Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Course goals, anticipated results, and preparation of the lab environment
- Introduction to EDR concepts and the architecture of the OpenEDR platform
- Grasping endpoint telemetry and associated data sources
Deploying OpenEDR
- Installing OpenEDR agents on both Windows and Linux endpoints
- Establishing the OpenEDR server and configuring its dashboards
- Setting up foundational telemetry and logging protocols
Fundamental Detection & Alerting
- Comprehending event types and their relevance
- Defining detection rules and setting appropriate thresholds
- Overseeing alerts and system notifications
Event Analysis & Investigation
- Scrutinizing events to uncover suspicious patterns
- Correlating endpoint behaviors with standard attack methodologies
- Leveraging OpenEDR dashboards and search utilities for thorough investigations
Response & Mitigation
- Addressing alerts and suspicious activities promptly
- Quarantining endpoints and neutralizing active threats
- Recording actions taken and aligning them with incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEM platforms or other security tools
- Creating comprehensive reports for management and key stakeholders
- Applying best practices for ongoing monitoring and alert optimization
Capstone Lab & Practical Exercises
- A hands-on lab simulating real-world endpoint threats
- Executing detection, analysis, and response workflows
- Debriefing on lab outcomes and key takeaways
Recap & Future Steps
Requirements
- A solid grasp of fundamental cybersecurity principles
- Practical experience in Windows and/or Linux system administration
- Familiarity with existing endpoint protection or monitoring utilities
Target Audience
- IT and security professionals introducing themselves to endpoint detection tools
- Cybersecurity engineers
- Security teams at small to medium-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.