Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course goals, learning outcomes, and preparation of the lab environment.
  • High-level architectural review of EDR systems and specific OpenEDR components.
  • Recap of the MITRE ATT&CK framework and essential threat-hunting concepts.

OpenEDR Deployment & Telemetry Collection

  • Installation and configuration of OpenEDR agents across Windows endpoints.
  • Management of server components, data ingestion pipelines, and storage strategies.
  • Setup of telemetry sources, along with event normalization and enrichment processes.

Understanding Endpoint Telemetry & Event Modeling

  • Analysis of key endpoint event types and fields, and their mapping to ATT&CK techniques.
  • Strategies for event filtering, correlation, and effective noise reduction.
  • Deriving reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage assessments and identifying detection gaps.
  • Utilizing the ATT&CK Navigator to document and visualize mapping decisions.
  • Prioritizing hunting efforts based on risk profiles and telemetry availability.

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigation methods.
  • Development of hunt playbooks and iterative discovery workflows.
  • Hands-on laboratory sessions focused on identifying lateral movement, persistence, and privilege escalation patterns.

Detection Engineering & Tuning

  • Crafting detection rules utilizing event correlation and behavioral baselines.
  • Testing rules, adjusting for false positives, and evaluating detection effectiveness.
  • Creating reusable signatures and analytic content for broader environmental application.

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Procedures for forensic artifact collection, evidence preservation, and maintaining chain-of-custody.
  • Incorporating investigative findings into IR playbooks and remediation strategies.

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripting and connector tools.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scaling, retention, and operational requirements for enterprise-grade deployments.

Advanced Use Cases & Red Team Collaboration

  • Simulating adversary behaviors for validation purposes, including purple-team exercises and ATT&CK-based emulation.
  • Review of case studies involving real-world hunts and post-incident analyses.
  • Establishing continuous improvement cycles for enhancing detection coverage.

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis formation through containment and root cause analysis using lab scenarios.
  • Participant presentations detailing findings and proposed mitigation strategies.
  • Course conclusion, distribution of materials, and recommendations for next steps.

Requirements

  • A solid grasp of endpoint security fundamentals.
  • Practical experience with log analysis and basic administration of Linux and Windows systems.
  • Familiarity with prevalent attack vectors and core incident response principles.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Dedicated threat hunters and incident response specialists.
  • Security engineers overseeing detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories