Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction & Course Orientation
- Overview of course objectives, expected outcomes, and lab environment preparation
- High-level view of EDR architecture and OpenEDR components
- Recap of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Deployment & Telemetry Collection
- Installing and configuring OpenEDR agents on Windows endpoints
- Setting up server components, data ingestion pipelines, and storage strategies
- Configuring telemetry sources, event normalisation, and data enrichment
Understanding Endpoint Telemetry & Event Modeling
- Key endpoint event types, fields, and their mapping to ATT&CK techniques
- Strategies for event filtering, correlation, and noise reduction
- Developing reliable detection signals from low-fidelity telemetry
Mapping Detections to MITRE ATT&CK
- Translating telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilising ATT&CK Navigator and documenting mapping decisions
- Prioritising techniques for hunting based on risk profile and telemetry availability
Threat Hunting Methodologies
- Comparative analysis of hypothesis-driven hunting versus indicator-led investigations
- Developing hunt playbooks and iterative discovery workflows
- Hands-on hunting labs: detecting lateral movement, persistence, and privilege escalation patterns
Detection Engineering & Tuning
- Crafting detection rules using event correlation and behavioral baselines
- Testing and tuning rules to minimise false positives and measure effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
- Forensic artifact collection, evidence preservation, and chain-of-custody protocols
- Integrating findings into IR playbooks and remediation workflows
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment using scripts and connectors
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, retention strategies, and operational considerations for enterprise deployments
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behavior for validation: purple-team exercises and ATT&CK-based emulation
- Case studies: real-world hunts and post-incident reviews
- Designing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis through containment and root cause analysis in lab scenarios
- Participant presentations of findings and recommended mitigations
- Course wrap-up, distribution of materials, and recommended next steps
Requirements
- A solid grasp of endpoint security fundamentals
- Proficiency in log analysis and basic Linux/Windows administration
- Knowledge of common attack techniques and core incident response concepts
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.