Endpoint Security
Defending endpoints end to end — architecture and attack surface, telemetry and EDR, process-lineage investigation, containment decisions, and hardening. Where telemetry, detection, forensics and response meet the real host. Recommended prior knowledge: Cyber Foundations, SOC or Detection Engineering.
What you will be able to do
- Read endpoint telemetry — process lineage, command lines, identity and network context — to investigate an alert.
- Make a defensible containment decision: isolate, terminate, disable or watch.
- Identify visibility and control gaps and recommend proportionate endpoint hardening.
Units
- 01
Endpoint Architecture & Attack Surface
Why endpoints matter, the endpoint attack surface, Windows and Linux endpoint architecture, processes, services, files, registry, memory, users and privileges.
BeginnerAvailableWhy you are learning this
You cannot defend an endpoint you do not understand. This module builds the mental model of what a host is made of and where attackers operate on it.
- 02
Processes, Identity & Attacker Behavior
Process trees and command lines, parent-child relationships, PowerShell and WMI, persistence mechanisms, fileless and LOLBin behavior, credential abuse and privilege escalation.
BeginnerAvailableWhy you are learning this
Almost every endpoint intrusion shows up as process and identity behavior. This module builds the core reading skill the whole path rests on.
- 03
EDR & Endpoint Telemetry
EPP vs EDR vs XDR, endpoint telemetry (process, file, registry, network, authentication, script), Event Logs and Sysmon, behavioral analytics, and IOC vs TTP detection on the endpoint.
BeginnerAvailableWhy you are learning this
EDR is the analyst's window into the endpoint. This module teaches what telemetry it collects, what each source shows, and where the blind spots are.
- 04
Endpoint Investigation
Investigating an EDR alert: validating it, tracing process lineage, establishing user and network context, and reviewing persistence — the endpoint investigation loop.
Job-ReadyAvailableWhy you are learning this
An alert is a starting point, not a verdict. This module builds the disciplined investigation that turns an EDR alert into an understood incident.
Unit contents8
Theory Lessons(6)
Practical Labs(2)
- 05
Containment & Response
Containment decisions — host isolation, process termination, account actions — artifact collection before action, recovery, and matching the response to the evidence.
Job-ReadyAvailableWhy you are learning this
The wrong containment action can destroy evidence, tip off the attacker, or take down a critical system. This module teaches deciding and acting proportionately.
Unit contents7
- 06
Hardening & the Saraya Incident
Endpoint hardening — application control, least privilege, attack-surface reduction, PowerShell and logging policy, credential protection, baselines and metrics — and the integrated Saraya capstone.
Job-ReadyAvailableWhy you are learning this
Investigation and response treat symptoms; hardening reduces the attack surface so fewer intrusions succeed. This module closes the loop — then proves the whole path on a full endpoint incident.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
Recommended next
Digital Forensics (DFIR)
Reconstructing what happened from evidence — execution artifacts, registry, event logs, filesystem metadata, memory and network traces — into a defensible timeline and report. Recommended prior knowledge: Cyber Foundations or Incident Response.
Detection Engineering
Turning attacker behavior and telemetry into high-quality, maintainable detections — from requirements and data quality through detection logic, testing, false-positive tuning, coverage and production readiness. Tool-neutral (Sigma-style logic). Recommended prior knowledge: SOC, Threat Hunting or Malware Analysis.