Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction and Course Overview
- Defining course objectives, expected outcomes, and setting up the lab environment.
- Exploring high-level EDR architecture and key OpenEDR components.
- Reviewing the MITRE ATT&CK framework and foundational threat-hunting concepts.
OpenEDR Deployment and Telemetry Collection
- Installing and configuring OpenEDR agents on Windows endpoints.
- Managing server components, data ingestion pipelines, and storage requirements.
- Configuring telemetry sources, normalizing events, and enriching data.
Endpoint Telemetry and Event Modeling
- Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques.
- Implementing event filtering, correlation strategies, and methods for noise reduction.
- Generating reliable detection signals from low-fidelity telemetry data.
Aligning Detections with MITRE ATT&CK
- Translating telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing the ATT&CK Navigator and documenting mapping decisions.
- Prioritizing hunting efforts based on risk levels and telemetry availability.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations.
- Developing hunt playbooks and iterative discovery workflows.
- Conducting hands-on labs to identify lateral movement, persistence, and privilege escalation patterns.
Detection Engineering and Tuning
- Designing detection rules through event correlation and behavioral baselining.
- Testing rules, tuning to minimize false positives, and evaluating effectiveness.
- Creating reusable signatures and analytic content for the broader environment.
Incident Response and Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and build attack timelines.
- Collecting forensic artifacts, preserving evidence, and addressing chain-of-custody issues.
- Integrating findings into incident response playbooks and remediation processes.
Automation, Orchestration, and Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scaling, retention, and operational needs for enterprise deployments.
Advanced Use Cases and Red Team Collaboration
- Validating defenses through purple-team exercises and ATT&CK-based adversary emulation.
- Analyzing case studies from real-world hunts and post-incident reviews.
- Establishing continuous improvement cycles for detection coverage.
Capstone Lab and Presentations
- Executing a guided capstone project: a complete hunt from hypothesis to containment and root cause analysis.
- Presenting findings and recommended mitigations.
- Course conclusion, distribution of materials, and outlining recommended next steps.
Requirements
- A solid grasp of endpoint security fundamentals.
- Practical experience in log analysis along with basic Linux or Windows administration skills.
- Knowledge of prevalent attack techniques and core incident response principles.
Target Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.