Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Course objectives, expected outcomes, and setup of the lab environment.
- Overview of EDR concepts and the OpenEDR platform architecture.
- Understanding endpoint telemetry and various data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints.
- Setting up the OpenEDR server and configuring dashboards.
- Configuring basic telemetry and logging mechanisms.
Basic Detection and Alerting
- Understanding event types and their security significance.
- Configuring detection rules and establishing thresholds.
- Monitoring alerts and managing notifications.
Event Analysis & Investigation
- Analyzing events to uncover suspicious patterns.
- Mapping endpoint behaviors to common attack techniques.
- Utilizing OpenEDR dashboards and search tools for thorough investigation.
Response & Mitigation
- Responding effectively to alerts and suspicious activity.
- Isolating affected endpoints and mitigating active threats.
- Documenting actions taken and integrating findings into incident response.
Integration & Reporting
- Integrating OpenEDR with SIEM or other security tools.
- Generating reports for management and key stakeholders.
- Best practices for continuous monitoring and alert tuning.
Capstone Lab & Practical Exercises
- Hands-on lab simulating real-world endpoint threats.
- Applying detection, analysis, and response workflows.
- Review and discussion of lab results and key lessons learned.
Summary and Next Steps
Requirements
- A solid understanding of basic cybersecurity concepts.
- Practical experience with Windows and/or Linux administration.
- Familiarity with endpoint protection or monitoring tools.
Audience
- IT and security professionals beginning their journey with endpoint detection tools.
- Cybersecurity engineers.
- Security staff in small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.