Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Orientation
- Defining course goals, anticipated results, and preparing the lab environment.
- A broad look at EDR principles and the underlying architecture of the OpenEDR platform.
- Gaining insight into endpoint telemetry and relevant data origins.
Deploying OpenEDR
- Installing OpenEDR clients on Windows and Linux systems.
- Establishing the OpenEDR server and configuring its dashboards.
- Setting up initial telemetry and logging frameworks.
Fundamental Detection & Alerting
- Grasping the nature of different event types and their implications.
- Defining detection rules and setting appropriate thresholds.
- Supervising alerts and managing notifications.
Event Investigation & Analysis
- Scrutinizing events to detect suspicious behavioral patterns.
- Correlating endpoint activities with standard attack methods.
- Leveraging OpenEDR dashboards and search utilities to conduct investigations.
Response Strategies & Mitigation
- Acting upon alerts and addressing suspicious behaviors.
- Quarantining affected endpoints and neutralizing risks.
- Recording actions taken and embedding them into the incident response process.
System Integration & Reporting
- Connecting OpenEDR with SIEM solutions or other security frameworks.
- Creating reports tailored for leadership and key stakeholders.
- Adopting best practices for ongoing monitoring and alert calibration.
Capstone Exercise & Practical Labs
- An interactive lab simulating genuine endpoint threats.
- Executing comprehensive workflows for detection, analysis, and response.
- Critiquing lab outcomes and extracting key lessons learned.
Recap and Future Directions
Requirements
- A foundational grasp of core cybersecurity principles.
- Practical experience in administering Windows and/or Linux systems.
- Working knowledge of existing endpoint protection or monitoring solutions.
Target Participants
- IT and security specialists beginning their journey with endpoint detection technologies.
- Cybersecurity engineers.
- Security personnel at small and mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
instructor's benevolence
Pierre Do Huu - L'assurance maladie
Course - MITRE ATT&CK
Machine Translated