Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, expected outcomes, and preparing the lab environment.
  • Overview of high-level EDR architecture and OpenEDR core components.
  • Recap of the MITRE ATT&CK framework and essential threat-hunting principles.

OpenEDR Deployment & Telemetry Acquisition

  • Installing and configuring OpenEDR agents on Windows-based endpoints.
  • Managing server components, data ingestion pipelines, and storage requirements.
  • Setting up telemetry sources, normalizing events, and enriching data.

Decoding Endpoint Telemetry & Event Modeling

  • Analyzing key endpoint event types and fields, and their correlation to ATT&CK techniques.
  • Implementing event filtering, correlation strategies, and techniques to minimize noise.
  • Generating reliable detection signals from low-fidelity telemetry data.

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator and documenting mapping decisions for clarity.
  • Prioritizing techniques for hunting based on risk levels and data availability.

Threat Hunting Methodologies

  • Contrasting hypothesis-driven hunting with indicator-led investigations.
  • Developing hunt playbooks and establishing iterative discovery processes.
  • Practical hunting labs: detecting lateral movement, persistence, and privilege escalation tactics.

Detection Engineering & Optimization

  • Crafting detection rules based on event correlation and behavioral baselines.
  • Testing rules, tuning to minimize false positives, and assessing effectiveness.
  • Creating reusable signatures and analytic content across the environment.

Incident Response & Root Cause Analysis using OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Handling forensic artifact collection, evidence preservation, and chain-of-custody protocols.
  • Embedding findings into IR playbooks and remediation procedures.

Automation, Orchestration & System Integration

  • Automating routine hunts and enriching alerts via scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scaling, retention, and operational challenges in enterprise deployments.

Advanced Scenarios & Red Team Collaboration

  • Validating defenses through adversary simulation, purple-team exercises, and ATT&CK-based emulation.
  • Examining case studies: real-world hunting efforts and post-incident reviews.
  • Establishing continuous improvement cycles for detection coverage.

Capstone Project & Presentations

  • Guided capstone exercise: executing a full hunt from hypothesis through containment and root cause analysis.
  • Presenting findings and proposing mitigation strategies.
  • Course conclusion, distribution of materials, and guidance on next steps.

Requirements

  • Foundational knowledge of endpoint security principles.
  • Practical experience with log analysis and basic Linux/Windows system administration.
  • Familiarity with standard attack vectors and incident response methodologies.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident response specialists.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories