Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course objectives, expected outcomes, and lab environment preparation
  • High-level view of EDR architecture and OpenEDR components
  • Recap of the MITRE ATT&CK framework and core threat-hunting principles

OpenEDR Deployment & Telemetry Collection

  • Installing and configuring OpenEDR agents on Windows endpoints
  • Setting up server components, data ingestion pipelines, and storage strategies
  • Configuring telemetry sources, event normalisation, and data enrichment

Understanding Endpoint Telemetry & Event Modeling

  • Key endpoint event types, fields, and their mapping to ATT&CK techniques
  • Strategies for event filtering, correlation, and noise reduction
  • Developing reliable detection signals from low-fidelity telemetry

Mapping Detections to MITRE ATT&CK

  • Translating telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilising ATT&CK Navigator and documenting mapping decisions
  • Prioritising techniques for hunting based on risk profile and telemetry availability

Threat Hunting Methodologies

  • Comparative analysis of hypothesis-driven hunting versus indicator-led investigations
  • Developing hunt playbooks and iterative discovery workflows
  • Hands-on hunting labs: detecting lateral movement, persistence, and privilege escalation patterns

Detection Engineering & Tuning

  • Crafting detection rules using event correlation and behavioral baselines
  • Testing and tuning rules to minimise false positives and measure effectiveness
  • Creating reusable signatures and analytic content across the environment

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
  • Forensic artifact collection, evidence preservation, and chain-of-custody protocols
  • Integrating findings into IR playbooks and remediation workflows

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment using scripts and connectors
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Scaling telemetry, retention strategies, and operational considerations for enterprise deployments

Advanced Use Cases & Red Team Collaboration

  • Simulating adversary behavior for validation: purple-team exercises and ATT&CK-based emulation
  • Case studies: real-world hunts and post-incident reviews
  • Designing continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis in lab scenarios
  • Participant presentations of findings and recommended mitigations
  • Course wrap-up, distribution of materials, and recommended next steps

Requirements

  • A solid grasp of endpoint security fundamentals
  • Proficiency in log analysis and basic Linux/Windows administration
  • Knowledge of common attack techniques and core incident response concepts

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories