Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course goals, learning outcomes, and preparation of the lab environment.
- High-level architectural review of EDR systems and specific OpenEDR components.
- Recap of the MITRE ATT&CK framework and essential threat-hunting concepts.
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents across Windows endpoints.
- Management of server components, data ingestion pipelines, and storage strategies.
- Setup of telemetry sources, along with event normalization and enrichment processes.
Understanding Endpoint Telemetry & Event Modeling
- Analysis of key endpoint event types and fields, and their mapping to ATT&CK techniques.
- Strategies for event filtering, correlation, and effective noise reduction.
- Deriving reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage assessments and identifying detection gaps.
- Utilizing the ATT&CK Navigator to document and visualize mapping decisions.
- Prioritizing hunting efforts based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigation methods.
- Development of hunt playbooks and iterative discovery workflows.
- Hands-on laboratory sessions focused on identifying lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Tuning
- Crafting detection rules utilizing event correlation and behavioral baselines.
- Testing rules, adjusting for false positives, and evaluating detection effectiveness.
- Creating reusable signatures and analytic content for broader environmental application.
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Procedures for forensic artifact collection, evidence preservation, and maintaining chain-of-custody.
- Incorporating investigative findings into IR playbooks and remediation strategies.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripting and connector tools.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scaling, retention, and operational requirements for enterprise-grade deployments.
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behaviors for validation purposes, including purple-team exercises and ATT&CK-based emulation.
- Review of case studies involving real-world hunts and post-incident analyses.
- Establishing continuous improvement cycles for enhancing detection coverage.
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis formation through containment and root cause analysis using lab scenarios.
- Participant presentations detailing findings and proposed mitigation strategies.
- Course conclusion, distribution of materials, and recommendations for next steps.
Requirements
- A solid grasp of endpoint security fundamentals.
- Practical experience with log analysis and basic administration of Linux and Windows systems.
- Familiarity with prevalent attack vectors and core incident response principles.
Target Audience
- Security Operations Center (SOC) analysts.
- Dedicated threat hunters and incident response specialists.
- Security engineers overseeing detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.