Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction and Course Alignment
- Defining course goals, anticipated outcomes, and preparing the lab environment
- Overview of high-level EDR architecture and core OpenEDR components
- Refresher on the MITRE ATT&CK framework and fundamental threat-hunting concepts
Deploying OpenEDR and Collecting Telemetry
- Installation and configuration of OpenEDR agents on Windows endpoints
- Setting up server components, data ingestion pipelines, and evaluating storage needs
- Establishing telemetry sources, normalizing events, and enriching data
Interpreting Endpoint Telemetry and Event Modeling
- Identifying key endpoint event types, relevant fields, and their alignment with ATT&CK techniques
- Applying event filtering, correlation strategies, and methods to reduce noise
- Deriving reliable detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage assessments and identifying detection gaps
- Leveraging ATT&CK Navigator and documenting mapping decisions
- Prioritizing techniques for hunting based on risk profiles and telemetry availability
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and implementing iterative discovery workflows
- Practical hunting labs focusing on lateral movement, persistence, and privilege escalation patterns
Detection Engineering and Tuning
- Crafting detection rules utilizing event correlation and behavioral baselines
- Testing rules, adjusting to minimize false positives, and evaluating effectiveness
- Developing reusable signatures and analytic content across the environment
Incident Response and Root Cause Analysis with OpenEDR
- Utilizing OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
- Embedding findings into IR playbooks and remediation processes
Automation, Orchestration, and Integration
- Automating routine hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Addressing scaling, retention, and operational factors for enterprise-grade deployments
Advanced Use Cases and Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
- Analyzing case studies from real-world hunts and post-incident reviews
- Establishing continuous improvement cycles to enhance detection coverage
Capstone Lab and Presentations
- Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis in a lab setting
- Participant presentations of discovered findings and recommended mitigations
- Course conclusion, resource distribution, and suggested next steps
Requirements
- Solid grasp of endpoint security fundamentals
- Practical experience in log analysis and basic Linux/Windows system administration
- Familiarity with prevalent attack techniques and incident response principles
Target Audience
- Security Operations Center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry management
Testimonials (1)
Clarity and pace of explanations