Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course goals, expected outcomes, and preparing the lab environment.
- Overview of EDR architecture and key OpenEDR components.
- Review of the MITRE ATT&CK framework and core threat-hunting concepts.
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Managing server components, data ingestion pipelines, and storage strategies.
- Setting up telemetry sources, normalizing events, and enriching data.
Understanding Endpoint Telemetry & Event Modeling
- Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques.
- Applying event filtering, correlation strategies, and noise reduction methods.
- Deriving reliable detection signals from low-fidelity telemetry.
Mapping Detections to MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator to document mapping decisions.
- Prioritizing hunting techniques based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations.
- Developing hunt playbooks and iterative discovery workflows.
- Hands-on labs: Detecting lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Tuning
- Crafting detection rules using event correlation and behavioral baselines.
- Testing rules, tuning to minimize false positives, and measuring efficacy.
- Developing signatures and analytic content for reuse across the environment.
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Collecting forensic artifacts, preserving evidence, and ensuring chain-of-custody integrity.
- Incorporating findings into IR playbooks and remediation processes.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Scaling telemetry, retention policies, and operational aspects for enterprise use.
Advanced Use Cases & Red Team Collaboration
- Validating defenses by simulating adversary behavior: Purple-team exercises and ATT&CK-based emulation.
- Examining case studies: Real-world hunts and post-incident reviews.
- Designing continuous improvement cycles to enhance detection coverage.
Capstone Lab & Presentations
- Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis in a lab scenario.
- Presenting findings and recommended mitigations.
- Course conclusion, distribution of materials, and suggestions for next steps.
Requirements
- Solid grasp of endpoint security fundamentals.
- Practical experience in log analysis and basic Linux/Windows system administration.
- Awareness of common attack vectors and incident response principles.
Target Audience
- Security operations center (SOC) analysts.
- Specialized threat hunters and incident responders.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.