Get in Touch
 Duration 14 hours

Course Outline

Introduction and Course Orientation

  • Defining course goals, anticipated outcomes, and preparing the laboratory environment.
  • A broad overview of EDR principles and the architectural design of the OpenEDR platform.
  • Gaining insight into endpoint telemetry mechanisms and various data sources.

OpenEDR Deployment

  • Installing OpenEDR agents on Windows and Linux devices.
  • Establishing the OpenEDR server infrastructure and configuring user dashboards.
  • Setting up initial telemetry collection and logging processes.

Foundational Detection and Alerting

  • Interpreting different event types and their operational relevance.
  • Defining detection rules and setting appropriate sensitivity thresholds.
  • Overseeing alerts and managing notification channels.

Event Analysis and Investigation

  • Examining events to uncover suspicious behavioral patterns.
  • Correlating endpoint activities with known attack techniques.
  • Leveraging OpenEDR dashboards and search utilities to conduct thorough investigations.

Response and Mitigation

  • Addressing alerts and containing suspicious activities.
  • Quarantining compromised endpoints to neutralize threats.
  • Recording response actions and aligning them with incident response protocols.

Integration and Reporting

  • Connecting OpenEDR with SIEM systems and other security tools.
  • Creating reports for executive leadership and key stakeholders.
  • Applying best practices for sustained monitoring and refining alert accuracy.

Capstone Lab and Practical Drills

  • Conducting hands-on simulations of real-world endpoint security incidents.
  • Executing comprehensive detection, analysis, and response workflows.
  • Debriefing on laboratory results and extracting key lessons.

Conclusions and Future Pathways

Requirements

  • Foundational knowledge of core cybersecurity principles.
  • Practical experience in administering Windows and/or Linux systems.
  • Basic familiarity with endpoint protection or monitoring utilities.

Target Audience

  • IT and security specialists new to endpoint detection tools.
  • Cybersecurity engineers.
  • Security personnel in small to mid-sized enterprises.

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories