Midnight is a theme for GitHub Pages.
Platform: Microsoft Defender for Endpoint / Microsoft Defender XDR
Focus: Endpoint onboarding, alert generation, incident investigation, and response
This lab demonstrates practical experience with Microsoft Defender for Endpoint, including:
The lab simulates a controlled attack scenario and follows a structured SOC investigation workflow.
All activities were performed in an isolated, non-production environment.
Initiated device discovery from the Defender portal to identify assets within the environment.


Executed onboarding script on a virtual machine to connect the host to Defender for Endpoint.

Confirmed that the host was successfully onboarded and visible in the Defender portal.

Executed a test script on the onboarded VM to generate security alerts.

Verified that alerts generated from the test activity were successfully ingested into Defender.

Configured roles within the Defender portal to manage access and permissions.



Created a security group in Microsoft Entra ID for role assignment and access control.

Configured device groups to segment endpoints and apply policies.

Opened and analysed the test alert generated during simulation.

Observed how Defender automatically correlates alerts into an incident.


Reviewed incident details, severity, affected assets, and recommended actions.

Executed another attack script to generate additional suspicious activity.

Verified that multiple alerts were grouped into a single incident for investigation.



Reviewed collected evidence including:
to understand the attack chain.

The investigation followed a structured SOC methodology:
All activities were performed in a controlled lab environment using simulated attack scenarios.