Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Overview

  • Defining course objectives, expected outcomes, and setting up the lab environment
  • An overview of EDR concepts and the OpenEDR platform architecture
  • Gaining insight into endpoint telemetry and various data sources

Deploying OpenEDR

  • Installing OpenEDR agents on Windows and Linux endpoints
  • Establishing the OpenEDR server and configuring dashboards
  • Setting up basic telemetry and logging mechanisms

Fundamental Detection and Alerting

  • Understanding different event types and their security significance
  • Configuring detection rules and sensitivity thresholds
  • Monitoring system alerts and notifications

Event Analysis & Investigation

  • Examining events to identify suspicious behavioral patterns
  • Correlating endpoint behaviors with common attack techniques
  • Utilizing OpenEDR dashboards and search tools for detailed investigation

Response & Mitigation Strategies

  • Responding effectively to alerts and detected suspicious activity
  • Isolating compromised endpoints and mitigating active threats
  • Documenting response actions and integrating them into incident response protocols

Integration & Reporting

  • Connecting OpenEDR with SIEM solutions and other security tools
  • Creating comprehensive reports for management and key stakeholders
  • Implementing best practices for continuous monitoring and alert optimization

Capstone Lab & Practical Application

  • Engaging in a hands-on lab that simulates real-world endpoint threats
  • Applying detection, analysis, and response workflows in practice
  • Reviewing lab results and discussing key lessons learned

Summary and Future Directions

Requirements

  • A solid grasp of fundamental cybersecurity concepts
  • Experience in administering Windows and/or Linux systems
  • Familiarity with existing endpoint protection or monitoring tools

Target Audience

  • IT and security professionals beginning their journey with endpoint detection tools
  • Cybersecurity engineers
  • Security staff in small to mid-sized businesses

Testimonials (2)

Related Categories