Endpoint Security Operations
Detect, Hunt, Triage and Contain on the Endpoint
Somebody else deployed the controls. You are the one who has to know what they catch, what they miss, and what to do at two in the morning when one of them fires. This course is the operations half of endpoint security: detection engineering against endpoint telemetry, hunting that starts from a question, triage to a defensible disposition, and the collection decisions you have to make before an incident rather than during one.
Course Syllabus
Every module and every lesson. Open a module to see its lessons.
Phase 1: Detection and Hunting
Build custom detection rules in MDE using KQL, credential access, lateral movement, persistence, defense evasion.
12 lessonsHide lessons
- EO1.1 Custom Detections in MDE vs Sentinel
- EO1.2 MDE Advanced Hunting Tables
- EO1.3 Building Effective Detection KQL
- EO1.4 Custom Detection: Credential Access
- EO1.5 Custom Detection: Lateral Movement
- EO1.6 Custom Detection: Persistence and Defense Evasion
- EO1.7 Threat Intelligence Integration
- EO1.8 Automated Actions on Detection
- EO1.9 Detection Testing and Validation
- EO1.10 Detection Lifecycle and Version Control
- EO1.11 Interactive Lab: Build Endpoint Detections
- Module Summary
Proactive threat hunting across MDE endpoint tables.
12 lessonsHide lessons
- EO2.1 Endpoint Hunting Philosophy
- EO2.2 DeviceProcessEvents Deep Dive
- EO2.3 DeviceNetworkEvents Deep Dive
- EO2.4 DeviceFileEvents and DeviceRegistryEvents
- EO2.5 DeviceLogonEvents and DeviceImageLoadEvents
- EO2.6 Essential Joins and Time-Window Queries
- EO2.7 Advanced Techniques: JSON Parsing and Nested Data
- EO2.8 LOLBAS Tracking and Living-off-the-Land Detection
- EO2.9 Parent-Child Process Anomalies
- EO2.10 Building the Endpoint Hunting Query Library
- EO2.11 Interactive Lab: Endpoint Hunting Exercise
- Module Summary
Phase 2: Response
Operationalize the detection layer. Triage MDE alerts in 60 minutes, investigate using device timeline and process tree analysis, execute containment at scale, and apply incident-type-specific playbooks for...
12 lessonsHide lessons
- EO3.1 MDE Alert → Sentinel Incident
- EO3.2 The 60-Minute Endpoint Triage Rule
- EO3.3 Device Timeline Exploration
- EO3.4 Process Tree Analysis
- EO3.5 Investigation Playbook: Ransomware on Endpoint
- EO3.6 Investigation Playbook: Commodity Malware
- EO3.7 Investigation Playbook: Living-off-the-Land
- EO3.8 Evidence Collection Without Breaking Chain of Custody
- EO3.9 Containment at Scale
- EO3.10 Decision Trees: Ransomware vs Commodity vs APT
- EO3.11 Interactive Lab: Endpoint Investigation and Containment
- Module Summary
Configure the telemetry layer that ensures evidence exists when the incident happens.
12 lessonsHide lessons
- EO4.1 Forensic Readiness: Designing for Investigation
- EO4.2 Windows Audit Policy Configuration
- EO4.3 PowerShell Logging
- EO4.4 Sysmon Deployment and Configuration
- EO4.5 Windows Event Forwarding Architecture
- EO4.6 KAPE for Endpoint Collection
- EO4.7 Memory Acquisition Readiness
- EO4.8 Velociraptor for Endpoint Collection at Scale
- EO4.9 OSQuery for Endpoint State Inspection
- EO4.10 Windows LAPS Configuration
- EO4.11 Interactive Lab: Forensic Readiness Deployment
- Module Summary
Phase 3: Advanced
Understand what attackers do to bypass the endpoint security stack, process injection, AMSI bypass, ETW tampering, EDR evasion, anti-forensics, from the defender's perspective.
12 lessonsHide lessons
- EO5.1 Why Defenders Need to Understand Evasion
- EO5.2 Process Injection Techniques
- EO5.3 AMSI Bypass and Script-Level Evasion
- EO5.4 ETW Tampering and Blind Spots
- EO5.5 EDR Evasion: What Attackers Actually Do
- EO5.6 Anti-Forensics on Endpoints
- EO5.7 Defense Evasion: Living-off-the-Land at Scale
- EO5.8 Validation: Red Team and Purple Team Exercises
- EO5.9 Threat Intelligence-Driven Defense
- EO5.10 Building Resilient Detections
- EO5.11 Interactive Lab: Evasion-Aware Defense
- Module Summary
Connect the endpoint security architecture to the broader security ecosystem.
12 lessonsHide lessons
- EO6.1 Zero Trust for Endpoints
- EO6.2 MDE + Sentinel Integration
- EO6.3 MDE + Entra ID + Conditional Access
- EO6.4 MDE + Defender for Cloud
- EO6.5 MDE + MDO + MDI
- EO6.6 Endpoint Security Automation with Logic Apps
- EO6.7 Cross-Workload Automation
- EO6.8 MDE API for Engineering and Operations
- EO6.9 Third-Party SIEM and MSSP Integration
- EO6.10 Building the Integrated Security Architecture
- EO6.11 Interactive Lab: Integration and Automation
- Module Summary
Course overview
Endpoint Security Operations is the half of endpoint security that starts once the estate is already deployed. It assumes the sensors are on, the policies are assigned, and somebody is now responsible for what the whole arrangement actually detects and how the organization responds when it does.
Learn how to:
By the end you will be able to say what your estate detects, what it does not, and how quickly it responds, with evidence rather than assertion.
How this course works
The course is organized around what an operator does with an estate rather than around the products they do it with.
1. The telemetry decides what is possible. Every detection and every hunt in this course is written against tables that exist, with the volume limits and retention windows named, because a rule against data you do not have is a rule that never fires.
2. Write the detection with its failure mode. A rule without a documented false positive profile and a stated data dependency is a rule somebody will disable during the first busy week.
3. Hunt from a hypothesis. A query with no question behind it produces results nobody can act on. Each hunt in this course states what it expects to find and what a null result would mean.
4. Triage to a disposition, not to a feeling. Every alert ends in escalate, contain or close, with the evidence that decided it recorded.
5. Decide collection before you need it. Forensic readiness is a set of configuration decisions taken while nothing is happening, and it is the phase that determines whether an investigation is possible at all.
The course closes on the adversary who knows which controls you deployed, and on wiring endpoint signal into the wider estate so that response happens without a person present.
What this course assumes
No minimum experience and no prerequisite course. Every concept is explained at first use, and the telemetry, the sensor model and the response surface are restated here rather than assumed from elsewhere.
What makes it go faster: access to a Defender for Endpoint tenant with advanced hunting, and an estate with enough activity in it to query. Neither is required to follow the material.
What this course does not cover: deploying and hardening the estate in the first place, which is ARC402 Endpoint Security Engineering; and deep artifact examination, which is FOR501 Windows Endpoint Investigation and FOR502 Endpoint Memory Forensic Investigation. This course stops at collection and preservation rather than analysis.
Who this course is for
You are a SOC analyst, detection engineer, incident responder or security engineer who has inherited a working endpoint estate and is now accountable for what it does.
This course is designed for you if you want to:
In short: if you want to be the person who can say what the estate detects and prove it, this is the course.
What you'll learn
By the end of this Endpoint Security Operations course you will be able to:
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
There are none. The course assumes an endpoint estate exists and explains the sensor model, the telemetry and the response surface as it goes. ARC402 Endpoint Security Engineering is the natural companion rather than a requirement: it covers building and hardening the estate this course operates.
What do I need access to?
A Defender for Endpoint tenant with advanced hunting is what makes the material immediately practical. Everything is followable without one, and every query in the course states which tables it needs.
How will the course benefit your career?
Detection engineering, hunting and triage are the three capabilities every SOC is short of, and they are the ones that separate an analyst who closes tickets from one who improves what the organization detects.
These skills apply in roles such as detection engineer, threat hunter, SOC analyst, incident responder and security engineer.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Detection content: All queries and detection rules are provided for use in your own environment. Test every rule against your own data before enabling it.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
Version and changelog
Current version: 1.0 | Last updated: September 2026
September 2026 - v1.0: Course created by splitting ARC402 Endpoint Security Engineering, which had grown to sixteen modules covering both the building of an endpoint estate and the operating of it. The six operations modules became this course. Orientation and capstone modules are in build.
This course is actively maintained.