Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Review of course goals, anticipated outcomes, and preparation of the lab environment.
- High-level overview of EDR principles and the OpenEDR platform’s architectural design.
- Gaining insight into endpoint telemetry and its associated data sources.
OpenEDR Deployment
- Installing OpenEDR agents across Windows and Linux endpoint devices.
- Establishing the OpenEDR server infrastructure and user dashboards.
- Setting up initial telemetry collection and logging frameworks.
Basic Detection and Alerting
- Exploring different event types and their relevance to security.
- Defining detection rules and setting appropriate thresholds.
- Overseeing alerts and managing notification streams.
Event Analysis & Investigation
- Examining events to uncover suspicious behavioral patterns.
- Correlating endpoint activities with prevalent attack methodologies.
- Utilizing OpenEDR dashboards and search utilities for in-depth investigation.
Response & Mitigation
- Taking action on alerts and addressing suspicious activities.
- Containing threats by isolating affected endpoints.
- Recording response actions and aligning them with incident response protocols.
Integration & Reporting
- Connecting OpenEDR with SIEM systems and other security tools.
- Creating reports tailored for management and key stakeholders.
- Applying best practices for ongoing monitoring and alert optimization.
Capstone Lab & Practical Exercises
- Conducting a hands-on lab that simulates real-world endpoint security challenges.
- Implementing end-to-end workflows for detection, analysis, and response.
- Evaluating lab results and discussing key takeaways.
Summary and Next Steps
Requirements
- A foundational grasp of core cybersecurity principles.
- Administrative experience with Windows and/or Linux operating systems.
- Working familiarity with existing endpoint protection or monitoring solutions.
Target Audience
- IT and security personnel beginning their journey with endpoint detection tools.
- Cybersecurity engineers seeking to expand their toolset.
- Security staff at small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.