Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, expected outcomes, and preparing the lab environment.
- Overview of high-level EDR architecture and OpenEDR core components.
- Recap of the MITRE ATT&CK framework and essential threat-hunting principles.
OpenEDR Deployment & Telemetry Acquisition
- Installing and configuring OpenEDR agents on Windows-based endpoints.
- Managing server components, data ingestion pipelines, and storage requirements.
- Setting up telemetry sources, normalizing events, and enriching data.
Decoding Endpoint Telemetry & Event Modeling
- Analyzing key endpoint event types and fields, and their correlation to ATT&CK techniques.
- Implementing event filtering, correlation strategies, and techniques to minimize noise.
- Generating reliable detection signals from low-fidelity telemetry data.
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator and documenting mapping decisions for clarity.
- Prioritizing techniques for hunting based on risk levels and data availability.
Threat Hunting Methodologies
- Contrasting hypothesis-driven hunting with indicator-led investigations.
- Developing hunt playbooks and establishing iterative discovery processes.
- Practical hunting labs: detecting lateral movement, persistence, and privilege escalation tactics.
Detection Engineering & Optimization
- Crafting detection rules based on event correlation and behavioral baselines.
- Testing rules, tuning to minimize false positives, and assessing effectiveness.
- Creating reusable signatures and analytic content across the environment.
Incident Response & Root Cause Analysis using OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Handling forensic artifact collection, evidence preservation, and chain-of-custody protocols.
- Embedding findings into IR playbooks and remediation procedures.
Automation, Orchestration & System Integration
- Automating routine hunts and enriching alerts via scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scaling, retention, and operational challenges in enterprise deployments.
Advanced Scenarios & Red Team Collaboration
- Validating defenses through adversary simulation, purple-team exercises, and ATT&CK-based emulation.
- Examining case studies: real-world hunting efforts and post-incident reviews.
- Establishing continuous improvement cycles for detection coverage.
Capstone Project & Presentations
- Guided capstone exercise: executing a full hunt from hypothesis through containment and root cause analysis.
- Presenting findings and proposing mitigation strategies.
- Course conclusion, distribution of materials, and guidance on next steps.
Requirements
- Foundational knowledge of endpoint security principles.
- Practical experience with log analysis and basic Linux/Windows system administration.
- Familiarity with standard attack vectors and incident response methodologies.
Target Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident response specialists.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.