Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and lab environment preparation
- High-level EDR architecture and an overview of OpenEDR components
- Review of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints
- Server components, data ingestion pipelines, and storage requirements
- Configuring telemetry sources, event normalization, and data enrichment
Understanding Endpoint Telemetry & Event Modeling
- Key endpoint event types, fields, and their correlation with ATT&CK techniques
- Event filtering, correlation strategies, and methods for noise reduction
- Generating reliable detection signals from low-fidelity telemetry data
Mapping Detections to MITRE ATT&CK
- Translating telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions
- Prioritizing techniques for hunting based on risk levels and telemetry availability
Threat Hunting Methodologies
- Hypothesis-driven hunting versus indicator-led investigations
- Developing hunt playbooks and iterative discovery workflows
- Hands-on labs: Identifying patterns of lateral movement, persistence, and privilege escalation
Detection Engineering & Tuning
- Designing detection rules using event correlation and behavioral baselines
- Testing rules, tuning to minimize false positives, and evaluating effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Forensic artifact collection, evidence preservation, and chain-of-custody protocols
- Integrating investigation findings into IR playbooks and remediation processes
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment via scripts and connectors
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, retention strategies, and operational considerations for enterprise environments
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behavior for validation: Purple-team exercises and ATT&CK-based emulation
- Case studies: Real-world hunting scenarios and post-incident analyses
- Establishing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone: Comprehensive hunt from hypothesis through containment and root cause analysis using lab scenarios
- Participant presentations of findings and suggested mitigations
- Course conclusion, material distribution, and recommended next steps
Requirements
- A solid understanding of endpoint security fundamentals
- Practical experience with log analysis and basic Linux/Windows administration
- Familiarity with prevalent attack techniques and core incident response concepts
Target Audience
- Security Operations Center (SOC) analysts
- Threat hunters and incident responders
- Security engineers overseeing detection engineering and telemetry
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.