Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course objectives, learning outcomes, and lab environment configuration
  • High-level architecture of EDR solutions and specific OpenEDR components
  • Review of the MITRE ATT&CK framework and core threat-hunting concepts

OpenEDR Deployment & Telemetry Collection

  • Installation and configuration of OpenEDR agents on Windows systems
  • Management of server components, data ingestion pipelines, and storage best practices
  • Setup of telemetry sources, event normalization, and data enrichment processes

Endpoint Telemetry & Event Modeling Insights

  • Analysis of key endpoint event types, fields, and their alignment with ATT&CK techniques
  • Strategies for event filtering, correlation, and noise reduction
  • Developing reliable detection signals from lower-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping decisions effectively
  • Prioritizing techniques for hunting based on risk assessment and telemetry availability

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigations
  • Development of hunt playbooks and iterative discovery processes
  • Practical labs: detecting lateral movement, persistence mechanisms, and privilege escalation

Detection Engineering & Optimization

  • Crafting detection rules using event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives and evaluate effectiveness
  • Creating reusable signatures and analytic content across the environment

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Forensic artifact collection, evidence preservation, and chain-of-custody management
  • Integrating findings into IR playbooks and remediation procedures

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Scaling telemetry, retention policies, and operational aspects for enterprise environments

Advanced Use Cases & Red Team Collaboration

  • Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
  • Case studies: real-world hunting scenarios and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis to containment and root cause analysis
  • Participant presentations showcasing findings and recommended mitigations
  • Course conclusion, resource distribution, and guidance for next steps

Requirements

  • Solid grasp of endpoint security fundamentals
  • Practical experience with log analysis and basic Linux/Windows system administration
  • Knowledge of common attack vectors and incident response principles

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories