Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Overview
- Course goals, anticipated results, and lab environment preparation.
- High-level view of EDR principles and the OpenEDR platform architecture.
- Insights into endpoint telemetry and relevant data sources.
Deploying OpenEDR
- Installing OpenEDR agents on Windows and Linux endpoints.
- Initializing the OpenEDR server and configuring dashboards.
- Setting up foundational telemetry and logging capabilities.
Core Detection and Alerting
- Grasping event categories and their operational significance.
- Defining detection rules and alert thresholds.
- Supervising alerts and notification streams.
Event Analysis and Investigation
- Scrutinizing events to uncover suspicious patterns.
- Correlating endpoint behaviors with known attack techniques.
- Leveraging OpenEDR dashboards and search utilities for deeper investigations.
Response and Mitigation
- Addressing alerts and identified suspicious activities.
- Isolating compromised endpoints and neutralizing threats.
- Recording actions taken and aligning them with incident response protocols.
Integration and Reporting
- Connecting OpenEDR with SIEM systems or other security platforms.
- Creating reports for leadership and key stakeholders.
- Adopting best practices for ongoing monitoring and alert optimization.
Capstone Lab and Practical Drills
- A hands-on lab session simulating real-world endpoint threats.
- Executing detection, analysis, and response procedures.
- Reviewing lab outcomes and discussing key takeaways.
Recap and Future Directions
Requirements
- A foundational grasp of core cybersecurity principles.
- Practical experience managing Windows and/or Linux systems.
- Familiarity with existing endpoint protection or monitoring solutions.
Target Audience
- IT and security professionals new to endpoint detection tools.
- Cybersecurity engineers.
- Security teams in small to medium-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.