Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, expected outcomes, and preparing the lab environment.
- Exploring core EDR concepts and the architecture of the OpenEDR platform.
- Gaining insight into endpoint telemetry and associated data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints.
- Setting up the OpenEDR server and configuring dashboards.
- Establishing basic telemetry collection and logging mechanisms.
Basic Detection and Alerting
- Interpreting event types and understanding their security significance.
- Defining detection rules and setting appropriate thresholds.
- Overseeing alerts and managing notifications.
Event Analysis & Investigation
- Examining events for suspicious behavioral patterns.
- Correlating endpoint behaviors with common attack techniques.
- Utilizing OpenEDR dashboards and search utilities for deeper investigation.
Response & Mitigation
- Addressing alerts and investigating suspicious activities.
- Isolating affected endpoints and mitigating active threats.
- Documenting actions taken and aligning them with incident response protocols.
Integration & Reporting
- Connecting OpenEDR with SIEM systems or other security tools.
- Creating reports for management and key stakeholders.
- Applying best practices for continuous monitoring and optimizing alert configurations.
Capstone Lab & Practical Exercises
- Conducting hands-on labs that simulate real-world endpoint threats.
- Applying detection, analysis, and response workflows in a practical context.
- Reviewing lab outcomes and discussing key takeaways.
Summary and Next Steps
Requirements
- A foundational understanding of basic cybersecurity concepts.
- Practical experience with Windows and/or Linux system administration.
- Familiarity with endpoint protection or monitoring tools.
Target Audience
- IT and security professionals new to endpoint detection tools.
- Cybersecurity engineers seeking to expand their toolkit.
- Security staff in small to mid-sized businesses.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.