Course Outline
Introduction and Course Orientation
- Overview of course objectives, expected outcomes, and lab environment setup.
- An overview of high-level EDR architecture and OpenEDR components.
- A review of the MITRE ATT&CK framework and core threat-hunting principles.
OpenEDR Deployment and Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Details on server components, data ingestion pipelines, and storage strategies.
- Configuration of telemetry sources, event normalization, and enrichment processes.
Understanding Endpoint Telemetry and Event Modeling
- Identification of key endpoint event types, fields, and their correspondence to ATT&CK techniques.
- Strategies for event filtering, correlation, and noise reduction.
- Development of reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Translation of telemetry into ATT&CK technique coverage and identification of detection gaps.
- Utilization of ATT&CK Navigator and documentation of mapping decisions.
- Prioritization of techniques for hunting based on risk levels and telemetry availability.
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigations.
- Development of hunt playbooks and iterative discovery workflows.
- Hands-on labs focused on identifying lateral movement, persistence, and privilege escalation patterns.
Detection Engineering and Tuning
- Design of detection rules utilizing event correlation and behavioral baselines.
- Testing and tuning rules to minimize false positives and measure effectiveness.
- Creation of signatures and analytic content for reuse across the environment.
Incident Response and Root Cause Analysis with OpenEDR
- Use of OpenEDR to triage alerts, investigate incidents, and construct attack timelines.
- Collection of forensic artifacts, evidence preservation, and adherence to chain-of-custody protocols.
- Integration of findings into IR playbooks and remediation workflows.
Automation, Orchestration, and Integration
- Automation of routine hunts and alert enrichment via scripts and connectors.
- Integration of OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Scaling telemetry, retention policies, and operational considerations for enterprise environments.
Advanced Use Cases and Red Team Collaboration
- Simulation of adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
- Review of case studies involving real-world hunts and post-incident analyses.
- Design of continuous improvement cycles for detection coverage.
Capstone Lab and Presentations
- Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
- Participant presentations of findings and recommended mitigations.
- Course conclusion, distribution of materials, and suggested next steps.
Requirements
- A solid understanding of endpoint security fundamentals.
- Practical experience in log analysis and basic Linux/Windows administration.
- Familiarity with prevalent attack techniques and incident response concepts.
Target Audience
- Security operations center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers tasked with detection engineering and telemetry management.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.