Endpoint Security Operations

Detect, Hunt, Triage and Contain on the Endpoint

Somebody else deployed the controls. You are the one who has to know what they catch, what they miss, and what to do at two in the morning when one of them fires. This course is the operations half of endpoint security: detection engineering against endpoint telemetry, hunting that starts from a question, triage to a defensible disposition, and the collection decisions you have to make before an incident rather than during one.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
SEC409 | Specialist tier | 6 modules across 3 phases | 24–30 hours at your own pace | 28 CPE credits | No prerequisite | Updated September 2026

Course Syllabus

Every module and every lesson. Open a module to see its lessons.

Course overview

Endpoint Security Operations is the half of endpoint security that starts once the estate is already deployed. It assumes the sensors are on, the policies are assigned, and somebody is now responsible for what the whole arrangement actually detects and how the organization responds when it does.

Learn how to:

Write endpoint detection rules with a stated scope, a data dependency and a documented failure mode
Run a hunt that begins with a question rather than a query, and keep what it produces
Triage an endpoint alert to a disposition you can defend, and contain with the blast radius stated
Decide what to collect before an incident, and prove the collection would survive one

By the end you will be able to say what your estate detects, what it does not, and how quickly it responds, with evidence rather than assertion.

How this course works

The course is organized around what an operator does with an estate rather than around the products they do it with.

1. The telemetry decides what is possible. Every detection and every hunt in this course is written against tables that exist, with the volume limits and retention windows named, because a rule against data you do not have is a rule that never fires.

2. Write the detection with its failure mode. A rule without a documented false positive profile and a stated data dependency is a rule somebody will disable during the first busy week.

3. Hunt from a hypothesis. A query with no question behind it produces results nobody can act on. Each hunt in this course states what it expects to find and what a null result would mean.

4. Triage to a disposition, not to a feeling. Every alert ends in escalate, contain or close, with the evidence that decided it recorded.

5. Decide collection before you need it. Forensic readiness is a set of configuration decisions taken while nothing is happening, and it is the phase that determines whether an investigation is possible at all.

The course closes on the adversary who knows which controls you deployed, and on wiring endpoint signal into the wider estate so that response happens without a person present.

What this course assumes

No minimum experience and no prerequisite course. Every concept is explained at first use, and the telemetry, the sensor model and the response surface are restated here rather than assumed from elsewhere.

What makes it go faster: access to a Defender for Endpoint tenant with advanced hunting, and an estate with enough activity in it to query. Neither is required to follow the material.

What this course does not cover: deploying and hardening the estate in the first place, which is ARC402 Endpoint Security Engineering; and deep artifact examination, which is FOR501 Windows Endpoint Investigation and FOR502 Endpoint Memory Forensic Investigation. This course stops at collection and preservation rather than analysis.

Who this course is for

You are a SOC analyst, detection engineer, incident responder or security engineer who has inherited a working endpoint estate and is now accountable for what it does.

This course is designed for you if you want to:

Stop adopting vendor detections and start writing ones you can defend in a review
Hunt with a method rather than by pasting queries you found and hoping
Reach a disposition on an endpoint alert quickly, and be able to justify it afterwards
Make the collection decisions that determine whether an investigation is possible

In short: if you want to be the person who can say what the estate detects and prove it, this is the course.

What you'll learn

By the end of this Endpoint Security Operations course you will be able to:

Author custom detections in Defender for Endpoint, and place each one where it belongs
Query the endpoint tables fluently, and know which table answers which question
Run a structured hunt, record the hypothesis, and turn findings into durable detections
Triage, investigate and contain an endpoint compromise end to end
Configure forensic readiness so that the evidence an investigation needs already exists
Build detections that hold against an adversary who knows the controls are there

Key course takeaways

A detection portfolio with scope, data dependency and failure mode recorded per rule
A hunt method that produces findings rather than result sets
A triage path that ends in a defensible disposition every time
A forensic readiness configuration decided in advance and tested
Detections that assume evasion rather than assuming cooperation
Endpoint signal wired into the wider estate, with response that runs unattended

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

Cheatsheets for the endpoint tables, detection authoring, triage and containment, and forensic collection
Cookbooks for the sixty-minute triage, collecting from a live host, and recovering a compromised endpoint
Walkthroughs of investigations that turned on a detail somebody nearly missed
Playbooks for tamper, credential access, ransomware preparation and unremediated malware
An operational reference of the queries, tables and action types the course uses

Things you need to know

What are the prerequisites for this course?

There are none. The course assumes an endpoint estate exists and explains the sensor model, the telemetry and the response surface as it goes. ARC402 Endpoint Security Engineering is the natural companion rather than a requirement: it covers building and hardening the estate this course operates.

What do I need access to?

A Defender for Endpoint tenant with advanced hunting is what makes the material immediately practical. Everything is followable without one, and every query in the course states which tables it needs.

How will the course benefit your career?

Detection engineering, hunting and triage are the three capabilities every SOC is short of, and they are the ones that separate an analyst who closes tickets from one who improves what the organization detects.

These skills apply in roles such as detection engineer, threat hunter, SOC analyst, incident responder and security engineer.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Detection content: All queries and detection rules are provided for use in your own environment. Test every rule against your own data before enabling it.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

Version and changelog

Current version: 1.0  |  Last updated: September 2026

September 2026 - v1.0: Course created by splitting ARC402 Endpoint Security Engineering, which had grown to sixteen modules covering both the building of an endpoint estate and the operating of it. The six operations modules became this course. Orientation and capstone modules are in build.

This course is actively maintained.