Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Course objectives, expected outcomes, and lab environment setup.
- High-level EDR architecture and an overview of OpenEDR components.
- Review of the MITRE ATT&CK framework and threat-hunting fundamentals.
OpenEDR Deployment & Telemetry Collection
- Installing and configuring OpenEDR agents on Windows endpoints.
- Setting up server components, data ingestion pipelines, and storage considerations.
- Configuring telemetry sources, event normalization, and enrichment processes.
Understanding Endpoint Telemetry & Event Modeling
- Key endpoint event types, fields, and their mapping to ATT&CK techniques.
- Event filtering, correlation strategies, and noise reduction techniques.
- Creating reliable detection signals from low-fidelity telemetry.
Mapping Detections to MITRE ATT&CK
- Translating telemetry into ATT&CK technique coverage and identifying detection gaps.
- Using ATT&CK Navigator and documenting mapping decisions.
- Prioritizing techniques for hunting based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Hypothesis-driven hunting versus indicator-led investigations.
- Hunt playbook development and iterative discovery workflows.
- Hands-on hunting labs focused on identifying lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Tuning
- Designing detection rules using event correlation and behavioral baselines.
- Rule-testing, tuning to reduce false positives, and measuring effectiveness.
- Creating signatures and analytic content for reuse across the environment.
Incident Response & Root Cause Analysis with OpenEDR
- Using OpenEDR to triage alerts, investigate incidents, and timeline attacks.
- Forensic artifact collection, evidence preservation, and chain-of-custody considerations.
- Integrating findings into IR playbooks and remediation workflows.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment using scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Scaling telemetry, retention, and operational considerations for enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
- Case studies featuring real-world hunts and post-incident analyses.
- Designing continuous improvement cycles for detection coverage.
Capstone Lab & Presentations
- Guided capstone: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
- Participant presentations of findings and recommended mitigations.
- Course wrap-up, materials distribution, and recommended next steps.
Requirements
- A solid understanding of endpoint security fundamentals.
- Practical experience with log analysis and basic Linux/Windows administration.
- Familiarity with common attack techniques and incident response concepts.
Audience
- Security operations center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers responsible for detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
The instructor's mastery of all the topics
Miguel Angel Jimenez Sanchez - ASP Integra Opciones
Course - MITRE ATT&CK
Machine Translated