In today’s evolving cyber threat landscape, every endpoint—whether a laptop, server, cloud workload, or mobile device—represents a potential gateway to sensitive data. Cybercriminals know this, making endpoint security the true front line of defense. This course provides a structured, beginner-friendly introduction to endpoint security, taking you beyond traditional antivirus into modern defenses like EDR, Zero Trust, and insider threat detection.
Through real-world scenarios and guided labs inside virtual machines, you’ll gain practical skills using lightweight, open-source tools such as Sysmon, Velociraptor, osquery, and Sigma. Instead of abstract concepts, you’ll work with the same workflows and investigative methods that SOC analysts, sysadmins, and blue teamers use daily.
By the end of the course, you’ll know how to design secure endpoint architectures, monitor and correlate logs for advanced threat detection, and apply Zero Trust principles using built-in security features. Whether you’re preparing for certifications like CySA+, Blue Team Level 1, or SC-200, aiming for an entry-level SOC role, or transitioning from system administration into security, this course equips you with the skills to stop real-world attacks and build effective defenses without costly tools.
In this course, you’ll learn how to build and manage endpoint security as the first line of defense in today’s threat landscape. You’ll focus on designing secure endpoint architectures, applying Zero Trust principles, and using tools like Sysmon, Sigma, and Velociraptor to detect and investigate threats. Through expert-led instruction, real-world scenarios, and hands-on labs in virtual environments, you’ll gain the skills to monitor processes, analyze alerts, and respond to insider and external threats. By the end, you’ll be equipped to think like a SOC analyst, correlate logs and behaviors, and implement practical defenses that protect endpoints and strengthen overall cybersecurity posture.
Das ist alles enthalten
1 Video1 Lektüre
Infos zu Modulinhalt anzeigen
1 Video•Insgesamt 4 Minuten
Course Introduction •4 Minuten
1 Lektüre•Insgesamt 5 Minuten
Welcome to the Course: Course Overview•5 Minuten
Introduction to Endpoint Security Management
Modul 2•2 Stunden abzuschließen
Moduldetails
In this module, you’ll learn why endpoints are a critical focus in cybersecurity and how attackers often exploit them to reach organizational data. You’ll explore endpoint types, common attack vectors, the CIA triad, and baseline hardening principles, and analyze real-world attack scenarios to see these concepts in action. You’ll also work with CIS-CAT Lite in hands-on labs to assess configurations and understand how architectural components like agents and policy engines interact. Finally, you’ll apply foundational security practices to strengthen baseline defenses and build a resilient endpoint environment.
Running a Baseline Scan with CIS-CAT Lite on Windows•7 Minuten
1 Lektüre•Insgesamt 5 Minuten
Understanding Endpoint Security Basics •5 Minuten
1 Aufgabe•Insgesamt 20 Minuten
Introduction to Endpoint Security Management•20 Minuten
1 peer review•Insgesamt 10 Minuten
Hands-On-Learning: Exploring the CIA Triad on Endpoints•10 Minuten
2 Diskussionsthemen•Insgesamt 20 Minuten
Applying the CIA Triad to Endpoint Protection•10 Minuten
Security Baselines in Practice •10 Minuten
Endpoint Detection and Response (EDR)
Modul 3•2 Stunden abzuschließen
Moduldetails
In this module, you’ll learn how Endpoint Detection and Response (EDR) strengthens modern security beyond traditional antivirus solutions. You’ll explore how EDR collects and analyzes telemetry, apply frameworks like MITRE ATT&CK to shape detection strategies, and practice using tools such as Sysmon, Process Monitor, osquery, and Velociraptor for visibility and threat hunting. Through hands-on configuration and guided workflows, you’ll build skills in interpreting endpoint telemetry, investigating suspicious activity, and applying structured analysis techniques to real-world defense scenarios.
Visualizing Endpoint Activity with Process Monitor•5 Minuten
Endpoint Visibility with osquery: Architecture & Live Queries•9 Minuten
Investigating a Suspicious File-Based Alert with Velociraptor•11 Minuten
Response Discussion and EDR Limitations•5 Minuten
1 Lektüre•Insgesamt 5 Minuten
Understanding MITRE ATT&CK•5 Minuten
1 Aufgabe•Insgesamt 20 Minuten
Endpoint Detection and Response (EDR)•20 Minuten
1 peer review•Insgesamt 10 Minuten
Hands-On-Learning: Endpoint Visibility with Sysmon & EDR Pipeline •10 Minuten
2 Diskussionsthemen•Insgesamt 20 Minuten
Designing an EDR Pipeline in the Real World •10 Minuten
Balancing Visibility and Noise with Sysmon •10 Minuten
Zero Trust Architecture
Modul 4•2 Stunden abzuschließen
Moduldetails
In this module, you’ll learn why Zero Trust is essential in today’s borderless networks and how it transforms access control beyond traditional perimeter defenses. You’ll explore core principles such as continuous verification, least privilege, and microsegmentation across identity, device, and application layers. Through real-world reference architectures and policy enforcement models, you’ll gain practical insight into Zero Trust design. Finally, you’ll apply these concepts in a hands-on lab using OpenZiti and endpoint hardening to rethink access workflows and experiment with identity-based segmentation.
NIST SP 800-207: Zero Trust Architecture•5 Minuten
1 Aufgabe•Insgesamt 20 Minuten
Zero Trust Architecture•20 Minuten
1 peer review•Insgesamt 10 Minuten
Hands-On-Learning: Enforcing Zero Trust: PDP vs. PEP on Windows •10 Minuten
2 Diskussionsthemen•Insgesamt 20 Minuten
Prioritizing Zero Trust Pillars in Implementation •10 Minuten
Deciding vs. Enforcing Access •10 Minuten
Insider Threat Management
Modul 5•2 Stunden abzuschließen
Moduldetails
In this module, you’ll learn how to identify and mitigate insider threats—one of the most challenging risks in cybersecurity. You’ll explore insider motives, behavioral indicators, and monitoring techniques based on log analysis and baseline deviations, while also considering the legal and ethical implications of monitoring trusted users. Through case studies, detection strategies, and hands-on simulations with Sysmon and Sigma, you’ll practice analyzing behavior patterns, interpreting activity trails, and evaluating potential misuse of privileges to build a responsible and effective insider threat program.
Windows Security Log Event ID Reference •10 Minuten
1 Aufgabe•Insgesamt 20 Minuten
Insider Threat Management•20 Minuten
1 peer review•Insgesamt 10 Minuten
Hands-On-Learning: Detecting Suspicious Insider Activity with Windows Event Viewer •10 Minuten
2 Diskussionsthemen•Insgesamt 20 Minuten
Understanding Insider Motivations •10 Minuten
Using Logs to Spot Insider Activity •10 Minuten
Course Conclusion
Modul 6•1 Stunde abzuschließen
Moduldetails
In this wrap-up module, you’ll consolidate everything learned across the course by demonstrating your ability to secure, monitor, and investigate a real-world endpoint scenario. Through a graded assessment, hands-on project, and final reflections, you’ll apply endpoint hardening techniques, configure telemetry, simulate insider or malware-like activity, and conduct a structured investigation using free tools. By the end, you’ll showcase the practical skills of a SOC analyst—detecting, responding, and reporting on endpoint threats—while reinforcing your readiness for professional roles and certifications in cybersecurity defense.
Das ist alles enthalten
1 Video1 peer review
Infos zu Modulinhalt anzeigen
1 Video•Insgesamt 2 Minuten
Course Wrap-up•2 Minuten
1 peer review•Insgesamt 60 Minuten
Project: Designing a Mini Endpoint Security Strategy for an Organization •60 Minuten
Our purpose at Starweaver is to empower individuals and organizations with practical knowledge and skills for a rapidly transforming world. By collaborating with an extensive, global network of proven expert educators, we deliver engaging, information-rich learning experiences that work to revolutionize lives and careers. Committed to our belief that people are the most valuable asset, we focus on building capabilities to navigate ever evolving challenges in technology, business, and design.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.
Finanzielle Unterstützung verfügbar, weitere Informationen
¹ Einige Aufgaben in diesem Kurs werden mit AI bewertet. Für diese Aufgaben werden Ihre Daten in Übereinstimmung mit Datenschutzhinweis von Courseraverwendet.