Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course goals, anticipated results, and preparing the lab environment
  • Overview of EDR architecture and specific OpenEDR components
  • Reviewing the MITRE ATT&CK framework and essential threat-hunting concepts

OpenEDR Deployment & Telemetry Acquisition

  • Installing and setting up OpenEDR agents on Windows-based endpoints
  • Configuring server components, data ingestion pipelines, and storage requirements
  • Establishing telemetry sources, normalizing events, and enriching data

Interpreting Endpoint Telemetry & Event Modeling

  • Analyzing key endpoint event types and fields, and their alignment with ATT&CK techniques
  • Applying event filtering, correlation strategies, and methods to reduce noise
  • Deriving reliable detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping rationales
  • Prioritizing hunting techniques based on risk assessment and telemetry availability

Threat Hunting Approaches

  • Comparing hypothesis-driven hunting with indicator-led investigative methods
  • Developing hunt playbooks and iterative discovery processes
  • Practical hunting labs: detecting lateral movement, persistence mechanisms, and privilege escalation trends

Detection Engineering & Optimization

  • Crafting detection rules utilizing event correlation and behavioral baselines
  • Testing and refining rules to minimize false positives and evaluate efficacy
  • Developing reusable signatures and analytic content for broader environmental application

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
  • Merging insights into IR playbooks and remediation procedures

Automation, Orchestration & System Integration

  • Automating routine hunts and alert enrichment through scripting and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Managing telemetry scaling, retention policies, and enterprise operational considerations

Advanced Scenarios & Red Team Collaboration

  • Emulating adversary behaviors for validation through purple-team exercises and ATT&CK-based simulations
  • Examining case studies of real-world hunts and post-incident reviews
  • Establishing continuous improvement loops for detection coverage

Capstone Project & Presentations

  • Supervised capstone: executing a complete hunt from hypothesis formation to containment and root cause analysis in lab scenarios
  • Participant presentations detailing findings and proposed mitigations
  • Course conclusion, resource distribution, and suggestions for further development

Requirements

  • A solid grasp of endpoint security core principles
  • Practical experience in log analysis and foundational Linux or Windows administration
  • Familiarity with prevalent attack vectors and incident response methodologies

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers overseeing detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories