Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and lab environment setup
- High-level view of EDR architecture and specific OpenEDR components
- Review of the MITRE ATT&CK framework and essential threat-hunting fundamentals
OpenEDR Deployment & Telemetry Collection
- Installation and configuration of OpenEDR agents on Windows endpoints
- Server-side components, data ingestion pipelines, and storage strategies
- Setting up telemetry sources, along with event normalization and enrichment processes
Understanding Endpoint Telemetry & Event Modeling
- Key endpoint event types, fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and noise reduction
- Deriving reliable detection signals from low-fidelity telemetry data
Mapping Detections to MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage while identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions
- Prioritizing hunting techniques based on risk profiles and telemetry availability
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and iterative discovery workflows
- Hands-on labs: detecting lateral movement, persistence, and privilege escalation patterns
Detection Engineering & Tuning
- Crafting detection rules using event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and measure effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and build attack timelines
- Collecting forensic artifacts, preserving evidence, and managing chain-of-custody
- Integrating findings into IR playbooks and remediation workflows
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment via scripts and connectors
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Addressing scaling, retention, and operational needs for enterprise deployments
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
- Case studies: real-world hunts and post-incident analysis
- Designing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios
- Participant presentations of findings and recommended mitigations
- Course wrap-up, distribution of materials, and recommended next steps
Requirements
- A solid grasp of endpoint security fundamentals
- Practical experience with log analysis and basic Linux/Windows administration
- Familiarity with prevalent attack techniques and core incident response concepts
Audience
- Security operations center (SOC) analysts
- Threat hunters and incident responders
- Security engineers overseeing detection engineering and telemetry
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
The instructor's mastery of all the topics
Miguel Angel Jimenez Sanchez - ASP Integra Opciones
Course - MITRE ATT&CK
Machine Translated