Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course goals, learning outcomes, and preparation of the lab environment
  • General overview of EDR architecture and key OpenEDR components
  • Recap of the MITRE ATT&CK framework and core threat-hunting principles

OpenEDR Deployment & Telemetry Acquisition

  • Installation and configuration of OpenEDR agents on Windows systems
  • Management of server-side components, data ingestion pipelines, and storage requirements
  • Setup of telemetry sources, along with event normalization and enrichment processes

Interpreting Endpoint Telemetry & Event Modeling

  • Identification of key endpoint event types and fields, and their correlation with ATT&CK techniques
  • Strategies for event filtering, correlation, and minimizing noise
  • Deriving dependable detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage assessments and identifying detection gaps
  • Utilization of ATT&CK Navigator and documentation of mapping decisions
  • Prioritization of techniques for hunting based on risk levels and telemetry availability

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigation approaches
  • Development of hunt playbooks and iterative discovery processes
  • Practical hunting exercises: detecting lateral movement, persistence, and privilege escalation behaviors

Detection Engineering & Optimization

  • Creation of detection rules leveraging event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives and evaluate efficacy
  • Development of signatures and analytic content for organizational reuse

Incident Response & Root Cause Analysis with OpenEDR

  • Utilizing OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Collection of forensic artifacts, evidence preservation, and adherence to chain-of-custody standards
  • Integration of findings into IR playbooks and remediation procedures

Automation, Orchestration & Integration

  • Automation of standard hunts and alert enrichment through scripting and connectors
  • Connection of OpenEDR with SIEM, SOAR, and threat intelligence systems
  • Scalability of telemetry, retention policies, and operational considerations for enterprise use

Advanced Scenarios & Red Team Collaboration

  • Simulation of adversary tactics for validation via purple-team exercises and ATT&CK-based emulation
  • Examination of case studies involving real-world hunts and post-incident reviews
  • Establishment of continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Supervised capstone project: executing a full hunt from hypothesis generation to containment and root cause analysis in a simulated environment
  • Participant presentations detailing findings and proposed mitigations
  • Course conclusion, distribution of materials, and guidance on subsequent steps

Requirements

  • A solid grasp of fundamental endpoint security principles
  • Practical experience in log analysis and basic administration of Linux and Windows systems
  • Knowledge of prevalent attack methods and incident response procedures

Target Audience

  • SOC analysts
  • Threat hunters and incident response specialists
  • Security engineers tasked with detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories