Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Orientation

  • Overview of course objectives, expected outcomes, and lab environment setup.
  • An overview of high-level EDR architecture and OpenEDR components.
  • A review of the MITRE ATT&CK framework and core threat-hunting principles.

OpenEDR Deployment and Telemetry Collection

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Details on server components, data ingestion pipelines, and storage strategies.
  • Configuration of telemetry sources, event normalization, and enrichment processes.

Understanding Endpoint Telemetry and Event Modeling

  • Identification of key endpoint event types, fields, and their correspondence to ATT&CK techniques.
  • Strategies for event filtering, correlation, and noise reduction.
  • Development of reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Translation of telemetry into ATT&CK technique coverage and identification of detection gaps.
  • Utilization of ATT&CK Navigator and documentation of mapping decisions.
  • Prioritization of techniques for hunting based on risk levels and telemetry availability.

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigations.
  • Development of hunt playbooks and iterative discovery workflows.
  • Hands-on labs focused on identifying lateral movement, persistence, and privilege escalation patterns.

Detection Engineering and Tuning

  • Design of detection rules utilizing event correlation and behavioral baselines.
  • Testing and tuning rules to minimize false positives and measure effectiveness.
  • Creation of signatures and analytic content for reuse across the environment.

Incident Response and Root Cause Analysis with OpenEDR

  • Use of OpenEDR to triage alerts, investigate incidents, and construct attack timelines.
  • Collection of forensic artifacts, evidence preservation, and adherence to chain-of-custody protocols.
  • Integration of findings into IR playbooks and remediation workflows.

Automation, Orchestration, and Integration

  • Automation of routine hunts and alert enrichment via scripts and connectors.
  • Integration of OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Scaling telemetry, retention policies, and operational considerations for enterprise environments.

Advanced Use Cases and Red Team Collaboration

  • Simulation of adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
  • Review of case studies involving real-world hunts and post-incident analyses.
  • Design of continuous improvement cycles for detection coverage.

Capstone Lab and Presentations

  • Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
  • Participant presentations of findings and recommended mitigations.
  • Course conclusion, distribution of materials, and suggested next steps.

Requirements

  • A solid understanding of endpoint security fundamentals.
  • Practical experience in log analysis and basic Linux/Windows administration.
  • Familiarity with prevalent attack techniques and incident response concepts.

Target Audience

  • Security operations center (SOC) analysts.
  • Threat hunters and incident responders.
  • Security engineers tasked with detection engineering and telemetry management.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 4800 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (2)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories