Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Clarification of course objectives, expected learning outcomes, and preparation of the lab environment
- Overview of high-level EDR architecture and core OpenEDR components
- Refresher on the MITRE ATT&CK framework and essential threat-hunting concepts
OpenEDR Deployment & Telemetry Acquisition
- Installation and configuration of OpenEDR agents across Windows endpoints
- Management of server components, data ingestion pipelines, and storage requirements
- Configuration of telemetry sources, along with event normalization and enrichment processes
Interpreting Endpoint Telemetry & Event Modeling
- Identification of key endpoint event types and fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and noise reduction
- Deriving reliable detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Translating telemetry data into ATT&CK technique coverage to identify detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions for transparency
- Prioritizing specific techniques for hunting based on risk levels and telemetry availability
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigative approaches
- Development of hunt playbooks and iterative discovery workflows
- Practical hunting labs: detecting patterns of lateral movement, persistence, and privilege escalation
Detection Engineering & Optimization
- Crafting detection rules utilizing event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and measure detection effectiveness
- Developing signatures and analytic content for reuse throughout the environment
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Collection of forensic artifacts, preservation of evidence, and adherence to chain-of-custody protocols
- Integration of investigation findings into IR playbooks and remediation procedures
Automation, Orchestration & System Integration
- Automating routine hunts and enriching alerts through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms for cohesive operations
- Addressing scaling of telemetry, data retention, and operational needs for enterprise-grade deployments
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behaviors for validation through purple-team exercises and ATT&CK-based emulation
- Examination of case studies involving real-world hunts and post-incident analyses
- Establishing continuous improvement cycles to enhance detection coverage
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis formation through containment and root cause analysis using lab scenarios
- Presentation of participant findings and recommended mitigation strategies
- Course conclusion, distribution of materials, and guidance on recommended next steps
Requirements
- A solid grasp of endpoint security principles
- Practical experience with log analysis and foundational Linux or Windows administration
- Knowledge of prevalent attack vectors and incident response methodologies
Target Audience
- Security Operations Center (SOC) analysts
- Dedicated threat hunters and incident response specialists
- Security engineers overseeing detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
instructor's benevolence
Pierre Do Huu - L'assurance maladie
Course - MITRE ATT&CK
Machine Translated