Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Overview

  • Defining course objectives, expected outcomes, and setting up the lab environment.
  • Exploring high-level EDR architecture and key OpenEDR components.
  • Reviewing the MITRE ATT&CK framework and foundational threat-hunting concepts.

OpenEDR Deployment and Telemetry Collection

  • Installing and configuring OpenEDR agents on Windows endpoints.
  • Managing server components, data ingestion pipelines, and storage requirements.
  • Configuring telemetry sources, normalizing events, and enriching data.

Endpoint Telemetry and Event Modeling

  • Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques.
  • Implementing event filtering, correlation strategies, and methods for noise reduction.
  • Generating reliable detection signals from low-fidelity telemetry data.

Aligning Detections with MITRE ATT&CK

  • Translating telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing the ATT&CK Navigator and documenting mapping decisions.
  • Prioritizing hunting efforts based on risk levels and telemetry availability.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations.
  • Developing hunt playbooks and iterative discovery workflows.
  • Conducting hands-on labs to identify lateral movement, persistence, and privilege escalation patterns.

Detection Engineering and Tuning

  • Designing detection rules through event correlation and behavioral baselining.
  • Testing rules, tuning to minimize false positives, and evaluating effectiveness.
  • Creating reusable signatures and analytic content for the broader environment.

Incident Response and Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and build attack timelines.
  • Collecting forensic artifacts, preserving evidence, and addressing chain-of-custody issues.
  • Integrating findings into incident response playbooks and remediation processes.

Automation, Orchestration, and Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scaling, retention, and operational needs for enterprise deployments.

Advanced Use Cases and Red Team Collaboration

  • Validating defenses through purple-team exercises and ATT&CK-based adversary emulation.
  • Analyzing case studies from real-world hunts and post-incident reviews.
  • Establishing continuous improvement cycles for detection coverage.

Capstone Lab and Presentations

  • Executing a guided capstone project: a complete hunt from hypothesis to containment and root cause analysis.
  • Presenting findings and recommended mitigations.
  • Course conclusion, distribution of materials, and outlining recommended next steps.

Requirements

  • A solid grasp of endpoint security fundamentals.
  • Practical experience in log analysis along with basic Linux or Windows administration skills.
  • Knowledge of prevalent attack techniques and core incident response principles.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident responders.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories