Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Course objectives, expected outcomes, and setup of the lab environment.
  • Overview of EDR concepts and the OpenEDR platform architecture.
  • Understanding endpoint telemetry and various data sources.

OpenEDR Deployment

  • Installing OpenEDR agents on Windows and Linux endpoints.
  • Setting up the OpenEDR server and configuring dashboards.
  • Configuring basic telemetry and logging mechanisms.

Basic Detection and Alerting

  • Understanding event types and their security significance.
  • Configuring detection rules and establishing thresholds.
  • Monitoring alerts and managing notifications.

Event Analysis & Investigation

  • Analyzing events to uncover suspicious patterns.
  • Mapping endpoint behaviors to common attack techniques.
  • Utilizing OpenEDR dashboards and search tools for thorough investigation.

Response & Mitigation

  • Responding effectively to alerts and suspicious activity.
  • Isolating affected endpoints and mitigating active threats.
  • Documenting actions taken and integrating findings into incident response.

Integration & Reporting

  • Integrating OpenEDR with SIEM or other security tools.
  • Generating reports for management and key stakeholders.
  • Best practices for continuous monitoring and alert tuning.

Capstone Lab & Practical Exercises

  • Hands-on lab simulating real-world endpoint threats.
  • Applying detection, analysis, and response workflows.
  • Review and discussion of lab results and key lessons learned.

Summary and Next Steps

Requirements

  • A solid understanding of basic cybersecurity concepts.
  • Practical experience with Windows and/or Linux administration.
  • Familiarity with endpoint protection or monitoring tools.

Audience

  • IT and security professionals beginning their journey with endpoint detection tools.
  • Cybersecurity engineers.
  • Security staff in small to mid-sized enterprises.

Testimonials (2)

Upcoming Courses

Related Categories