К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Mastering Endpoint Security & Threat Defense · LearnSpace
Назад в каталог
courseraIT и технологии

Mastering Endpoint Security & Threat Defense

Курс от STARWEAVER
Средний≈ 9 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

In today's evolving cyber threat landscape, every endpoint, whether a laptop, server, cloud workload, or mobile device, represents a potential gateway to sensitive data. Cybercriminals know this, making endpoint security the true front line of threat defense. This endpoint security, and threat defense course provides a structured, beginner-friendly introduction to endpoint security management, taking you beyond traditional antivirus into modern defenses like endpoint detection and response (EDR), Zero Trust, and insider threat detection. Through real-world scenarios and guided labs inside virtual machines, you'll gain practical skills using lightweight, open-source tools such as Sysmon, Velociraptor, osquery, and Sigma. Instead of abstract concepts, you'll work with the same workflows and investigative methods that SOC analysts, sysadmins, and blue teamers use daily for real cyber threat defense and protection practice. By the end of the course, you'll know how to design secure endpoint architectures, monitor and correlate logs for advanced threat detection, and apply Zero Trust principles using built-in security features, the core of effective endpoint security solutions. Whether you're preparing for certifications like CySA+, Blue Team Level 1, or SC-200, aiming for an entry-level SOC role, or transitioning from system administration into a career as an endpoint administrator or security specialist, this course equips you with the skills to stop real-world attacks and build effective cyber threat defenses without costly tools.

Навыки, которые вы освоите

Endpoint SecurityMITRE ATT&CK FrameworkEndpoint Detection and ResponseCyber Threat HuntingHardeningThreat DetectionZero Trust Network AccessSecurity ControlsAnomaly DetectionVirtual MachinesHuman Factors (Security)Cyber Threat IntelligenceAuthenticationsIntrusion Detection and PreventionThreat ManagementContinuous MonitoringIT Security ArchitectureEvent MonitoringCybersecuritySystem Monitoring

Программа курса

6 модулей · 65 учебных материалов

01Course Introduction 3 материалов
Welcome to the Course: Course OverviewЧтениеCourse Introduction ВидеоRolling Out Endpoint Defense in 30 Days: Your First Cross-Functional Decision DIALOGUE
02Introduction to Endpoint Security Management15 материалов

Lesson 1: Foundations & Baseline Hardening

Учитесь у экспертов

Starweaver

Global Leaders in Professional & Technology Education

Rohit Mukherjee

Cybersecurity Mentor |Ex Zscaler, Sophos

Mastering Endpoint Security & Threat Defense
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 9 ч

6 модулей

Язык: Английский

Субтитры: Узбекский, Казахский

Часть программы вашего университета
Module IntroductionВидео
What Is an Endpoint and Why It MattersВидео
Common Attack VectorsВидео
Real-world AttacksВидео

Lesson 2: Core Security Concepts

CIA Triad in Endpoint ContextВидеоHardening Techniques & Best PracticesВидеоEndpoint vs. Network SecurityВидеоApplying the CIA Triad to Endpoint ProtectionОбсуждение

Lesson 3: Endpoint Security Architecture & Assessment

Key Components of Endpoint Security SystemsВидеоSecurity Baseline & Compliance StandardsВидеоRunning a Baseline Scan with CIS-CAT Lite on WindowsВидеоUnderstanding Endpoint Security Basics ЧтениеSecurity Baselines in Practice ОбсуждениеHands-On-Learning: Exploring the CIA Triad on EndpointsВзаимная проверкаIntroduction to Endpoint Security ManagementЗадание
03Endpoint Detection and Response (EDR)15 материалов

Lesson 1: EDR Fundamentals

Module IntroductionВидеоFrom Antivirus to EDRВидеоEDR Pipeline: Collect → Detect → RespondВидеоMITRE ATT&CK in EDRВидеоDesigning an EDR Pipeline in the Real World Обсуждение

Lesson 2: Log Generation & Collection

Key Artifacts: Process, File, Registry, NetworkВидеоSysmon Setup & Rule TuningВидеоVisualizing Endpoint Activity with Process MonitorВидеоBalancing Visibility and Noise with Sysmon Обсуждение

Lesson 3: Endpoint Alert Handling & EDR Analysis

Endpoint Visibility with osquery: Architecture & Live QueriesВидеоInvestigating a Suspicious File-Based Alert with VelociraptorВидеоResponse Discussion and EDR LimitationsВидеоUnderstanding MITRE ATT&CKЧтениеHands-On-Learning: Endpoint Visibility with Sysmon & EDR Pipeline Взаимная проверкаEndpoint Detection and Response (EDR)Задание
04Zero Trust Architecture15 материалов

Lesson 1: Foundations of Zero Trust

Module IntroductionВидеоWhat Is Zero Trust?ВидеоWhy Traditional Models FailВидеоPillars of Zero TrustВидеоPrioritizing Zero Trust Pillars in Implementation Обсуждение

Lesson 2: Inside Zero Trust Architecture

Trust Evaluation WorkflowВидеоPolicy Decision vs EnforcementВидеоEnterprise Reference ModelsВидеоDeciding vs. Enforcing Access Обсуждение

Lesson 3: Zero Trust in Practice

Hardening the Endpoint for Host SecurityВидеоAdvanced Windows Hardening: ASR, Folder Access, Exploit ProtectionВидеоMonitoring & Tamper Protection: Logs, Audit, BaselinesВидеоNIST SP 800-207: Zero Trust ArchitectureЧтениеHands-On-Learning: Enforcing Zero Trust: PDP vs. PEP on Windows Взаимная проверкаZero Trust ArchitectureЗадание
05Insider Threat Management15 материалов

Lesson 1: Understanding Insider Threats

Module IntroductionВидеоWhat Are Insider Threats?ВидеоTypes of Insiders & MotivationsВидеоKey Indicators of Insider BehaviorВидеоUnderstanding Insider Motivations Обсуждение

Lesson 2: Detection Strategies & Endpoint Monitoring

Detection via Logs and BaselinesВидеоRisks Posed by Privileged UsersВидеоPolicy and Legal ConsiderationsВидеоUsing Logs to Spot Insider Activity Обсуждение

Lesson 3: Simulating and Identifying Insider Threat Behavior

Simulating Suspicious ActivityВидеоCapturing Behavior with Sysmon & SigmaВидеоInvestigating the Insider TrailВидеоWindows Security Log Event ID Reference ЧтениеHands-On-Learning: Detecting Suspicious Insider Activity with Windows Event Viewer Взаимная проверкаInsider Threat ManagementЗадание
06Course Conclusion 2 материалов

Final Assessment & Project

Course Wrap-upВидеоProject: Designing a Mini Endpoint Security Strategy for an Organization Взаимная проверка