Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Beginner Hard42 hours

Endpoint Security

Defending endpoints end to end — architecture and attack surface, telemetry and EDR, process-lineage investigation, containment decisions, and hardening. Where telemetry, detection, forensics and response meet the real host. Recommended prior knowledge: Cyber Foundations, SOC or Detection Engineering.

Recommended first:SOC Analyst L2
Windows SecurityLog AnalysisIOC AnalysisIncident TriageNetwork Analysis

What you will be able to do

  • Read endpoint telemetry — process lineage, command lines, identity and network context — to investigate an alert.
  • Make a defensible containment decision: isolate, terminate, disable or watch.
  • Identify visibility and control gaps and recommend proportionate endpoint hardening.

Units

  1. 01

    Endpoint Architecture & Attack Surface

    Why endpoints matter, the endpoint attack surface, Windows and Linux endpoint architecture, processes, services, files, registry, memory, users and privileges.

    BeginnerAvailable

    Why you are learning this

    You cannot defend an endpoint you do not understand. This module builds the mental model of what a host is made of and where attackers operate on it.

    Unit contents6
  2. 02

    Processes, Identity & Attacker Behavior

    Process trees and command lines, parent-child relationships, PowerShell and WMI, persistence mechanisms, fileless and LOLBin behavior, credential abuse and privilege escalation.

    BeginnerAvailable

    Why you are learning this

    Almost every endpoint intrusion shows up as process and identity behavior. This module builds the core reading skill the whole path rests on.

    Unit contents6
  3. 03

    EDR & Endpoint Telemetry

    EPP vs EDR vs XDR, endpoint telemetry (process, file, registry, network, authentication, script), Event Logs and Sysmon, behavioral analytics, and IOC vs TTP detection on the endpoint.

    BeginnerAvailable

    Why you are learning this

    EDR is the analyst's window into the endpoint. This module teaches what telemetry it collects, what each source shows, and where the blind spots are.

    Unit contents6
  4. 04

    Endpoint Investigation

    Investigating an EDR alert: validating it, tracing process lineage, establishing user and network context, and reviewing persistence — the endpoint investigation loop.

    Job-ReadyAvailable

    Why you are learning this

    An alert is a starting point, not a verdict. This module builds the disciplined investigation that turns an EDR alert into an understood incident.

    Unit contents8
  5. 05

    Containment & Response

    Containment decisions — host isolation, process termination, account actions — artifact collection before action, recovery, and matching the response to the evidence.

    Job-ReadyAvailable

    Why you are learning this

    The wrong containment action can destroy evidence, tip off the attacker, or take down a critical system. This module teaches deciding and acting proportionately.

    Unit contents7
  6. 06

    Hardening & the Saraya Incident

    Endpoint hardening — application control, least privilege, attack-surface reduction, PowerShell and logging policy, credential protection, baselines and metrics — and the integrated Saraya capstone.

    Job-ReadyAvailable

    Why you are learning this

    Investigation and response treat symptoms; hardening reduces the attack surface so fewer intrusions succeed. This module closes the loop — then proves the whole path on a full endpoint incident.

    Unit contents7

Recommended next