Back to all modules

Microsoft Defender XDR

Microsoft Defender XDR icon

Explore how Microsoft Defender XDR detects and responds to real-world attack techniques—from initial access to lateral movement—using live lab scenarios.

Microsoft Defender XDR is built to correlate threat signals across endpoints, identities, email, and cloud apps. This module walks you through the attacker kill chain step-by-step, helping you understand how different stages of an attack surface in Defender tools. Across the module, you'll investigate alerts and signals related to Initial Access, Privilege Escalation, Lateral Movement, and more. By working through real-world scenarios, you'll develop hands-on experience with Microsoft Defender for Endpoint and Identity, building the skills needed to detect, investigate, and respond to complex threats using XDR.

Microsoft Defender XDR icon

We use cookies to ensure you get the best user experience. For more information contact us.

Read more