Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and lab environment configuration
- High-level architecture of EDR systems and an introduction to OpenEDR components
- A refresher on the MITRE ATT&CK framework and core threat-hunting concepts
OpenEDR Deployment & Telemetry Collection
- Installing and configuring OpenEDR agents on Windows endpoints
- Managing server components, data ingestion pipelines, and storage requirements
- Setting up telemetry sources, event normalization, and enrichment processes
Understanding Endpoint Telemetry & Event Modeling
- Examining key endpoint event types, fields, and their alignment with ATT&CK techniques
- Implementing event filtering, correlation strategies, and noise reduction methods
- Deriving reliable detection signals from low-fidelity telemetry data
Mapping Detections to MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions effectively
- Prioritizing techniques for hunting based on risk levels and telemetry availability
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and iterative discovery workflows
- Conducting hands-on hunting labs to detect lateral movement, persistence, and privilege escalation patterns
Detection Engineering & Tuning
- Crafting detection rules utilizing event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives while measuring effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attacks
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
- Integrating findings into IR playbooks and remediation processes
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Addressing telemetry scaling, retention, and operational aspects for enterprise deployments
Advanced Use Cases & Red Team Collaboration
- Validating defenses through purple-team exercises and ATT&CK-based adversary behavior simulation
- Reviewing case studies involving real-world hunts and post-incident analyses
- Designing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Executing a guided capstone project: a full hunt from hypothesis to containment and root cause analysis using lab scenarios
- Presenting findings and recommended mitigations
- Course conclusion, distribution of materials, and suggested next steps
Requirements
- A solid grasp of endpoint security fundamentals
- Practical experience with log analysis and basic Linux or Windows administration
- Familiarity with prevalent attack techniques and incident response principles
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident responders
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.