Lesson 1 — What is Microsoft Defender for Endpoint?
Most attacks leave evidence on the endpoint.
A process starts, a file changes, a registry key appears, a user signs in or a network connection leaves the device.
Microsoft Defender for Endpoint collects and analyses that activity so defenders can detect threats, investigate what happened, reduce attack paths and respond directly to affected devices.
What you will learn
This lesson introduces Microsoft Defender for Endpoint and explains how it supports modern endpoint protection, detection, investigation and response.
Learning objectives
After completing this lesson, you should understand the purpose and core capabilities of Microsoft Defender for Endpoint.
- Explain what Microsoft Defender for Endpoint is.
- Understand endpoint detection and response.
- Recognise the main sources of endpoint telemetry.
- Understand device onboarding and visibility.
- Explain how Defender for Endpoint connects to Microsoft Defender XDR.
The problem this solves
Traditional antivirus may detect known malware, but modern attacks often use legitimate tools, stolen credentials and trusted system processes.
Defender for Endpoint gives analysts the deeper device telemetry required to investigate those behaviours.
What is Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint is Microsoft's enterprise endpoint security platform.
It provides prevention, endpoint detection and response, automated investigation, vulnerability management, threat hunting and direct response actions for supported devices.
Do not think of Defender for Endpoint as only antivirus. Its greatest value is the visibility it gives analysts into what happened on the device.
How Defender for Endpoint fits into Microsoft security
Endpoint protection
Defender for Endpoint includes preventative controls designed to reduce malware, phishing and exploit-driven activity on devices.
These controls can include antivirus, web protection, network protection and attack surface reduction capabilities.
Endpoint detection and response
Endpoint detection and response, or EDR, records detailed device activity and analyses it for suspicious behaviour.
This gives analysts visibility into activity that may not be identified by a simple file-based malware signature.
Endpoint telemetry
Endpoint telemetry is the recorded activity generated by users, applications, operating systems and security controls.
It becomes the evidence analysts use to reconstruct an attack.
Common telemetry sources
- Process creation and command lines
- File creation, modification and deletion
- Registry activity
- User and device logons
- Network connections
- Security control actions
Device onboarding
A device must be onboarded before Defender for Endpoint can provide full endpoint visibility and response capabilities.
Onboarding connects the device to the Defender service and enables the required sensor and security configuration.
Supported device platforms
Defender for Endpoint can protect multiple operating system platforms depending on licensing, deployment method and feature support.
Organisations should validate platform-specific capabilities before designing a standard deployment.
Device inventory
Onboarded and discovered devices appear in the device inventory.
The inventory provides a central view of device status, operating system, exposure, risk and sensor health.
The device page
The device page brings together endpoint information, alerts, logged-on users, software, vulnerabilities, recommendations and response actions.
It becomes one of the main starting points for an endpoint investigation.
The device timeline
The device timeline presents security-relevant activity in chronological order.
Analysts can use it to follow processes, files, registry changes, network activity and other events around the time of an alert.
Traditional antivirus versus Defender for Endpoint
| Traditional antivirus | Microsoft Defender for Endpoint |
|---|---|
| Primarily focuses on malware prevention and detection. | Combines prevention, EDR, investigation, hunting and response. |
| May focus heavily on files and signatures. | Analyses behaviour across processes, identities, files, registry and network activity. |
| Often provides limited investigation context. | Provides device timelines, entities, evidence and Advanced Hunting telemetry. |
| May stop a threat without explaining the wider attack. | Helps analysts reconstruct what happened before, during and after the alert. |
Alerts
Alerts are generated when Defender identifies suspicious or malicious endpoint activity.
An alert should be treated as an investigation lead that must be validated against the underlying device evidence.
Incidents
Microsoft Defender XDR groups related alerts, entities and evidence into incidents.
An endpoint alert may therefore become part of a wider attack involving identity, email, cloud applications or other devices.
Advanced Hunting
Advanced Hunting gives analysts direct access to endpoint and cross-domain security telemetry using KQL.
This is where tables such as DeviceProcessEvents, DeviceNetworkEvents and DeviceFileEvents become especially valuable.
Automated investigation
Defender can investigate certain alerts automatically and perform supported remediation actions.
Analysts should still review the investigation evidence and understand what actions were taken.
Response actions
- Isolate a device
- Collect an investigation package
- Run antivirus scans
- Restrict application execution
- Use Live Response
- Manage indicators
Threat and vulnerability management
Defender for Endpoint also identifies vulnerable software, weak configurations and security recommendations.
This helps organisations reduce exposure before an attacker can exploit it.
Real-world investigation example
Why process trees matter
Process trees show which process launched another process.
This helps analysts distinguish expected application behaviour from suspicious parent-child execution chains.
Why timelines matter
An alert represents one point in time.
The timeline helps analysts understand what occurred before the alert, what happened next and whether the attacker performed additional actions.
Common mistake
A common mistake is closing an endpoint alert after reviewing only the alert title.
Always inspect the device timeline, process tree, entities and related incident evidence.
Another common mistake
Do not isolate a device without understanding the operational impact.
Containment actions should be deliberate, documented and coordinated with the incident response process.
Agent Foskett investigation tip
The alert points you toward the evidence. The device timeline, process tree, network activity and surrounding context explain what actually happened.
Best practices
- Keep device onboarding and sensor health visible.
- Review the complete process tree.
- Use the device timeline to build chronology.
- Connect endpoint evidence to the wider incident.
- Document every response action.
Agent Foskett takeaway
Microsoft Defender for Endpoint gives analysts deep visibility into what happens on protected devices.
It combines prevention, detection, investigation, exposure management and response into one endpoint security platform.
Related Agent Foskett learning
Continue learning
What is Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint is an enterprise endpoint security platform providing antivirus, endpoint detection and response, Advanced Hunting, device investigations, vulnerability management and response actions.
Defender for Endpoint Lesson 1
This Agent Foskett Defender for Endpoint Academy lesson explains EDR, endpoint telemetry, device onboarding, device inventory, timelines, alerts, incidents, threat hunting and endpoint response.
