Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Review of course goals, anticipated outcomes, and preparation of the lab environment.
  • High-level overview of EDR principles and the OpenEDR platform’s architectural design.
  • Gaining insight into endpoint telemetry and its associated data sources.

OpenEDR Deployment

  • Installing OpenEDR agents across Windows and Linux endpoint devices.
  • Establishing the OpenEDR server infrastructure and user dashboards.
  • Setting up initial telemetry collection and logging frameworks.

Basic Detection and Alerting

  • Exploring different event types and their relevance to security.
  • Defining detection rules and setting appropriate thresholds.
  • Overseeing alerts and managing notification streams.

Event Analysis & Investigation

  • Examining events to uncover suspicious behavioral patterns.
  • Correlating endpoint activities with prevalent attack methodologies.
  • Utilizing OpenEDR dashboards and search utilities for in-depth investigation.

Response & Mitigation

  • Taking action on alerts and addressing suspicious activities.
  • Containing threats by isolating affected endpoints.
  • Recording response actions and aligning them with incident response protocols.

Integration & Reporting

  • Connecting OpenEDR with SIEM systems and other security tools.
  • Creating reports tailored for management and key stakeholders.
  • Applying best practices for ongoing monitoring and alert optimization.

Capstone Lab & Practical Exercises

  • Conducting a hands-on lab that simulates real-world endpoint security challenges.
  • Implementing end-to-end workflows for detection, analysis, and response.
  • Evaluating lab results and discussing key takeaways.

Summary and Next Steps

Requirements

  • A foundational grasp of core cybersecurity principles.
  • Administrative experience with Windows and/or Linux operating systems.
  • Working familiarity with existing endpoint protection or monitoring solutions.

Target Audience

  • IT and security personnel beginning their journey with endpoint detection tools.
  • Cybersecurity engineers seeking to expand their toolset.
  • Security staff at small to mid-sized enterprises.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories