Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, expected learning outcomes, and preparing the lab environment.
- Overview of EDR architecture and core OpenEDR components.
- Review of the MITRE ATT&CK framework and foundational threat-hunting concepts.
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Managing server components, data ingestion pipelines, and storage strategies.
- Setting up telemetry sources, event normalization, and data enrichment processes.
Understanding Endpoint Telemetry & Event Modeling
- Analyzing key endpoint event types and their mapping to ATT&CK techniques.
- Applying event filtering, correlation strategies, and noise reduction methods.
- Extracting reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Translating telemetry data into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator to document and visualize mapping decisions.
- Prioritizing hunting efforts based on risk levels and data availability.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigation approaches.
- Developing hunt playbooks and iterative discovery workflows.
- Practical labs focused on identifying lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Tuning
- Creating detection rules leveraging event correlation and behavioral baselines.
- Testing and tuning rules to minimize false positives while measuring effectiveness.
- Developing reusable signatures and analytic content for broader environmental deployment.
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines.
- Collecting forensic artifacts, preserving evidence, and managing chain-of-custody.
- Integrating analytical findings into IR playbooks and remediation workflows.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scalability, data retention, and operational needs for enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Validating defenses through purple-team exercises and ATT&CK-based adversary emulation.
- Examining case studies featuring real-world hunts and post-incident reviews.
- Establishing continuous improvement cycles to enhance detection coverage.
Capstone Lab & Presentations
- Guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios.
- Presenting findings and recommended mitigations to the cohort.
- Course conclusion, distribution of materials, and guidance for next steps.
Requirements
- Solid grasp of endpoint security principles.
- Practical experience in log analysis and fundamental Linux/Windows system administration.
- Proficiency in recognizing common attack vectors and understanding incident response methodologies.
Target Audience
- Security Operations Center (SOC) analysts.
- Dedicated threat hunters and incident response specialists.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.