Course Outline
Introduction & Course Orientation
- Defining course objectives, expected outcomes, and setting up the laboratory environment.
- An overview of EDR architecture and the constituent parts of OpenEDR.
- A recap of the MITRE ATT&CK framework and the core principles of threat hunting.
OpenEDR Deployment & Telemetry Collection
- Installing and configuring OpenEDR agents across Windows endpoints.
- Managing server components, data ingestion pipelines, and storage requirements.
- Setting up telemetry sources, event normalisation, and data enrichment processes.
Understanding Endpoint Telemetry & Event Modelling
- Examining key endpoint event types and fields, and their correlation with ATT&CK techniques.
- Strategies for event filtering, correlation, and reducing signal noise.
- Developing reliable detection signals from low-fidelity telemetry data.
Mapping Detections to MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage to identify and address detection gaps.
- Utilising ATT&CK Navigator and documenting mapping decisions effectively.
- Prioritising techniques for hunting based on risk levels and available telemetry.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations.
- Developing hunt playbooks and establishing iterative discovery workflows.
- Practical hunting labs: detecting patterns of lateral movement, persistence, and privilege escalation.
Detection Engineering & Tuning
- Crafting detection rules that utilise event correlation and behavioural baselines.
- Testing and tuning rules to minimise false positives and measure effectiveness.
- Creating signatures and analytical content for reuse throughout the environment.
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attack sequences.
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
- Integrating findings into IR playbooks and remediation workflows.
Automation, Orchestration & Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing the scaling of telemetry, retention, and operational needs for enterprise deployments.
Advanced Use Cases & Red Team Collaboration
- Simulating adversary behaviour for validation purposes through purple-team exercises and ATT&CK-based emulation.
- Examining case studies of real-world hunts and post-incident analyses.
- Designing continuous improvement cycles to enhance detection coverage.
Capstone Lab & Presentations
- A guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios.
- Participant presentations detailing findings and recommended mitigations.
- Course conclusion, distribution of materials, and guidance on subsequent steps.
Requirements
- A solid grasp of endpoint security fundamentals.
- Practical experience with log analysis and foundational Linux/Windows administration.
- Knowledge of prevalent attack vectors and incident response principles.
Target Audience
- Security Operations Centre (SOC) analysts.
- Dedicated threat hunters and incident response specialists.
- Security engineers overseeing detection engineering and telemetry infrastructure.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3900 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.