Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Reviewing course objectives, anticipated outcomes, and preparing the lab environment
- Exploring core EDR concepts and the architectural design of the OpenEDR platform
- Grasping the nature of endpoint telemetry and its underlying data sources
OpenEDR Deployment
- Installing OpenEDR agents across Windows and Linux endpoints
- Establishing the OpenEDR server infrastructure and dashboards
- Setting up fundamental telemetry and logging parameters
Basic Detection and Alerting
- Interpreting various event types and understanding their relevance
- Defining detection rules and establishing appropriate thresholds
- Monitoring system alerts and notifications
Event Analysis & Investigation
- Scrutinizing events for patterns indicative of suspicious behavior
- Correlating endpoint activities with recognized attack methodologies
- Leveraging OpenEDR dashboards and search utilities for detailed investigation
Response & Mitigation
- Taking action on alerts and addressing suspicious activities
- Quarantining affected endpoints to mitigate immediate threats
- Recording actions taken and aligning them with incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEM systems or other security tools
- Creating comprehensive reports for leadership and key stakeholders
- Applying best practices for ongoing monitoring and alert optimization
Capstone Lab & Practical Exercises
- Engaging in a hands-on lab that replicates real-world endpoint threats
- Executing workflows for detection, analysis, and response
- Evaluating lab outcomes and discussing key takeaways
Summary and Next Steps
Requirements
- A foundational understanding of core cybersecurity concepts
- Practical experience in administering Windows and/or Linux systems
- Familiarity with existing endpoint protection or monitoring solutions
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security teams within small to mid-sized businesses
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.