Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Orientation
- Defining course objectives, expected outcomes, and setting up the lab environment.
- Understanding endpoint telemetry and data sources.
OpenEDR Deployment
- Installing OpenEDR agents across Windows and Linux endpoints.
- Establishing the OpenEDR server infrastructure and dashboards.
- Setting up basic telemetry and logging configurations.
Basic Detection and Alerting
- Comprehending event types and their relevance to security.
- Tuning detection rules and establishing thresholds.
- Overseeing alerts and notification systems.
Event Analysis and Investigation
- Examining events to uncover suspicious patterns.
- Correlating endpoint behaviors with common attack techniques.
- Leveraging OpenEDR dashboards and search utilities for detailed investigations.
Response and Mitigation
- Addressing alerts and suspicious activities effectively.
- Isolating affected endpoints and mitigating active threats.
- Documenting actions taken and integrating findings into incident response processes.
Integration and Reporting
- Connecting OpenEDR with SIEM systems or other security tools.
- Creating comprehensive reports for management and key stakeholders.
- Adopting best practices for ongoing monitoring and alert optimization.
Capstone Lab and Practical Exercises
- Engaging in a hands-on lab that simulates real-world endpoint threats.
- Applying detection, analysis, and response workflows in a practical context.
- Reviewing and discussing lab outcomes and key lessons learned.
Summary and Next Steps
Requirements
- A solid grasp of fundamental cybersecurity concepts.
- Practical experience in Windows and/or Linux system administration.
- Familiarity with endpoint protection or monitoring tools.
Audience
- IT and security professionals beginning their journey with endpoint detection tools.
- Cybersecurity engineers.
- Security staff within small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.