Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, anticipated outcomes, and lab environment preparation
  • Exploring EDR concepts and the architectural design of the OpenEDR platform
  • Grasping the nature of endpoint telemetry and its associated data sources

OpenEDR Deployment

  • Installing OpenEDR agents on Windows and Linux endpoint devices
  • Establishing the OpenEDR server infrastructure and visual dashboards
  • Setting up foundational telemetry streams and logging configurations

Fundamental Detection & Alerting

  • Interpreting various event types and assessing their security significance
  • Defining detection rules and adjusting sensitivity thresholds
  • Tracking system alerts and managing notifications

Event Analysis & Investigation

  • Examining events to uncover suspicious behavioral patterns
  • Correlating endpoint actions with prevalent attack methodologies
  • Utilizing OpenEDR dashboards and search utilities for detailed investigation

Response & Mitigation Strategies

  • Executing appropriate responses to alerts and identified suspicious activity
  • Quarantining affected endpoints to contain and mitigate threats
  • Recording remedial actions and aligning them with incident response protocols

Integration & Reporting

  • Connecting OpenEDR with SIEM platforms or other complementary security tools
  • Compiling executive reports for management and key stakeholders
  • Adopting best practices for sustained monitoring and alert optimization

Capstone Lab & Practical Application

  • Engaging in hands-on simulations of realistic endpoint threats
  • Implementing end-to-end detection, analysis, and response procedures
  • Collaborative review of lab outcomes and key takeaways

Conclusion & Future Pathways

Requirements

  • Foundational knowledge of cybersecurity principles
  • Administrative experience with Windows and/or Linux systems
  • Working familiarity with endpoint protection or monitoring solutions

Target Audience

  • IT and security specialists initiating their journey with endpoint detection tools
  • Cybersecurity engineers
  • Security personnel within small to mid-sized enterprises

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories