Course Outline
Introduction and Course Orientation
- Course goals, anticipated outcomes, and preparation of the lab environment
- Overview of EDR architecture and key OpenEDR components
- Examination of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Deployment and Telemetry Acquisition
- Installation and configuration of OpenEDR agents on Windows endpoints
- Server components, data ingestion pipelines, and storage requirements
- Setting up telemetry sources, event normalization, and data enrichment
Interpreting Endpoint Telemetry and Event Modeling
- Essential endpoint event types, fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and minimizing noise
- Deriving reliable detection signals from low-fidelity telemetry
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and recording mapping decisions
- Prioritizing hunting efforts based on risk levels and telemetry availability
Threat Hunting Methodologies
- Contrasting hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and iterative discovery processes
- Practical hunting labs: detecting lateral movement, persistence, and privilege escalation patterns
Detection Engineering and Optimization
- Crafting detection rules utilizing event correlation and behavioral baselines
- Testing rules, reducing false positives, and assessing effectiveness
- Developing signatures and analytic content for cross-environment reuse
Incident Response and Root Cause Analysis via OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Collecting forensic artifacts, preserving evidence, and managing chain-of-custody
- Integrating insights into IR playbooks and remediation procedures
Automation, Orchestration, and Integration
- Automating standard hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, retention policies, and operational aspects for enterprise setups
Advanced Scenarios and Red Team Collaboration
- Validating defenses through adversary behavior simulation: purple-team exercises and ATT&CK-based emulation
- Case studies: real-world hunting experiences and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Capstone Project and Presentations
- Guided capstone: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
- Participant presentations of findings and suggested mitigation strategies
- Course conclusion, material distribution, and recommended subsequent steps
Requirements
- A solid grasp of endpoint security principles
- Practical experience in log analysis and fundamental Linux/Windows administration
- Knowledge of prevalent attack techniques and incident response methodologies
Target Audience
- Security Operations Center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.