Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Overview
- Course goals, anticipated results, and setting up the lab environment
- Introduction to EDR principles and the architecture of the OpenEDR platform
- Grasping the nature of endpoint telemetry and its data origins
Implementing OpenEDR
- Installing OpenEDR agents on Windows and Linux devices
- Establishing the OpenEDR server and configuring dashboards
- Setting up fundamental telemetry and log recording
Fundamental Detection and Notifications
- Recognizing different event categories and their importance
- Defining detection parameters and trigger levels
- Tracking alerts and system notifications
Event Examination & Forensics
- Scrutinizing events for irregular patterns
- Correlating endpoint behaviors with standard attack methodologies
- Leveraging OpenEDR dashboards and search utilities for deep dives
Reaction & Containment
- Addressing alerts and detected anomalies
- Quarantining devices and neutralizing threats
- Recording actions and aligning them with incident response protocols
Integration & Documentation
- Connecting OpenEDR with SIEM or other security systems
- Creating reports for leadership and stakeholders
- Optimal strategies for ongoing surveillance and alert refinement
Capstone Project & Practical Drills
- Interactive lab recreating real-world endpoint vulnerabilities
- Executing workflows for detection, analysis, and response
- Debriefing on lab outcomes and key takeaways
Recap and Future Directions
Requirements
- A solid grasp of fundamental cybersecurity principles
- Practical experience in managing Windows and/or Linux systems
- Prior exposure to endpoint security or surveillance utilities
Intended Participants
- IT and security specialists new to endpoint detection solutions
- Cybersecurity engineers
- Security teams at small to medium-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.