Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and preparation of the lab environment.
- High-level examination of EDR architecture and the core components of OpenEDR.
- Review of the MITRE ATT&CK framework and foundational threat-hunting concepts.
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Analysis of server components, data ingestion pipelines, and storage requirements.
- Setup of telemetry sources, along with event normalization and enrichment processes.
Understanding Endpoint Telemetry & Event Modeling
- Examination of key endpoint event types, fields, and their alignment with ATT&CK techniques.
- Strategies for event filtering, correlation, and reducing data noise.
- Development of reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Translation of telemetry data into ATT&CK technique coverage and identification of detection gaps.
- Utilization of ATT&CK Navigator and documentation of mapping decisions.
- Prioritization of hunting techniques based on risk profiles and data availability.
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigations.
- Development of hunt playbooks and iterative discovery workflows.
- Hands-on labs: Identifying patterns of lateral movement, persistence, and privilege escalation.
Detection Engineering & Tuning
- Design of detection rules leveraging event correlation and behavioral baselines.
- Testing and tuning rules to minimize false positives and assess effectiveness.
- Creation of signatures and analytic content for reusable application across environments.
Incident Response & Root Cause Analysis with OpenEDR
- Use of OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Collection of forensic artifacts, evidence preservation, and chain-of-custody protocols.
- Integration of findings into IR playbooks and remediation workflows.
Automation, Orchestration & Integration
- Automation of routine hunts and alert enrichment via scripts and connectors.
- Integration of OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Considerations for scaling telemetry, retention, and operations in enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Simulation of adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
- Examination of case studies involving real-world hunts and post-incident analyses.
- Design of continuous improvement cycles to enhance detection coverage.
Capstone Lab & Presentations
- Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios.
- Participant presentations of findings and recommended mitigation strategies.
- Course conclusion, distribution of materials, and identification of recommended next steps.
Requirements
- A solid grasp of endpoint security fundamentals.
- Practical experience in log analysis and basic Linux/Windows system administration.
- Familiarity with prevalent attack techniques and core incident response principles.
Target Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and dedicated incident responders.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.