Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, expected outcomes, and setting up the laboratory environment.
  • An overview of EDR architecture and the constituent parts of OpenEDR.
  • A recap of the MITRE ATT&CK framework and the core principles of threat hunting.

OpenEDR Deployment & Telemetry Collection

  • Installing and configuring OpenEDR agents across Windows endpoints.
  • Managing server components, data ingestion pipelines, and storage requirements.
  • Setting up telemetry sources, event normalisation, and data enrichment processes.

Understanding Endpoint Telemetry & Event Modelling

  • Examining key endpoint event types and fields, and their correlation with ATT&CK techniques.
  • Strategies for event filtering, correlation, and reducing signal noise.
  • Developing reliable detection signals from low-fidelity telemetry data.

Mapping Detections to MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage to identify and address detection gaps.
  • Utilising ATT&CK Navigator and documenting mapping decisions effectively.
  • Prioritising techniques for hunting based on risk levels and available telemetry.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations.
  • Developing hunt playbooks and establishing iterative discovery workflows.
  • Practical hunting labs: detecting patterns of lateral movement, persistence, and privilege escalation.

Detection Engineering & Tuning

  • Crafting detection rules that utilise event correlation and behavioural baselines.
  • Testing and tuning rules to minimise false positives and measure effectiveness.
  • Creating signatures and analytical content for reuse throughout the environment.

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attack sequences.
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
  • Integrating findings into IR playbooks and remediation workflows.

Automation, Orchestration & Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing the scaling of telemetry, retention, and operational needs for enterprise deployments.

Advanced Use Cases & Red Team Collaboration

  • Simulating adversary behaviour for validation purposes through purple-team exercises and ATT&CK-based emulation.
  • Examining case studies of real-world hunts and post-incident analyses.
  • Designing continuous improvement cycles to enhance detection coverage.

Capstone Lab & Presentations

  • A guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios.
  • Participant presentations detailing findings and recommended mitigations.
  • Course conclusion, distribution of materials, and guidance on subsequent steps.

Requirements

  • A solid grasp of endpoint security fundamentals.
  • Practical experience with log analysis and foundational Linux/Windows administration.
  • Knowledge of prevalent attack vectors and incident response principles.

Target Audience

  • Security Operations Centre (SOC) analysts.
  • Dedicated threat hunters and incident response specialists.
  • Security engineers overseeing detection engineering and telemetry infrastructure.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3900 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (2)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories