Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Orientation

  • Course goals, anticipated outcomes, and preparation of the lab environment
  • Overview of EDR architecture and key OpenEDR components
  • Examination of the MITRE ATT&CK framework and core threat-hunting principles

OpenEDR Deployment and Telemetry Acquisition

  • Installation and configuration of OpenEDR agents on Windows endpoints
  • Server components, data ingestion pipelines, and storage requirements
  • Setting up telemetry sources, event normalization, and data enrichment

Interpreting Endpoint Telemetry and Event Modeling

  • Essential endpoint event types, fields, and their alignment with ATT&CK techniques
  • Strategies for event filtering, correlation, and minimizing noise
  • Deriving reliable detection signals from low-fidelity telemetry

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and recording mapping decisions
  • Prioritizing hunting efforts based on risk levels and telemetry availability

Threat Hunting Methodologies

  • Contrasting hypothesis-driven hunting with indicator-led investigations
  • Developing hunt playbooks and iterative discovery processes
  • Practical hunting labs: detecting lateral movement, persistence, and privilege escalation patterns

Detection Engineering and Optimization

  • Crafting detection rules utilizing event correlation and behavioral baselines
  • Testing rules, reducing false positives, and assessing effectiveness
  • Developing signatures and analytic content for cross-environment reuse

Incident Response and Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Collecting forensic artifacts, preserving evidence, and managing chain-of-custody
  • Integrating insights into IR playbooks and remediation procedures

Automation, Orchestration, and Integration

  • Automating standard hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Scaling telemetry, retention policies, and operational aspects for enterprise setups

Advanced Scenarios and Red Team Collaboration

  • Validating defenses through adversary behavior simulation: purple-team exercises and ATT&CK-based emulation
  • Case studies: real-world hunting experiences and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Capstone Project and Presentations

  • Guided capstone: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
  • Participant presentations of findings and suggested mitigation strategies
  • Course conclusion, material distribution, and recommended subsequent steps

Requirements

  • A solid grasp of endpoint security principles
  • Practical experience in log analysis and fundamental Linux/Windows administration
  • Knowledge of prevalent attack techniques and incident response methodologies

Target Audience

  • Security Operations Center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories