Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Clarification of course objectives, expected learning outcomes, and preparation of the lab environment
  • Overview of high-level EDR architecture and core OpenEDR components
  • Refresher on the MITRE ATT&CK framework and essential threat-hunting concepts

OpenEDR Deployment & Telemetry Acquisition

  • Installation and configuration of OpenEDR agents across Windows endpoints
  • Management of server components, data ingestion pipelines, and storage requirements
  • Configuration of telemetry sources, along with event normalization and enrichment processes

Interpreting Endpoint Telemetry & Event Modeling

  • Identification of key endpoint event types and fields, and their alignment with ATT&CK techniques
  • Strategies for event filtering, correlation, and noise reduction
  • Deriving reliable detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Translating telemetry data into ATT&CK technique coverage to identify detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping decisions for transparency
  • Prioritizing specific techniques for hunting based on risk levels and telemetry availability

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigative approaches
  • Development of hunt playbooks and iterative discovery workflows
  • Practical hunting labs: detecting patterns of lateral movement, persistence, and privilege escalation

Detection Engineering & Optimization

  • Crafting detection rules utilizing event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives and measure detection effectiveness
  • Developing signatures and analytic content for reuse throughout the environment

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Collection of forensic artifacts, preservation of evidence, and adherence to chain-of-custody protocols
  • Integration of investigation findings into IR playbooks and remediation procedures

Automation, Orchestration & System Integration

  • Automating routine hunts and enriching alerts through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms for cohesive operations
  • Addressing scaling of telemetry, data retention, and operational needs for enterprise-grade deployments

Advanced Use Cases & Red Team Collaboration

  • Simulating adversary behaviors for validation through purple-team exercises and ATT&CK-based emulation
  • Examination of case studies involving real-world hunts and post-incident analyses
  • Establishing continuous improvement cycles to enhance detection coverage

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis formation through containment and root cause analysis using lab scenarios
  • Presentation of participant findings and recommended mitigation strategies
  • Course conclusion, distribution of materials, and guidance on recommended next steps

Requirements

  • A solid grasp of endpoint security principles
  • Practical experience with log analysis and foundational Linux or Windows administration
  • Knowledge of prevalent attack vectors and incident response methodologies

Target Audience

  • Security Operations Center (SOC) analysts
  • Dedicated threat hunters and incident response specialists
  • Security engineers overseeing detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories