Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Course objectives, expected outcomes, and lab environment setup
- Overview of EDR concepts and the OpenEDR platform architecture
- Understanding endpoint telemetry and associated data sources
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints
- Setting up the OpenEDR server and associated dashboards
- Configuring basic telemetry and logging mechanisms
Basic Detection and Alerting
- Understanding different event types and their significance
- Configuring detection rules and thresholds
- Monitoring alerts and system notifications
Event Analysis & Investigation
- Analyzing events to identify suspicious patterns
- Mapping endpoint behaviors to common attack techniques
- Utilizing OpenEDR dashboards and search tools for in-depth investigation
Response & Mitigation
- Responding to alerts and identified suspicious activity
- Isolating compromised endpoints and mitigating active threats
- Documenting actions taken and integrating them into incident response protocols
Integration & Reporting
- Integrating OpenEDR with SIEMs or other security tools
- Generating comprehensive reports for management and stakeholders
- Best practices for continuous monitoring and alert tuning
Capstone Lab & Practical Exercises
- Hands-on lab simulating real-world endpoint threats
- Applying detection, analysis, and response workflows in practice
- Review and discussion of lab results and key takeaways
Summary and Next Steps
Requirements
- A solid grasp of fundamental cybersecurity concepts
- Practical experience with Windows and/or Linux administration
- Familiarity with existing endpoint protection or monitoring solutions
Target Audience
- IT and security professionals beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security staff at small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.