Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, expected learning outcomes, and lab environment setup.
  • Overview of high-level EDR architecture and specific OpenEDR components.
  • A refresher on the MITRE ATT&CK framework and the fundamentals of threat hunting.

OpenEDR Deployment & Telemetry Collection

  • Installing and configuring OpenEDR agents on Windows-based endpoints.
  • Managing server components, data ingestion pipelines, and storage strategies.
  • Setting up telemetry sources, event normalization, and enrichment processes.

Understanding Endpoint Telemetry & Event Modeling

  • Identifying key endpoint event types, their fields, and their mapping to ATT&CK techniques.
  • Applying event filtering, correlation strategies, and techniques to reduce noise.
  • Developing reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator to document and justify mapping decisions.
  • Prioritizing techniques for hunting efforts based on risk profiles and telemetry availability.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting approaches with indicator-led investigations.
  • Formulating hunt playbooks and iterative discovery workflows.
  • Engaging in hands-on hunting labs to identify patterns of lateral movement, persistence, and privilege escalation.

Detection Engineering & Tuning

  • Crafting detection rules that leverage event correlation and behavioral baselines.
  • Testing rules, tuning to minimize false positives, and assessing overall effectiveness.
  • Generating signatures and analytic content designed for reuse across the environment.

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines.
  • Collecting forensic artifacts, preserving evidence, and addressing chain-of-custody requirements.
  • Integrating investigative findings into IR playbooks and remediation workflows.

Automation, Orchestration & Integration

  • Automating routine hunts and enriching alerts through scripts and connectors.
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing the scaling of telemetry, data retention, and operational needs for enterprise deployments.

Advanced Use Cases & Red Team Collaboration

  • Validating defenses by simulating adversary behavior through purple-team exercises and ATT&CK-based emulation.
  • Examining case studies involving real-world hunts and post-incident analyses.
  • Establishing continuous improvement cycles for enhancing detection coverage.

Capstone Lab & Presentations

  • Executing a guided capstone project: a full hunt from hypothesis formulation through containment and root cause analysis using lab scenarios.
  • Presenting findings and proposing recommended mitigations.
  • Concluding the course with material distribution and guidance on recommended next steps.

Requirements

  • A solid grasp of endpoint security fundamentals.
  • Practical experience in log analysis and basic administration of Linux/Windows systems.
  • Familiarity with prevalent attack techniques and core incident response concepts.

Target Audience

  • Security operations center (SOC) analysts.
  • Threat hunters and incident responders.
  • Security engineers tasked with detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories