Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Overview
- Learning objectives, anticipated outcomes, and preparation of the lab environment
- Insight into endpoint telemetry and relevant data sources
Deploying OpenEDR
- Installing OpenEDR agents across Windows and Linux endpoints
- Establishing the OpenEDR server and configuring dashboards
- Setting up basic telemetry and logging mechanisms
Foundational Detection & Alerting
- Comprehending event types and their operational significance
- Defining detection rules and sensitivity thresholds
- Overseeing alerts and system notifications
Event Analysis & Investigative Workflows
- Scrutinizing events to uncover suspicious patterns
- Correlating endpoint behaviors with known attack methods
- Utilizing OpenEDR dashboards and search utilities for detailed investigation
Response & Mitigation Strategies
- Addressing alerts and managing suspicious activity
- Containing endpoints and reducing threat impact
- Recording actions taken and aligning them with incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEMs or complementary security tools
- Compiling reports for leadership and key stakeholders
- Implementing best practices for ongoing monitoring and alert refinement
Capstone Lab & Practical Applications
- Interactive lab session replicating real-world endpoint threats
- Executing detection, analysis, and response procedures
- Analyzing lab outcomes and discussing key takeaways
Conclusion and Future Directions
Requirements
- Foundational knowledge of cybersecurity principles
- Practical experience in Windows and/or Linux system administration
- Basic familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security teams within small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.