Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Orientation
- Defining course goals, anticipated outcomes, and preparing the laboratory environment.
- A broad overview of EDR principles and the architectural design of the OpenEDR platform.
- Gaining insight into endpoint telemetry mechanisms and various data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux devices.
- Establishing the OpenEDR server infrastructure and configuring user dashboards.
- Setting up initial telemetry collection and logging processes.
Foundational Detection and Alerting
- Interpreting different event types and their operational relevance.
- Defining detection rules and setting appropriate sensitivity thresholds.
- Overseeing alerts and managing notification channels.
Event Analysis and Investigation
- Examining events to uncover suspicious behavioral patterns.
- Correlating endpoint activities with known attack techniques.
- Leveraging OpenEDR dashboards and search utilities to conduct thorough investigations.
Response and Mitigation
- Addressing alerts and containing suspicious activities.
- Quarantining compromised endpoints to neutralize threats.
- Recording response actions and aligning them with incident response protocols.
Integration and Reporting
- Connecting OpenEDR with SIEM systems and other security tools.
- Creating reports for executive leadership and key stakeholders.
- Applying best practices for sustained monitoring and refining alert accuracy.
Capstone Lab and Practical Drills
- Conducting hands-on simulations of real-world endpoint security incidents.
- Executing comprehensive detection, analysis, and response workflows.
- Debriefing on laboratory results and extracting key lessons.
Conclusions and Future Pathways
Requirements
- Foundational knowledge of core cybersecurity principles.
- Practical experience in administering Windows and/or Linux systems.
- Basic familiarity with endpoint protection or monitoring utilities.
Target Audience
- IT and security specialists new to endpoint detection tools.
- Cybersecurity engineers.
- Security personnel in small to mid-sized enterprises.
Testimonials (1)
Clarity and pace of explanations