Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course objectives, expected outcomes, and lab environment configuration.
  • High-level EDR architecture and an examination of OpenEDR components.
  • Review of the MITRE ATT&CK framework and essential threat-hunting principles.

OpenEDR Deployment & Telemetry Ingestion

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Examination of server components, data ingestion pipelines, and storage requirements.
  • Configuration of telemetry sources, event normalization, and data enrichment.

Endpoint Telemetry Understanding & Event Modeling

  • Analysis of key endpoint event types, fields, and their correspondence to ATT&CK techniques.
  • Strategies for event filtering, correlation, and noise reduction.
  • Deriving reliable detection signals from low-fidelity telemetry.

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator and documenting mapping decisions.
  • Prioritizing hunting techniques based on risk profiles and telemetry availability.

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigations.
  • Development of hunt playbooks and iterative discovery workflows.
  • Practical hunting labs focused on identifying lateral movement, persistence, and privilege escalation patterns.

Detection Engineering & Optimization

  • Designing detection rules leveraging event correlation and behavioral baselines.
  • Testing and tuning rules to minimize false positives and measure effectiveness.
  • Creating reusable signatures and analytic content for the broader environment.

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Forensic artifact collection, evidence preservation, and chain-of-custody protocols.
  • Integrating findings into IR playbooks and remediation processes.

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scalability of telemetry, retention policies, and operational aspects for enterprise deployments.

Advanced Use Cases & Red Team Collaboration

  • Adversary behavior simulation for validation, including purple-team exercises and ATT&CK-based emulation.
  • Review of case studies involving real-world hunts and post-incident analyses.
  • Establishing continuous improvement cycles for detection coverage.

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
  • Participant presentations of findings and recommended mitigation strategies.
  • Course conclusion, distribution of materials, and recommended next steps.

Requirements

  • A solid understanding of endpoint security fundamentals.
  • Practical experience with log analysis and basic Linux or Windows administration.
  • Familiarity with prevalent attack techniques and incident response methodologies.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident responders.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories