Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Overview
- Defining course goals, expected results, and preparing the lab environment
- Introduction to EDR concepts and the architectural design of the OpenEDR platform
- Understanding the nature of endpoint telemetry and its data sources
Deploying OpenEDR
- Installing OpenEDR agents on Windows and Linux systems
- Establishing the OpenEDR server and configuring dashboards
- Setting up foundational telemetry and logging mechanisms
Foundational Detection and Alerting
- Understanding various event types and their operational significance
- Defining detection rules and setting appropriate thresholds
- Monitoring alerts and system notifications
Event Analysis and Investigation
- Scrutinizing events to identify suspicious behavioral patterns
- Correlating endpoint actions with known attack techniques
- Leveraging OpenEDR dashboards and search utilities for in-depth investigation
Response and Mitigation Strategies
- Reacting to alerts and anomalous activity
- Isolating affected endpoints to contain and mitigate threats
- Recording response actions and integrating them into the incident response framework
Integration and Reporting
- Connecting OpenEDR with SIEM systems or other security applications
- Creating reports for executive leadership and key stakeholders
- Applying best practices for ongoing monitoring and alert optimization
Capstone Lab and Practical Application
- Interactive lab exercise simulating realistic endpoint threats
- Executing detection, analysis, and response workflows in practice
- Evaluating lab outcomes and discussing key takeaways
Conclusion and Future Pathways
Requirements
- Foundational knowledge of cybersecurity principles
- Operational experience with Windows and/or Linux systems administration
- General familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security experts new to endpoint detection tools
- Cybersecurity engineers
- Security personnel in small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.