Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Defining course goals, expected outcomes, and preparing the lab environment
- A comprehensive look at EDR concepts and the OpenEDR platform architecture
- Gaining insight into endpoint telemetry and associated data sources
Deploying OpenEDR
- Installing OpenEDR agents across Windows and Linux systems
- Establishing the OpenEDR server and setting up visual dashboards
- Configuring initial telemetry settings and logging parameters
Fundamental Detection & Alerting
- Interpreting various event types and understanding their operational significance
- Setting up detection rules and defining appropriate thresholds
- Overseeing alerts and system notifications
Event Analysis & Investigation
- Scrutinizing events to uncover suspicious behavioral patterns
- Correlating endpoint activities with common attack methodologies
- Leveraging OpenEDR dashboards and search utilities for deep-dive investigations
Response & Mitigation
- Taking immediate action in response to alerts and unusual activity
- Quarantining affected endpoints and executing threat mitigation measures
- Recording response actions and aligning them with incident response procedures
Integration & Reporting
- Connecting OpenEDR with SIEM solutions or other security platforms
- Creating reports for executive leadership and key stakeholders
- Applying best practices for ongoing monitoring and alert optimization
Capstone Lab & Practical Exercises
- Engaging in a hands-on simulation of realistic endpoint threats
- Executing detection, analysis, and response workflows in a practical setting
- Analyzing lab outcomes and discussing key takeaways
Summary and Future Directions
Requirements
- A solid grasp of fundamental cybersecurity principles
- Practical experience in Windows and/or Linux system administration
- Working knowledge of endpoint protection or monitoring solutions
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security teams within small and mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.