Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course goals, learning outcomes, and preparation of the lab environment
- General overview of EDR architecture and key OpenEDR components
- Recap of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Deployment & Telemetry Acquisition
- Installation and configuration of OpenEDR agents on Windows systems
- Management of server-side components, data ingestion pipelines, and storage requirements
- Setup of telemetry sources, along with event normalization and enrichment processes
Interpreting Endpoint Telemetry & Event Modeling
- Identification of key endpoint event types and fields, and their correlation with ATT&CK techniques
- Strategies for event filtering, correlation, and minimizing noise
- Deriving dependable detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage assessments and identifying detection gaps
- Utilization of ATT&CK Navigator and documentation of mapping decisions
- Prioritization of techniques for hunting based on risk levels and telemetry availability
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigation approaches
- Development of hunt playbooks and iterative discovery processes
- Practical hunting exercises: detecting lateral movement, persistence, and privilege escalation behaviors
Detection Engineering & Optimization
- Creation of detection rules leveraging event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and evaluate efficacy
- Development of signatures and analytic content for organizational reuse
Incident Response & Root Cause Analysis with OpenEDR
- Utilizing OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Collection of forensic artifacts, evidence preservation, and adherence to chain-of-custody standards
- Integration of findings into IR playbooks and remediation procedures
Automation, Orchestration & Integration
- Automation of standard hunts and alert enrichment through scripting and connectors
- Connection of OpenEDR with SIEM, SOAR, and threat intelligence systems
- Scalability of telemetry, retention policies, and operational considerations for enterprise use
Advanced Scenarios & Red Team Collaboration
- Simulation of adversary tactics for validation via purple-team exercises and ATT&CK-based emulation
- Examination of case studies involving real-world hunts and post-incident reviews
- Establishment of continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Supervised capstone project: executing a full hunt from hypothesis generation to containment and root cause analysis in a simulated environment
- Participant presentations detailing findings and proposed mitigations
- Course conclusion, distribution of materials, and guidance on subsequent steps
Requirements
- A solid grasp of fundamental endpoint security principles
- Practical experience in log analysis and basic administration of Linux and Windows systems
- Knowledge of prevalent attack methods and incident response procedures
Target Audience
- SOC analysts
- Threat hunters and incident response specialists
- Security engineers tasked with detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.