoft Defender for Endpoint from the ground up, covering device telemetry, endpoint investigations, EDR, attack surface reduction, vulnerability management, Live Response and practical endpoint threat hunting.

Understand Defender for Endpoint telemetry
Investigate process, file, registry and network activity
Use ASR, TVM and device control effectively
Respond with isolation, indicators and Live Response

Defender for Endpoint Academy roadmap

This Academy builds Microsoft Defender for Endpoint knowledge progressively, from platform foundations and device visibility through to telemetry, investigations, attack surface reduction, exposure management and response.
Module 1 — Endpoint FoundationsWhat Defender for Endpoint is, how devices are onboarded, how endpoint telemetry is collected and how alerts connect to Microsoft Defender XDR.
Module 2 — Device TelemetryUnderstand DeviceInfo, DeviceEvents, DeviceProcessEvents, DeviceFileEvents, DeviceRegistryEvents, DeviceLogonEvents and DeviceNetworkEvents.
Module 3 — Endpoint InvestigationsInvestigate suspicious processes, parent-child relationships, file changes, network connections, registry activity and device timelines.
Module 4 — Attack Surface ReductionLearn ASR rules, controlled folder access, network protection, web protection, device control and hardening strategy.
Module 5 — Threat & Vulnerability ManagementUse TVM to identify exposed software, vulnerable devices, missing patches, weak configurations and security recommendations.
Module 6 — Response ActionsUse device isolation, collect investigation packages, restrict app execution, manage indicators and perform Live Response safely.

Microsoft Defender for Endpoint Academy Learning Path

A practical endpoint security curriculum organised into structured modules.
The learning path begins with Defender for Endpoint foundations, then moves into endpoint telemetry, investigations, hardening, exposure management and response.
 
Module 1 — Endpoint Foundations ✅ Complete Build a solid understanding of Microsoft Defender for Endpoint by learning how devices are onboarded, represented in Device Inventory, investigated through the Device Page and Device Timeline, analysed using alerts, and connected to Microsoft Defender XDR incidents.
✅ Module 1
Lesson 1 — What is Microsoft Defender for Endpoint? Understand Defender for Endpoint, endpoint detection and response, onboarding, device visibility and how endpoint signals become part of Microsoft Defender XDR investigations.
✅ Module 1
Lesson 2 — Microsoft Defender XDR vs Defender for Endpoint Understand the difference between the wider Defender XDR platform and the endpoint-focused capabilities of Defender for Endpoint, and learn how endpoint telemetry becomes part of cross-domain Microsoft Defender XDR investigations.
✅ Module 1
Lesson 3 — Understanding Device Inventory Learn how Microsoft Defender for Endpoint uses Device Inventory to identify onboarded devices, assess risk and exposure, monitor sensor health, and quickly pivot into endpoint investigations.
✅ Module 1
Lesson 4 — Understanding the Device Page Learn how the Microsoft Defender for Endpoint Device Page brings together device context, alerts, timeline activity, logged-on users, software, vulnerabilities, security recommendations and response actions.
✅ Module 1
Lesson 5 — Understanding the Device Timeline Learn how the Microsoft Defender for Endpoint Device Timeline helps analysts reconstruct attacks by following process, file, network, registry and logon activity in chronological order.
✅ Module 1
Lesson 6 — Understanding Endpoint Alerts Learn how Microsoft Defender for Endpoint creates alerts, interprets severity and evidence, maps detections to MITRE ATT&CK techniques, and connects endpoint activity to Microsoft Defender XDR incidents.
Module 2 — Endpoint Telemetry 🚀 In Progress Learn how Microsoft Defender for Endpoint records endpoint activity through Advanced Hunting tables, including process execution, network connections, file activity, registry changes, logons and broader device telemetry used during investigations.
📘 Module 2
Lesson 7 — Investigating Process Events Learn how Microsoft Defender for Endpoint records process execution using DeviceProcessEvents, including command lines, parent-child relationships, user context, hashes, integrity levels and suspicious LOLBin activity.
Module 3 — Endpoint Investigations 📚 Planned Build practical workflows using Advanced Hunting, device timelines, evidence collection, indicators, isolation and Live Response.
Module 4 — Hardening and Exposure Management 📚 Planned Reduce endpoint attack paths with Attack Surface Reduction, vulnerability management and prioritised security recommendations.

Related Agent Foskett resources

The Defender for Endpoint Academy builds directly on existing Agent Foskett endpoint investigations and Advanced KQL lessons.
Investigating DeviceProcessEventsUse Defender XDR process telemetry to investigate process execution, parent-child activity, command lines and suspicious endpoint behaviour.
Investigating DeviceNetworkEventsInvestigate network connections, remote IPs, RemoteUrl, ports and process-to-network pivots from endpoint telemetry.
Investigating DeviceFileEventsTrack file creation, modification, deletion, hashes, paths and suspicious file activity across endpoints.
Investigating DeviceRegistryEventsHunt registry changes, persistence mechanisms, run keys and suspicious endpoint configuration changes.
Building a Device TimelineCorrelate process, file, registry, logon and network events into a clear device investigation timeline.
Hunting LOLBinsUse existing hunting content to identify living-off-the-land binaries and suspicious endpoint execution patterns.

Skills this Academy will build

Defender for Endpoint is not only a detection tool. It is an endpoint investigation, hardening, response and exposure management platform.
Endpoint investigationFollow processes, files, registry changes, logons and network connections to understand what happened on a device.
EDR responseKnow when to isolate a device, collect evidence, manage indicators and use Live Response during an active incident.
Attack surface reductionUse ASR, device control and endpoint hardening controls to reduce the opportunities attackers can exploit.
Exposure managementPrioritise vulnerable software, missing patches and weak endpoint configurations with threat and vulnerability management.
Custom detection logicBuild endpoint-focused KQL hunts and custom detections that identify suspicious process and device behaviour.
Enterprise endpoint strategyScale endpoint security across thousands of devices with consistent investigation and response workflows.
First lesson coming next
Lesson 1 will introduce Microsoft Defender for Endpoint, explain endpoint detection and response, and show how device signals become part of Microsoft Defender XDR investigations.
Review Learning Path

Final thought

Endpoint telemetry often shows the attack in motion. Learn to read it properly, and the device will tell you what happened.
Agent Foskett mindsetDo not treat endpoint alerts as isolated events. Build the process tree, follow the timeline, check the network activity and confirm what changed on the device.
New Academy SeriesThe Defender for Endpoint Academy expands Agent Foskett from KQL and XDR investigations into practical endpoint protection, EDR response and device security operations.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Defender for Endpoint Academy by Agent Foskett

The Agent Foskett Microsoft Defender for Endpoint Academy teaches endpoint security, EDR, device investigations, attack surface reduction, vulnerability management, Live Response and practical Microsoft endpoint defence.

Learn Microsoft Defender for Endpoint security and investigations

This Defender for Endpoint learning path explains device telemetry, process investigations, file activity, registry changes, network events, endpoint response actions, ASR, TVM and enterprise endpoint protection.

Microsoft Defender for Endpoint training for SOC analysts

The Defender for Endpoint Academy builds on the Agent Foskett KQL Academy and Microsoft Sentinel Academy by showing defenders how to investigate device signals, respond to endpoint incidents and harden Microsoft endpoint environments.