Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, expected learning outcomes, and preparing the lab environment.
  • Overview of EDR architecture and core OpenEDR components.
  • Review of the MITRE ATT&CK framework and foundational threat-hunting concepts.

OpenEDR Deployment & Telemetry Collection

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Managing server components, data ingestion pipelines, and storage strategies.
  • Setting up telemetry sources, event normalization, and data enrichment processes.

Understanding Endpoint Telemetry & Event Modeling

  • Analyzing key endpoint event types and their mapping to ATT&CK techniques.
  • Applying event filtering, correlation strategies, and noise reduction methods.
  • Extracting reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Translating telemetry data into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator to document and visualize mapping decisions.
  • Prioritizing hunting efforts based on risk levels and data availability.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigation approaches.
  • Developing hunt playbooks and iterative discovery workflows.
  • Practical labs focused on identifying lateral movement, persistence, and privilege escalation patterns.

Detection Engineering & Tuning

  • Creating detection rules leveraging event correlation and behavioral baselines.
  • Testing and tuning rules to minimize false positives while measuring effectiveness.
  • Developing reusable signatures and analytic content for broader environmental deployment.

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines.
  • Collecting forensic artifacts, preserving evidence, and managing chain-of-custody.
  • Integrating analytical findings into IR playbooks and remediation workflows.

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scalability, data retention, and operational needs for enterprise deployments.

Advanced Use Cases & Red Team Collaboration

  • Validating defenses through purple-team exercises and ATT&CK-based adversary emulation.
  • Examining case studies featuring real-world hunts and post-incident reviews.
  • Establishing continuous improvement cycles to enhance detection coverage.

Capstone Lab & Presentations

  • Guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios.
  • Presenting findings and recommended mitigations to the cohort.
  • Course conclusion, distribution of materials, and guidance for next steps.

Requirements

  • Solid grasp of endpoint security principles.
  • Practical experience in log analysis and fundamental Linux/Windows system administration.
  • Proficiency in recognizing common attack vectors and understanding incident response methodologies.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Dedicated threat hunters and incident response specialists.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories