Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, learning outcomes, and lab environment configuration
- High-level architecture of EDR solutions and specific OpenEDR components
- Review of the MITRE ATT&CK framework and core threat-hunting concepts
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows systems
- Management of server components, data ingestion pipelines, and storage best practices
- Setup of telemetry sources, event normalization, and data enrichment processes
Endpoint Telemetry & Event Modeling Insights
- Analysis of key endpoint event types, fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and noise reduction
- Developing reliable detection signals from lower-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions effectively
- Prioritizing techniques for hunting based on risk assessment and telemetry availability
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigations
- Development of hunt playbooks and iterative discovery processes
- Practical labs: detecting lateral movement, persistence mechanisms, and privilege escalation
Detection Engineering & Optimization
- Crafting detection rules using event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and evaluate effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Forensic artifact collection, evidence preservation, and chain-of-custody management
- Integrating findings into IR playbooks and remediation procedures
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, retention policies, and operational aspects for enterprise environments
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
- Case studies: real-world hunting scenarios and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis to containment and root cause analysis
- Participant presentations showcasing findings and recommended mitigations
- Course conclusion, resource distribution, and guidance for next steps
Requirements
- Solid grasp of endpoint security fundamentals
- Practical experience with log analysis and basic Linux/Windows system administration
- Knowledge of common attack vectors and incident response principles
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.