Agent Foskett Academy • Defender for Endpoint • Module 1 • Lesson 1

Lesson 1 — What is Microsoft Defender for Endpoint?

Most attacks leave evidence on the endpoint.

A process starts, a file changes, a registry key appears, a user signs in or a network connection leaves the device.

Microsoft Defender for Endpoint collects and analyses that activity so defenders can detect threats, investigate what happened, reduce attack paths and respond directly to affected devices.

The endpoint records the attack in motion. Defender for Endpoint helps analysts read that evidence.
Agent Foskett What is Microsoft Defender for Endpoint lesson
What you will learn

This lesson introduces Microsoft Defender for Endpoint and explains how it supports modern endpoint protection, detection, investigation and response.

What Defender for Endpoint is
How EDR and endpoint telemetry work
How devices are onboarded
How endpoint signals connect to Defender XDR

Learning objectives

After completing this lesson, you should understand the purpose and core capabilities of Microsoft Defender for Endpoint.

  • Explain what Microsoft Defender for Endpoint is.
  • Understand endpoint detection and response.
  • Recognise the main sources of endpoint telemetry.
  • Understand device onboarding and visibility.
  • Explain how Defender for Endpoint connects to Microsoft Defender XDR.

The problem this solves

Traditional antivirus may detect known malware, but modern attacks often use legitimate tools, stolen credentials and trusted system processes.

Defender for Endpoint gives analysts the deeper device telemetry required to investigate those behaviours.

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint is Microsoft's enterprise endpoint security platform.

It provides prevention, endpoint detection and response, automated investigation, vulnerability management, threat hunting and direct response actions for supported devices.

Agent Foskett tip:

Do not think of Defender for Endpoint as only antivirus. Its greatest value is the visibility it gives analysts into what happened on the device.

How Defender for Endpoint fits into Microsoft security

User works on a device │ ▼ Processes, files, registry, logons and network activity occur │ ▼ Defender for Endpoint sensor collects telemetry │ ▼ Microsoft cloud analytics evaluate behaviour │ ├── Alerts ├── Device timeline ├── Advanced Hunting data ├── Vulnerability insights └── Response actions │ ▼ Microsoft Defender XDR incident and investigation

Endpoint protection

Defender for Endpoint includes preventative controls designed to reduce malware, phishing and exploit-driven activity on devices.

These controls can include antivirus, web protection, network protection and attack surface reduction capabilities.

Endpoint detection and response

Endpoint detection and response, or EDR, records detailed device activity and analyses it for suspicious behaviour.

This gives analysts visibility into activity that may not be identified by a simple file-based malware signature.

Endpoint telemetry

Endpoint telemetry is the recorded activity generated by users, applications, operating systems and security controls.

It becomes the evidence analysts use to reconstruct an attack.

Common telemetry sources

  • Process creation and command lines
  • File creation, modification and deletion
  • Registry activity
  • User and device logons
  • Network connections
  • Security control actions

Device onboarding

A device must be onboarded before Defender for Endpoint can provide full endpoint visibility and response capabilities.

Onboarding connects the device to the Defender service and enables the required sensor and security configuration.

Supported device platforms

Defender for Endpoint can protect multiple operating system platforms depending on licensing, deployment method and feature support.

Organisations should validate platform-specific capabilities before designing a standard deployment.

Device inventory

Onboarded and discovered devices appear in the device inventory.

The inventory provides a central view of device status, operating system, exposure, risk and sensor health.

The device page

The device page brings together endpoint information, alerts, logged-on users, software, vulnerabilities, recommendations and response actions.

It becomes one of the main starting points for an endpoint investigation.

The device timeline

The device timeline presents security-relevant activity in chronological order.

Analysts can use it to follow processes, files, registry changes, network activity and other events around the time of an alert.

Traditional antivirus versus Defender for Endpoint

Traditional antivirusMicrosoft Defender for Endpoint
Primarily focuses on malware prevention and detection.Combines prevention, EDR, investigation, hunting and response.
May focus heavily on files and signatures.Analyses behaviour across processes, identities, files, registry and network activity.
Often provides limited investigation context.Provides device timelines, entities, evidence and Advanced Hunting telemetry.
May stop a threat without explaining the wider attack.Helps analysts reconstruct what happened before, during and after the alert.

Alerts

Alerts are generated when Defender identifies suspicious or malicious endpoint activity.

An alert should be treated as an investigation lead that must be validated against the underlying device evidence.

Incidents

Microsoft Defender XDR groups related alerts, entities and evidence into incidents.

An endpoint alert may therefore become part of a wider attack involving identity, email, cloud applications or other devices.

Advanced Hunting

Advanced Hunting gives analysts direct access to endpoint and cross-domain security telemetry using KQL.

This is where tables such as DeviceProcessEvents, DeviceNetworkEvents and DeviceFileEvents become especially valuable.

Automated investigation

Defender can investigate certain alerts automatically and perform supported remediation actions.

Analysts should still review the investigation evidence and understand what actions were taken.

Response actions

  • Isolate a device
  • Collect an investigation package
  • Run antivirus scans
  • Restrict application execution
  • Use Live Response
  • Manage indicators

Threat and vulnerability management

Defender for Endpoint also identifies vulnerable software, weak configurations and security recommendations.

This helps organisations reduce exposure before an attacker can exploit it.

Real-world investigation example

Suspicious PowerShell alert │ ▼ Open the affected device │ ▼ Review process tree and command line │ ▼ Check file, registry and network activity │ ▼ Identify affected user and related devices │ ▼ Contain the endpoint and preserve evidence │ ▼ Confirm the wider Defender XDR incident

Why process trees matter

Process trees show which process launched another process.

This helps analysts distinguish expected application behaviour from suspicious parent-child execution chains.

Why timelines matter

An alert represents one point in time.

The timeline helps analysts understand what occurred before the alert, what happened next and whether the attacker performed additional actions.

Common mistake

A common mistake is closing an endpoint alert after reviewing only the alert title.

Always inspect the device timeline, process tree, entities and related incident evidence.

Another common mistake

Do not isolate a device without understanding the operational impact.

Containment actions should be deliberate, documented and coordinated with the incident response process.

Agent Foskett investigation tip

The alert is not the investigation.

The alert points you toward the evidence. The device timeline, process tree, network activity and surrounding context explain what actually happened.

Best practices

  • Keep device onboarding and sensor health visible.
  • Review the complete process tree.
  • Use the device timeline to build chronology.
  • Connect endpoint evidence to the wider incident.
  • Document every response action.

Agent Foskett takeaway

Microsoft Defender for Endpoint gives analysts deep visibility into what happens on protected devices.

It combines prevention, detection, investigation, exposure management and response into one endpoint security platform.

Lesson summary
Microsoft Defender for Endpoint is an enterprise endpoint security platform that combines prevention, endpoint detection and response, Advanced Hunting, vulnerability management, automated investigation and direct device response actions. Its telemetry helps analysts reconstruct what happened on the endpoint and connect that evidence to Microsoft Defender XDR incidents.
Defender for Endpoint Academy

Related Agent Foskett learning

These links connect Lesson 1 with existing endpoint investigations, KQL learning and the wider Agent Foskett Academy.

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint is an enterprise endpoint security platform providing antivirus, endpoint detection and response, Advanced Hunting, device investigations, vulnerability management and response actions.

Defender for Endpoint Lesson 1

This Agent Foskett Defender for Endpoint Academy lesson explains EDR, endpoint telemetry, device onboarding, device inventory, timelines, alerts, incidents, threat hunting and endpoint response.