Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course goals, anticipated outcomes, and preparing the lab environment
  • Overview of EDR architecture and the various components of OpenEDR
  • Recap of the MITRE ATT&CK framework and the basics of threat hunting

Deploying OpenEDR & Gathering Telemetry

  • Installation and configuration of OpenEDR agents across Windows endpoints
  • Setting up server components, data ingestion pipelines, and storage structures
  • Configuring telemetry sources, normalizing events, and enriching data

Analyzing Endpoint Telemetry & Event Modeling

  • Examining critical endpoint event types and fields, and their relationship to ATT&CK techniques
  • Strategies for event filtering, correlation, and minimizing noise
  • Deriving trustworthy detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage and identifying detection gaps
  • Utilizing the ATT&CK Navigator and documenting mapping rationale
  • Prioritizing techniques for hunting efforts based on risk levels and data availability

Methodologies for Threat Hunting

  • Contrasting hypothesis-driven hunting with indicator-led investigative approaches
  • Developing hunt playbooks and refining iterative discovery processes
  • Practical hunting labs: Detecting lateral movement, persistence, and privilege escalation

Detection Engineering & Optimization

  • Crafting detection rules using event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives and gauge effectiveness
  • Developing signatures and analytical content for reuse across the environment

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and map attack timelines
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
  • Embedding findings into IR playbooks and remediation procedures

Automation, Orchestration & System Integration

  • Automating routine hunts and enhancing alerts through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence systems
  • Managing telemetry scaling, retention policies, and operational aspects for enterprise scale

Advanced Scenarios & Red Team Collaboration

  • Emulating adversary actions for validation through purple-team exercises and ATT&CK-based simulations
  • Analyzing case studies of real-world hunts and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Capstone Project & Presentations

  • Supervised capstone: Executing a complete hunt from hypothesis to containment and root cause analysis in a lab setting
  • Presenting participant findings and suggested mitigation strategies
  • Final course summary, resource distribution, and suggestions for further learning

Requirements

  • Solid grasp of core endpoint security principles
  • Practical experience with log analysis and fundamental Linux/Windows system administration
  • Knowledge of prevalent attack vectors and incident response methodologies

Target Audience

  • Security Operations Center (SOC) specialists
  • Dedicated threat hunters and incident response professionals
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories