Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and lab environment configuration.
- High-level EDR architecture and an examination of OpenEDR components.
- Review of the MITRE ATT&CK framework and essential threat-hunting principles.
OpenEDR Deployment & Telemetry Ingestion
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Examination of server components, data ingestion pipelines, and storage requirements.
- Configuration of telemetry sources, event normalization, and data enrichment.
Endpoint Telemetry Understanding & Event Modeling
- Analysis of key endpoint event types, fields, and their correspondence to ATT&CK techniques.
- Strategies for event filtering, correlation, and noise reduction.
- Deriving reliable detection signals from low-fidelity telemetry.
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator and documenting mapping decisions.
- Prioritizing hunting techniques based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigations.
- Development of hunt playbooks and iterative discovery workflows.
- Practical hunting labs focused on identifying lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Optimization
- Designing detection rules leveraging event correlation and behavioral baselines.
- Testing and tuning rules to minimize false positives and measure effectiveness.
- Creating reusable signatures and analytic content for the broader environment.
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Forensic artifact collection, evidence preservation, and chain-of-custody protocols.
- Integrating findings into IR playbooks and remediation processes.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scalability of telemetry, retention policies, and operational aspects for enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Adversary behavior simulation for validation, including purple-team exercises and ATT&CK-based emulation.
- Review of case studies involving real-world hunts and post-incident analyses.
- Establishing continuous improvement cycles for detection coverage.
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
- Participant presentations of findings and recommended mitigation strategies.
- Course conclusion, distribution of materials, and recommended next steps.
Requirements
- A solid understanding of endpoint security fundamentals.
- Practical experience with log analysis and basic Linux or Windows administration.
- Familiarity with prevalent attack techniques and incident response methodologies.
Target Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.