<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GOC Defender Training on Eriks training corner</title><link>https://training.caha.cloud/goc-defender/index.html</link><description>Recent content in GOC Defender Training on Eriks training corner</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><atom:link href="https://training.caha.cloud/goc-defender/index.xml" rel="self" type="application/rss+xml"/><item><title>M01 · Threat Modeling and MITRE ATT&amp;CK</title><link>https://training.caha.cloud/goc-defender/m01-threat-modeling-and-mitre-attack-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m01-threat-modeling-and-mitre-attack-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.0 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; MITRE ATT&amp;amp;CK is versioned and updated roughly twice a
year, and Microsoft renames portal surfaces frequently. Technique IDs are stable, but matrix
contents, the current ATT&amp;amp;CK version number, and Microsoft portal paths change. Verify the live
ATT&amp;amp;CK version at &lt;a href="https://attack.mitre.org" target="_blank"&gt;https://attack.mitre.org&lt;/a&gt; and product names against Microsoft Learn before
relying on any specific detail below.&lt;/p&gt;</description></item><item><title>M02 · Azure Supporting Technologies</title><link>https://training.caha.cloud/goc-defender/m02-azure-supporting-technologies-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m02-azure-supporting-technologies-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; Azure portal labels, blade names, and navigation paths
change frequently. This handout describes &lt;em&gt;goals and structure&lt;/em&gt; rather than exact click-paths
where the portal is volatile. Verify current paths against Microsoft Learn before relying on a
specific UI step.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;</description></item><item><title>M03 · Security Platform Overview</title><link>https://training.caha.cloud/goc-defender/m03-security-platform-overview-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m03-security-platform-overview-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 2.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; Microsoft renames and reorganizes this product family
frequently, and licensing bundles change regularly. Verify product names, portal paths, and which
plan unlocks which capability against current Microsoft Learn before relying on specifics here.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Describe the Microsoft security ecosystem and how its major products relate to one another.&lt;/li&gt;
&lt;li&gt;Explain Zero Trust principles and identify where each Microsoft product enforces them.&lt;/li&gt;
&lt;li&gt;Name the core products — Defender XDR, Sentinel, Entra, Intune, Purview, Security Copilot — and
their primary functions.&lt;/li&gt;
&lt;li&gt;Identify which licensing plans unlock which capabilities.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-the-microsoft-security-stack-at-a-glance"&gt;1. The Microsoft security stack at a glance&lt;/h2&gt;
&lt;p&gt;Microsoft&amp;rsquo;s security portfolio spans several disciplines that together cover identity, devices, data,
cloud, and operations. The acronyms map to familiar categories:&lt;/p&gt;</description></item><item><title>M04 · Microsoft Defender XDR</title><link>https://training.caha.cloud/goc-defender/m04-defender-xdr-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m04-defender-xdr-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; Portal paths, schema table names, and feature labels in the
unified Defender portal change frequently. Verify navigation and Advanced Hunting schema against
current Microsoft Learn / in-portal schema reference before relying on specifics.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Explain the unified portal&amp;rsquo;s data sources and how signals from multiple workloads are correlated.&lt;/li&gt;
&lt;li&gt;Navigate incidents, alerts, and the investigation graph.&lt;/li&gt;
&lt;li&gt;Describe how automated attack disruption works and when it triggers.&lt;/li&gt;
&lt;li&gt;Perform basic threat hunting using the Advanced Hunting interface and pre-built queries.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-what-xdr-means-here"&gt;1. What &amp;ldquo;XDR&amp;rdquo; means here&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Extended Detection and Response (XDR)&lt;/strong&gt; unifies detections from multiple security workloads into a
single, correlated investigation experience. &lt;strong&gt;Microsoft Defender XDR&lt;/strong&gt; is the unified portal
(&lt;a href="https://security.microsoft.com" target="_blank"&gt;https://security.microsoft.com&lt;/a&gt;) that brings together the workload Defenders so you investigate one
&lt;strong&gt;incident&lt;/strong&gt; instead of chasing separate alerts in separate consoles.&lt;/p&gt;</description></item><item><title>M05 · Defender for Endpoint</title><link>https://training.caha.cloud/goc-defender/m05-defender-for-endpoint-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m05-defender-for-endpoint-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; MDE portal paths, ASR rule sets, and response-action labels
change frequently. Verify rule IDs, default behaviors, and click-paths against current Microsoft
Learn before relying on specifics.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Describe the core capabilities of Microsoft Defender for Endpoint (MDE): EPP, EDR, and
vulnerability management.&lt;/li&gt;
&lt;li&gt;Explain attack surface reduction (ASR) rules and identify common configurations.&lt;/li&gt;
&lt;li&gt;Use the device page to review alerts, timeline, and recommendations.&lt;/li&gt;
&lt;li&gt;Perform basic device response actions: isolate, collect investigation package, run antivirus scan.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-mde-architecture"&gt;1. MDE architecture&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Defender for Endpoint (MDE)&lt;/strong&gt; is Microsoft&amp;rsquo;s endpoint security platform. Three pieces
work together:&lt;/p&gt;</description></item><item><title>M06 · Defender for Office 365</title><link>https://training.caha.cloud/goc-defender/m06-defender-for-office-365-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m06-defender-for-office-365-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.0 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; MDO policy names, Threat Explorer labels, and portal paths
change frequently. Plan 1 vs. Plan 2 feature boundaries also shift. Verify against current
Microsoft Learn before relying on specifics.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Describe how Defender for Office 365 (MDO) protects email and collaboration services.&lt;/li&gt;
&lt;li&gt;Explain the function of Anti-phishing policies, Safe Links, and Safe Attachments.&lt;/li&gt;
&lt;li&gt;Use Threat Explorer to investigate an email-based threat.&lt;/li&gt;
&lt;li&gt;Describe automated investigation and response (AIR) and how to review AIR results.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-mdo-protection-layers"&gt;1. MDO protection layers&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Defender for Office 365 (MDO)&lt;/strong&gt; protects email and collaboration (Exchange Online,
Teams, SharePoint, OneDrive) against phishing, malware, and business email compromise. It is layered:&lt;/p&gt;</description></item><item><title>M07 · Defender for Cloud Apps</title><link>https://training.caha.cloud/goc-defender/m07-defender-for-cloud-apps-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m07-defender-for-cloud-apps-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.0 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; MDCA (Cloud App Security) portal location, policy templates,
and app-governance labels change frequently; much of MDCA now surfaces inside the unified Defender
portal. Verify paths against current Microsoft Learn before relying on specifics.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Explain how Defender for Cloud Apps (MDCA) discovers and assesses SaaS application usage.&lt;/li&gt;
&lt;li&gt;Describe OAuth app governance and the risks of over-permissioned apps.&lt;/li&gt;
&lt;li&gt;Explain session controls and conditional access app control (CAAC).&lt;/li&gt;
&lt;li&gt;Create a simple app policy and review policy matches.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-what-mdca-is-and-how-it-sees-cloud-apps"&gt;1. What MDCA is and how it sees cloud apps&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Defender for Cloud Apps (MDCA)&lt;/strong&gt; is a &lt;strong&gt;Cloud Access Security Broker (CASB)&lt;/strong&gt; — it gives
visibility and control over the SaaS applications your organization uses. It gathers signal through
three mechanisms:&lt;/p&gt;</description></item><item><title>M08 · Defender for Cloud</title><link>https://training.caha.cloud/goc-defender/m08-defender-for-cloud-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m08-defender-for-cloud-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; Defender for Cloud plan names, Secure Score controls, and
portal paths change frequently; compliance standards are updated by their authoring bodies. Verify
plan coverage and navigation against current Microsoft Learn before relying on specifics.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Describe the difference between cloud security posture management (CSPM) and cloud workload
protection (CWPP).&lt;/li&gt;
&lt;li&gt;Navigate the Secure Score and explain how recommendations improve it.&lt;/li&gt;
&lt;li&gt;Identify workload protection plans and what each covers (servers, containers, SQL, storage,
Key Vault).&lt;/li&gt;
&lt;li&gt;Use the regulatory compliance dashboard to review a compliance standard.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id="1-cspm-vs-cwpp--two-jobs-one-product"&gt;1. CSPM vs. CWPP — two jobs, one product&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Defender for Cloud&lt;/strong&gt; does two complementary things:&lt;/p&gt;</description></item><item><title>M09 · Additional Defender Workloads</title><link>https://training.caha.cloud/goc-defender/m09-additional-defender-workloads-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m09-additional-defender-workloads-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 2.5 hours (including light lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; These workloads evolve quickly and some surfaces have been
renamed or reorganized (e.g., &amp;ldquo;Defender for DevOps&amp;rdquo; capabilities under DevOps security posture
management). Verify product names, plan availability, and portal paths against current Microsoft
Learn before relying on specifics; mark anything in preview &lt;code&gt;[PREVIEW]&lt;/code&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;</description></item><item><title>M10 · Security Copilot</title><link>https://training.caha.cloud/goc-defender/m10-security-copilot-handout/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://training.caha.cloud/goc-defender/m10-security-copilot-handout/index.html</guid><description>&lt;p&gt;&lt;strong&gt;Course:&lt;/strong&gt; Microsoft Defender — Security Operations Fundamentals
&lt;strong&gt;Module duration:&lt;/strong&gt; 3.5 hours (including lab)
&lt;strong&gt;Format:&lt;/strong&gt; Instructor-led, hands-on&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Currency note (as of June 2026):&lt;/strong&gt; Microsoft Security Copilot changes rapidly — embedded
experiences, plugins/agents, and the standalone portal evolve on roughly a monthly cadence, and
some features are &lt;code&gt;[PREVIEW]&lt;/code&gt;. Verify capabilities, availability, and portal paths against current
Microsoft Learn before relying on specifics; never present a preview feature as generally available.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="learning-objectives"&gt;Learning objectives&lt;/h2&gt;
&lt;p&gt;By the end of this module you will be able to:&lt;/p&gt;</description></item></channel></rss>