It began on a device. A process launched, a command executed, a file changed and a connection left the network.
Microsoft Defender for Endpoint gives defenders the telemetry needed to understand what happened on the endpoint, how the attacker moved and what evidence remains.
The Agent Foskett Defender for Endpoint Academy teaches endpoint security the practical way: one device, one process, one investigation and one response action at a time.
Learn Microsoft Defender for Endpoint from the ground up, covering device telemetry, endpoint investigations, EDR, attack surface reduction, vulnerability management, Live Response and practical endpoint threat hunting.
Understand Defender for Endpoint telemetry
Investigate process, file, registry and network activity
Use ASR, TVM and device control effectively
Respond with isolation, indicators and Live Response
Defender for Endpoint Academy roadmap
This Academy builds Microsoft Defender for Endpoint knowledge progressively, from platform foundations and device visibility through to telemetry, investigations, attack surface reduction, exposure management and response.
Module 1 — Endpoint FoundationsWhat Defender for Endpoint is, how devices are onboarded, how endpoint telemetry is collected and how alerts connect to Microsoft Defender XDR.
Module 4 — Attack Surface ReductionLearn ASR rules, controlled folder access, network protection, web protection, device control and hardening strategy.
Module 6 — Response ActionsUse device isolation, collect investigation packages, restrict app execution, manage indicators and perform Live Response safely.
Microsoft Defender for Endpoint Academy Learning Path
A practical endpoint security curriculum organised into structured modules.
The learning path begins with Defender for Endpoint foundations, then moves into endpoint telemetry, investigations, hardening, exposure management and response.
Module 1 — Endpoint Foundations ✅ CompleteBuild a solid understanding of Microsoft Defender for Endpoint by learning how devices are onboarded, represented in Device Inventory, investigated through the Device Page and Device Timeline, analysed using alerts, and connected to Microsoft Defender XDR incidents.
Module 2 — Endpoint Telemetry 🚀 In ProgressLearn how Microsoft Defender for Endpoint records endpoint activity through Advanced Hunting tables, including process execution, network connections, file activity, registry changes, logons and broader device telemetry used during investigations.
Lesson 8 — Investigating DeviceNetworkEventsTrack remote IP addresses, domains, URLs, ports, initiating processes and possible command-and-control activity.
📚 Module 2
Lesson 9 — Investigating DeviceFileEventsTrack file creation, modification, deletion, hashes, paths and the processes responsible for suspicious file activity.
📚 Module 2
Lesson 10 — Investigating DeviceRegistryEventsHunt for persistence, run keys, configuration changes and suspicious registry modifications.
📚 Module 2
Lesson 11 — Investigating DeviceLogonEventsUnderstand local, remote, interactive and network logons and how they support identity and lateral movement investigations.
📚 Module 2
Lesson 12 — Investigating DeviceEventsUse broader endpoint action telemetry to investigate Defender actions, security controls and miscellaneous device activity.
Module 3 — Endpoint Investigations 📚 PlannedBuild practical workflows using Advanced Hunting, device timelines, evidence collection, indicators, isolation and Live Response.
📚 Module 3
Lesson 13 — Advanced Hunting in Defender for EndpointUse endpoint-focused KQL to form hypotheses, investigate suspicious behaviour and create repeatable hunts.
📚 Module 3
Lesson 14 — Live Response BasicsUnderstand Live Response sessions, evidence collection, command safety and operational precautions.
📚 Module 3
Lesson 15 — Device IsolationLearn when to isolate a device, how isolation affects connectivity and how to validate the response action.
📚 Module 3
Lesson 16 — IndicatorsUse file, certificate, IP, URL and domain indicators to allow, block or audit endpoint activity.
📚 Module 3
Lesson 17 — Investigation PackagesCollect endpoint artefacts and understand how investigation packages support deeper device analysis.
Module 4 — Hardening and Exposure Management 📚 PlannedReduce endpoint attack paths with Attack Surface Reduction, vulnerability management and prioritised security recommendations.
📚 Module 4
Lesson 18 — Attack Surface Reduction BasicsPlan, audit, test and enforce ASR rules safely while reducing common attack techniques.
📚 Module 4
Lesson 19 — Threat and Vulnerability ManagementIdentify vulnerable software, exposed devices, missing patches and configuration weaknesses.
📚 Module 4
Lesson 20 — Security RecommendationsPrioritise remediation using exposure, threat context, affected devices and practical risk reduction.
Related Agent Foskett resources
The Defender for Endpoint Academy builds directly on existing Agent Foskett endpoint investigations and Advanced KQL lessons.
Investigating DeviceProcessEventsUse Defender XDR process telemetry to investigate process execution, parent-child activity, command lines and suspicious endpoint behaviour.
Investigating DeviceNetworkEventsInvestigate network connections, remote IPs, RemoteUrl, ports and process-to-network pivots from endpoint telemetry.
Investigating DeviceFileEventsTrack file creation, modification, deletion, hashes, paths and suspicious file activity across endpoints.
Investigating DeviceRegistryEventsHunt registry changes, persistence mechanisms, run keys and suspicious endpoint configuration changes.
Building a Device TimelineCorrelate process, file, registry, logon and network events into a clear device investigation timeline.
Hunting LOLBinsUse existing hunting content to identify living-off-the-land binaries and suspicious endpoint execution patterns.
Skills this Academy will build
Defender for Endpoint is not only a detection tool. It is an endpoint investigation, hardening, response and exposure management platform.
Endpoint investigationFollow processes, files, registry changes, logons and network connections to understand what happened on a device.
EDR responseKnow when to isolate a device, collect evidence, manage indicators and use Live Response during an active incident.
Attack surface reductionUse ASR, device control and endpoint hardening controls to reduce the opportunities attackers can exploit.
Exposure managementPrioritise vulnerable software, missing patches and weak endpoint configurations with threat and vulnerability management.
Custom detection logicBuild endpoint-focused KQL hunts and custom detections that identify suspicious process and device behaviour.
Enterprise endpoint strategyScale endpoint security across thousands of devices with consistent investigation and response workflows.
First lesson coming next Lesson 1 will introduce Microsoft Defender for Endpoint, explain endpoint detection and response, and show how device signals become part of Microsoft Defender XDR investigations.
Endpoint telemetry often shows the attack in motion. Learn to read it properly, and the device will tell you what happened.
Agent Foskett mindsetDo not treat endpoint alerts as isolated events. Build the process tree, follow the timeline, check the network activity and confirm what changed on the device.
New Academy SeriesThe Defender for Endpoint Academy expands Agent Foskett from KQL and XDR investigations into practical endpoint protection, EDR response and device security operations.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD
Microsoft Defender for Endpoint Academy by Agent Foskett
The Agent Foskett Microsoft Defender for Endpoint Academy teaches endpoint security, EDR, device investigations, attack surface reduction, vulnerability management, Live Response and practical Microsoft endpoint defence.
Learn Microsoft Defender for Endpoint security and investigations
This Defender for Endpoint learning path explains device telemetry, process investigations, file activity, registry changes, network events, endpoint response actions, ASR, TVM and enterprise endpoint protection.
Microsoft Defender for Endpoint training for SOC analysts
The Defender for Endpoint Academy builds on the Agent Foskett KQL Academy and Microsoft Sentinel Academy by showing defenders how to investigate device signals, respond to endpoint incidents and harden Microsoft endpoint environments.