Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Alignment

  • Defining course goals, anticipated outcomes, and preparing the lab environment
  • Overview of high-level EDR architecture and core OpenEDR components
  • Refresher on the MITRE ATT&CK framework and fundamental threat-hunting concepts

Deploying OpenEDR and Collecting Telemetry

  • Installation and configuration of OpenEDR agents on Windows endpoints
  • Setting up server components, data ingestion pipelines, and evaluating storage needs
  • Establishing telemetry sources, normalizing events, and enriching data

Interpreting Endpoint Telemetry and Event Modeling

  • Identifying key endpoint event types, relevant fields, and their alignment with ATT&CK techniques
  • Applying event filtering, correlation strategies, and methods to reduce noise
  • Deriving reliable detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage assessments and identifying detection gaps
  • Leveraging ATT&CK Navigator and documenting mapping decisions
  • Prioritizing techniques for hunting based on risk profiles and telemetry availability

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations
  • Developing hunt playbooks and implementing iterative discovery workflows
  • Practical hunting labs focusing on lateral movement, persistence, and privilege escalation patterns

Detection Engineering and Tuning

  • Crafting detection rules utilizing event correlation and behavioral baselines
  • Testing rules, adjusting to minimize false positives, and evaluating effectiveness
  • Developing reusable signatures and analytic content across the environment

Incident Response and Root Cause Analysis with OpenEDR

  • Utilizing OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
  • Embedding findings into IR playbooks and remediation processes

Automation, Orchestration, and Integration

  • Automating routine hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Addressing scaling, retention, and operational factors for enterprise-grade deployments

Advanced Use Cases and Red Team Collaboration

  • Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
  • Analyzing case studies from real-world hunts and post-incident reviews
  • Establishing continuous improvement cycles to enhance detection coverage

Capstone Lab and Presentations

  • Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis in a lab setting
  • Participant presentations of discovered findings and recommended mitigations
  • Course conclusion, resource distribution, and suggested next steps

Requirements

  • Solid grasp of endpoint security fundamentals
  • Practical experience in log analysis and basic Linux/Windows system administration
  • Familiarity with prevalent attack techniques and incident response principles

Target Audience

  • Security Operations Center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories