Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, anticipated outcomes, and lab environment preparation
- Exploring EDR concepts and the architectural design of the OpenEDR platform
- Grasping the nature of endpoint telemetry and its associated data sources
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoint devices
- Establishing the OpenEDR server infrastructure and visual dashboards
- Setting up foundational telemetry streams and logging configurations
Fundamental Detection & Alerting
- Interpreting various event types and assessing their security significance
- Defining detection rules and adjusting sensitivity thresholds
- Tracking system alerts and managing notifications
Event Analysis & Investigation
- Examining events to uncover suspicious behavioral patterns
- Correlating endpoint actions with prevalent attack methodologies
- Utilizing OpenEDR dashboards and search utilities for detailed investigation
Response & Mitigation Strategies
- Executing appropriate responses to alerts and identified suspicious activity
- Quarantining affected endpoints to contain and mitigate threats
- Recording remedial actions and aligning them with incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEM platforms or other complementary security tools
- Compiling executive reports for management and key stakeholders
- Adopting best practices for sustained monitoring and alert optimization
Capstone Lab & Practical Application
- Engaging in hands-on simulations of realistic endpoint threats
- Implementing end-to-end detection, analysis, and response procedures
- Collaborative review of lab outcomes and key takeaways
Conclusion & Future Pathways
Requirements
- Foundational knowledge of cybersecurity principles
- Administrative experience with Windows and/or Linux systems
- Working familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security specialists initiating their journey with endpoint detection tools
- Cybersecurity engineers
- Security personnel within small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.