Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Defining course goals, anticipated outcomes, and preparing the lab environment
- Overview of EDR architecture and the various components of OpenEDR
- Recap of the MITRE ATT&CK framework and the basics of threat hunting
Deploying OpenEDR & Gathering Telemetry
- Installation and configuration of OpenEDR agents across Windows endpoints
- Setting up server components, data ingestion pipelines, and storage structures
- Configuring telemetry sources, normalizing events, and enriching data
Analyzing Endpoint Telemetry & Event Modeling
- Examining critical endpoint event types and fields, and their relationship to ATT&CK techniques
- Strategies for event filtering, correlation, and minimizing noise
- Deriving trustworthy detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
- Utilizing the ATT&CK Navigator and documenting mapping rationale
- Prioritizing techniques for hunting efforts based on risk levels and data availability
Methodologies for Threat Hunting
- Contrasting hypothesis-driven hunting with indicator-led investigative approaches
- Developing hunt playbooks and refining iterative discovery processes
- Practical hunting labs: Detecting lateral movement, persistence, and privilege escalation
Detection Engineering & Optimization
- Crafting detection rules using event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and gauge effectiveness
- Developing signatures and analytical content for reuse across the environment
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and map attack timelines
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
- Embedding findings into IR playbooks and remediation procedures
Automation, Orchestration & System Integration
- Automating routine hunts and enhancing alerts through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence systems
- Managing telemetry scaling, retention policies, and operational aspects for enterprise scale
Advanced Scenarios & Red Team Collaboration
- Emulating adversary actions for validation through purple-team exercises and ATT&CK-based simulations
- Analyzing case studies of real-world hunts and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Capstone Project & Presentations
- Supervised capstone: Executing a complete hunt from hypothesis to containment and root cause analysis in a lab setting
- Presenting participant findings and suggested mitigation strategies
- Final course summary, resource distribution, and suggestions for further learning
Requirements
- Solid grasp of core endpoint security principles
- Practical experience with log analysis and fundamental Linux/Windows system administration
- Knowledge of prevalent attack vectors and incident response methodologies
Target Audience
- Security Operations Center (SOC) specialists
- Dedicated threat hunters and incident response professionals
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.