Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course objectives, expected outcomes, and lab environment configuration
  • High-level architecture of EDR systems and an introduction to OpenEDR components
  • A refresher on the MITRE ATT&CK framework and core threat-hunting concepts

OpenEDR Deployment & Telemetry Collection

  • Installing and configuring OpenEDR agents on Windows endpoints
  • Managing server components, data ingestion pipelines, and storage requirements
  • Setting up telemetry sources, event normalization, and enrichment processes

Understanding Endpoint Telemetry & Event Modeling

  • Examining key endpoint event types, fields, and their alignment with ATT&CK techniques
  • Implementing event filtering, correlation strategies, and noise reduction methods
  • Deriving reliable detection signals from low-fidelity telemetry data

Mapping Detections to MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping decisions effectively
  • Prioritizing techniques for hunting based on risk levels and telemetry availability

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations
  • Developing hunt playbooks and iterative discovery workflows
  • Conducting hands-on hunting labs to detect lateral movement, persistence, and privilege escalation patterns

Detection Engineering & Tuning

  • Crafting detection rules utilizing event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives while measuring effectiveness
  • Creating reusable signatures and analytic content across the environment

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attacks
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
  • Integrating findings into IR playbooks and remediation processes

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Addressing telemetry scaling, retention, and operational aspects for enterprise deployments

Advanced Use Cases & Red Team Collaboration

  • Validating defenses through purple-team exercises and ATT&CK-based adversary behavior simulation
  • Reviewing case studies involving real-world hunts and post-incident analyses
  • Designing continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Executing a guided capstone project: a full hunt from hypothesis to containment and root cause analysis using lab scenarios
  • Presenting findings and recommended mitigations
  • Course conclusion, distribution of materials, and suggested next steps

Requirements

  • A solid grasp of endpoint security fundamentals
  • Practical experience with log analysis and basic Linux or Windows administration
  • Familiarity with prevalent attack techniques and incident response principles

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident responders
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories