Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, expected learning outcomes, and lab environment setup.
- Overview of high-level EDR architecture and specific OpenEDR components.
- A refresher on the MITRE ATT&CK framework and the fundamentals of threat hunting.
OpenEDR Deployment & Telemetry Collection
- Installing and configuring OpenEDR agents on Windows-based endpoints.
- Managing server components, data ingestion pipelines, and storage strategies.
- Setting up telemetry sources, event normalization, and enrichment processes.
Understanding Endpoint Telemetry & Event Modeling
- Identifying key endpoint event types, their fields, and their mapping to ATT&CK techniques.
- Applying event filtering, correlation strategies, and techniques to reduce noise.
- Developing reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator to document and justify mapping decisions.
- Prioritizing techniques for hunting efforts based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting approaches with indicator-led investigations.
- Formulating hunt playbooks and iterative discovery workflows.
- Engaging in hands-on hunting labs to identify patterns of lateral movement, persistence, and privilege escalation.
Detection Engineering & Tuning
- Crafting detection rules that leverage event correlation and behavioral baselines.
- Testing rules, tuning to minimize false positives, and assessing overall effectiveness.
- Generating signatures and analytic content designed for reuse across the environment.
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines.
- Collecting forensic artifacts, preserving evidence, and addressing chain-of-custody requirements.
- Integrating investigative findings into IR playbooks and remediation workflows.
Automation, Orchestration & Integration
- Automating routine hunts and enriching alerts through scripts and connectors.
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing the scaling of telemetry, data retention, and operational needs for enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Validating defenses by simulating adversary behavior through purple-team exercises and ATT&CK-based emulation.
- Examining case studies involving real-world hunts and post-incident analyses.
- Establishing continuous improvement cycles for enhancing detection coverage.
Capstone Lab & Presentations
- Executing a guided capstone project: a full hunt from hypothesis formulation through containment and root cause analysis using lab scenarios.
- Presenting findings and proposing recommended mitigations.
- Concluding the course with material distribution and guidance on recommended next steps.
Requirements
- A solid grasp of endpoint security fundamentals.
- Practical experience in log analysis and basic administration of Linux/Windows systems.
- Familiarity with prevalent attack techniques and core incident response concepts.
Target Audience
- Security operations center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers tasked with detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.