Specialization
Endpoint Security Professional
Master enterprise endpoint protection with Microsoft Defender for Endpoint and CrowdStrike Falcon — EDR/XDR, threat hunting, incident response and endpoint hardening.
LEARNING OUTCOMES
What you will learn
EPP, EDR and XDR fundamentals
Microsoft Defender for Endpoint operations
CrowdStrike Falcon investigation
Threat hunting with KQL and endpoint hardening
Curriculum
EPP, EDR, XDR, common endpoint threats, MITRE ATT&CK framework, enterprise endpoint architecture
Windows security architecture, registry, services, UAC, Windows Firewall, BitLocker, Secure Boot, Defender Antivirus
Endpoint telemetry, detection techniques, behavioral analytics, IOC vs IOA, detection workflow
Defender portal, device inventory, vulnerability management, Live Response, advanced hunting with KQL, device isolation
Falcon platform, sensor deployment, host management, RTR, Falcon Intelligence, threat investigation
Threat hunting, threat intelligence, KQL, containment, recovery, ransomware investigation
CIS Benchmarks, Microsoft security baselines, ASR rules, application control, USB restrictions, patch management, Zero Trust for endpoints
Deploy Microsoft Defender for Endpoint, investigate malware, threat hunting, incident response, executive security report
Tools covered: Microsoft Defender for Endpoint, Microsoft Defender XDR, CrowdStrike Falcon, PowerShell, Event Viewer, Sysinternals Suite
Program experience
Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.