Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course goals, expected outcomes, and preparing the lab environment.
  • Overview of EDR architecture and key OpenEDR components.
  • Review of the MITRE ATT&CK framework and core threat-hunting concepts.

OpenEDR Deployment & Telemetry Collection

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Managing server components, data ingestion pipelines, and storage strategies.
  • Setting up telemetry sources, normalizing events, and enriching data.

Understanding Endpoint Telemetry & Event Modeling

  • Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques.
  • Applying event filtering, correlation strategies, and noise reduction methods.
  • Deriving reliable detection signals from low-fidelity telemetry.

Mapping Detections to MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator to document mapping decisions.
  • Prioritizing hunting techniques based on risk profiles and telemetry availability.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations.
  • Developing hunt playbooks and iterative discovery workflows.
  • Hands-on labs: Detecting lateral movement, persistence, and privilege escalation patterns.

Detection Engineering & Tuning

  • Crafting detection rules using event correlation and behavioral baselines.
  • Testing rules, tuning to minimize false positives, and measuring efficacy.
  • Developing signatures and analytic content for reuse across the environment.

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Collecting forensic artifacts, preserving evidence, and ensuring chain-of-custody integrity.
  • Incorporating findings into IR playbooks and remediation processes.

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Scaling telemetry, retention policies, and operational aspects for enterprise use.

Advanced Use Cases & Red Team Collaboration

  • Validating defenses by simulating adversary behavior: Purple-team exercises and ATT&CK-based emulation.
  • Examining case studies: Real-world hunts and post-incident reviews.
  • Designing continuous improvement cycles to enhance detection coverage.

Capstone Lab & Presentations

  • Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis in a lab scenario.
  • Presenting findings and recommended mitigations.
  • Course conclusion, distribution of materials, and suggestions for next steps.

Requirements

  • Solid grasp of endpoint security fundamentals.
  • Practical experience in log analysis and basic Linux/Windows system administration.
  • Awareness of common attack vectors and incident response principles.

Target Audience

  • Security operations center (SOC) analysts.
  • Specialized threat hunters and incident responders.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories