Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Overview
- Defining course objectives, expected outcomes, and setting up the lab environment
- An overview of EDR concepts and the OpenEDR platform architecture
- Gaining insight into endpoint telemetry and various data sources
Deploying OpenEDR
- Installing OpenEDR agents on Windows and Linux endpoints
- Establishing the OpenEDR server and configuring dashboards
- Setting up basic telemetry and logging mechanisms
Fundamental Detection and Alerting
- Understanding different event types and their security significance
- Configuring detection rules and sensitivity thresholds
- Monitoring system alerts and notifications
Event Analysis & Investigation
- Examining events to identify suspicious behavioral patterns
- Correlating endpoint behaviors with common attack techniques
- Utilizing OpenEDR dashboards and search tools for detailed investigation
Response & Mitigation Strategies
- Responding effectively to alerts and detected suspicious activity
- Isolating compromised endpoints and mitigating active threats
- Documenting response actions and integrating them into incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEM solutions and other security tools
- Creating comprehensive reports for management and key stakeholders
- Implementing best practices for continuous monitoring and alert optimization
Capstone Lab & Practical Application
- Engaging in a hands-on lab that simulates real-world endpoint threats
- Applying detection, analysis, and response workflows in practice
- Reviewing lab results and discussing key lessons learned
Summary and Future Directions
Requirements
- A solid grasp of fundamental cybersecurity concepts
- Experience in administering Windows and/or Linux systems
- Familiarity with existing endpoint protection or monitoring tools
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security staff in small to mid-sized businesses
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.