Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Overview
- Course goals, anticipated outcomes, and setup of the lab environment
- Introduction to EDR concepts and the architectural design of the OpenEDR platform
- Comprehending endpoint telemetry and various data sources
Implementing OpenEDR
- Installation of OpenEDR agents on Windows and Linux endpoints
- Configuration of the OpenEDR server and associated dashboards
- Setup of basic telemetry and logging mechanisms
Initial Detection and Alert Configuration
- Recognizing event types and their operational significance
- Establishing detection rules and appropriate thresholds
- Oversight of alerts and notification systems
Event Scrutiny and Investigation
- Evaluating events to identify suspicious patterns
- Correlating endpoint behaviors with prevalent attack techniques
- Utilizing OpenEDR dashboards and search utilities for thorough investigation
Response and Mitigation Strategies
- Addressing alerts and identified suspicious activities
- Isolating affected endpoints to contain threats
- Recording actions taken and aligning them with incident response protocols
System Integration and Reporting
- Connecting OpenEDR with SIEMs or other security infrastructure
- Creating reports for management and key stakeholders
- Best practices for ongoing monitoring and alert optimization
Capstone Lab and Practical Application
- Practical lab session simulating real-world endpoint threats
- Execution of detection, analysis, and response workflows
- Evaluation of lab outcomes and key takeaways
Recap and Future Directions
Requirements
- A foundational grasp of basic cybersecurity principles
- Practical experience with Windows and/or Linux administration
- Familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security staff at small to mid-sized businesses
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.