Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course goals, anticipated results, and preparing the lab environment
- Overview of EDR architecture and specific OpenEDR components
- Reviewing the MITRE ATT&CK framework and essential threat-hunting concepts
OpenEDR Deployment & Telemetry Acquisition
- Installing and setting up OpenEDR agents on Windows-based endpoints
- Configuring server components, data ingestion pipelines, and storage requirements
- Establishing telemetry sources, normalizing events, and enriching data
Interpreting Endpoint Telemetry & Event Modeling
- Analyzing key endpoint event types and fields, and their alignment with ATT&CK techniques
- Applying event filtering, correlation strategies, and methods to reduce noise
- Deriving reliable detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping rationales
- Prioritizing hunting techniques based on risk assessment and telemetry availability
Threat Hunting Approaches
- Comparing hypothesis-driven hunting with indicator-led investigative methods
- Developing hunt playbooks and iterative discovery processes
- Practical hunting labs: detecting lateral movement, persistence mechanisms, and privilege escalation trends
Detection Engineering & Optimization
- Crafting detection rules utilizing event correlation and behavioral baselines
- Testing and refining rules to minimize false positives and evaluate efficacy
- Developing reusable signatures and analytic content for broader environmental application
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
- Merging insights into IR playbooks and remediation procedures
Automation, Orchestration & System Integration
- Automating routine hunts and alert enrichment through scripting and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Managing telemetry scaling, retention policies, and enterprise operational considerations
Advanced Scenarios & Red Team Collaboration
- Emulating adversary behaviors for validation through purple-team exercises and ATT&CK-based simulations
- Examining case studies of real-world hunts and post-incident reviews
- Establishing continuous improvement loops for detection coverage
Capstone Project & Presentations
- Supervised capstone: executing a complete hunt from hypothesis formation to containment and root cause analysis in lab scenarios
- Participant presentations detailing findings and proposed mitigations
- Course conclusion, resource distribution, and suggestions for further development
Requirements
- A solid grasp of endpoint security core principles
- Practical experience in log analysis and foundational Linux or Windows administration
- Familiarity with prevalent attack vectors and incident response methodologies
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers overseeing detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.