Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Reviewing course objectives, anticipated outcomes, and preparing the lab environment
  • Exploring core EDR concepts and the architectural design of the OpenEDR platform
  • Grasping the nature of endpoint telemetry and its underlying data sources

OpenEDR Deployment

  • Installing OpenEDR agents across Windows and Linux endpoints
  • Establishing the OpenEDR server infrastructure and dashboards
  • Setting up fundamental telemetry and logging parameters

Basic Detection and Alerting

  • Interpreting various event types and understanding their relevance
  • Defining detection rules and establishing appropriate thresholds
  • Monitoring system alerts and notifications

Event Analysis & Investigation

  • Scrutinizing events for patterns indicative of suspicious behavior
  • Correlating endpoint activities with recognized attack methodologies
  • Leveraging OpenEDR dashboards and search utilities for detailed investigation

Response & Mitigation

  • Taking action on alerts and addressing suspicious activities
  • Quarantining affected endpoints to mitigate immediate threats
  • Recording actions taken and aligning them with incident response protocols

Integration & Reporting

  • Connecting OpenEDR with SIEM systems or other security tools
  • Creating comprehensive reports for leadership and key stakeholders
  • Applying best practices for ongoing monitoring and alert optimization

Capstone Lab & Practical Exercises

  • Engaging in a hands-on lab that replicates real-world endpoint threats
  • Executing workflows for detection, analysis, and response
  • Evaluating lab outcomes and discussing key takeaways

Summary and Next Steps

Requirements

  • A foundational understanding of core cybersecurity concepts
  • Practical experience in administering Windows and/or Linux systems
  • Familiarity with existing endpoint protection or monitoring solutions

Target Audience

  • IT and security professionals beginning their journey with endpoint detection tools
  • Cybersecurity engineers
  • Security teams within small to mid-sized businesses

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories