Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course objectives, expected outcomes, and preparation of the lab environment.
  • High-level examination of EDR architecture and the core components of OpenEDR.
  • Review of the MITRE ATT&CK framework and foundational threat-hunting concepts.

OpenEDR Deployment & Telemetry Collection

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Analysis of server components, data ingestion pipelines, and storage requirements.
  • Setup of telemetry sources, along with event normalization and enrichment processes.

Understanding Endpoint Telemetry & Event Modeling

  • Examination of key endpoint event types, fields, and their alignment with ATT&CK techniques.
  • Strategies for event filtering, correlation, and reducing data noise.
  • Development of reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Translation of telemetry data into ATT&CK technique coverage and identification of detection gaps.
  • Utilization of ATT&CK Navigator and documentation of mapping decisions.
  • Prioritization of hunting techniques based on risk profiles and data availability.

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigations.
  • Development of hunt playbooks and iterative discovery workflows.
  • Hands-on labs: Identifying patterns of lateral movement, persistence, and privilege escalation.

Detection Engineering & Tuning

  • Design of detection rules leveraging event correlation and behavioral baselines.
  • Testing and tuning rules to minimize false positives and assess effectiveness.
  • Creation of signatures and analytic content for reusable application across environments.

Incident Response & Root Cause Analysis with OpenEDR

  • Use of OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Collection of forensic artifacts, evidence preservation, and chain-of-custody protocols.
  • Integration of findings into IR playbooks and remediation workflows.

Automation, Orchestration & Integration

  • Automation of routine hunts and alert enrichment via scripts and connectors.
  • Integration of OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Considerations for scaling telemetry, retention, and operations in enterprise deployments.

Advanced Use Cases & Red Team Collaboration

  • Simulation of adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
  • Examination of case studies involving real-world hunts and post-incident analyses.
  • Design of continuous improvement cycles to enhance detection coverage.

Capstone Lab & Presentations

  • Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios.
  • Participant presentations of findings and recommended mitigation strategies.
  • Course conclusion, distribution of materials, and identification of recommended next steps.

Requirements

  • A solid grasp of endpoint security fundamentals.
  • Practical experience in log analysis and basic Linux/Windows system administration.
  • Familiarity with prevalent attack techniques and core incident response principles.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and dedicated incident responders.
  • Security engineers focused on detection engineering and telemetry management.

Testimonials (2)

Related Categories