Specialization

Endpoint Security Professional

Master enterprise endpoint protection with Microsoft Defender for Endpoint and CrowdStrike Falcon — EDR/XDR, threat hunting, incident response and endpoint hardening.

Duration4 Weeks
LevelIntermediate
FormatLive Online

LEARNING OUTCOMES

What you will learn

1

EPP, EDR and XDR fundamentals

2

Microsoft Defender for Endpoint operations

3

CrowdStrike Falcon investigation

4

Threat hunting with KQL and endpoint hardening

Curriculum

Module 1 · Endpoint Security Fundamentals

EPP, EDR, XDR, common endpoint threats, MITRE ATT&CK framework, enterprise endpoint architecture

Module 2 · Windows Security Fundamentals

Windows security architecture, registry, services, UAC, Windows Firewall, BitLocker, Secure Boot, Defender Antivirus

Module 3 · Endpoint Detection & Response (EDR)

Endpoint telemetry, detection techniques, behavioral analytics, IOC vs IOA, detection workflow

Module 4 · Microsoft Defender for Endpoint

Defender portal, device inventory, vulnerability management, Live Response, advanced hunting with KQL, device isolation

Module 5 · CrowdStrike Falcon

Falcon platform, sensor deployment, host management, RTR, Falcon Intelligence, threat investigation

Module 6 · Threat Hunting & Incident Response

Threat hunting, threat intelligence, KQL, containment, recovery, ransomware investigation

Module 7 · Endpoint Hardening & Enterprise Security

CIS Benchmarks, Microsoft security baselines, ASR rules, application control, USB restrictions, patch management, Zero Trust for endpoints

Module 8 · Capstone Project

Deploy Microsoft Defender for Endpoint, investigate malware, threat hunting, incident response, executive security report

Tools covered: Microsoft Defender for Endpoint, Microsoft Defender XDR, CrowdStrike Falcon, PowerShell, Event Viewer, Sysinternals Suite

Program experience

Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.