Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Overview

  • Defining course goals, expected learning outcomes, and preparing the lab environment
  • Overview of EDR architecture and key OpenEDR components
  • Recap of the MITRE ATT&CK framework and core threat-hunting concepts

Implementing OpenEDR & Gathering Telemetry

  • Installation and configuration of OpenEDR agents on Windows endpoints
  • Management of server components, data ingestion pipelines, and storage requirements
  • Setting up telemetry sources, normalizing events, and enriching data

Interpreting Endpoint Telemetry & Event Modeling

  • Identifying key endpoint event types and fields, and their alignment with ATT&CK techniques
  • Strategies for event filtering, correlation, and minimizing noise
  • Developing trustworthy detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping decisions
  • Prioritizing techniques for hunting based on risk levels and data availability

Threat Hunting Approaches

  • Comparing hypothesis-driven hunting with indicator-led investigations
  • Creating hunt playbooks and establishing iterative discovery processes
  • Practical labs: Detecting lateral movement, persistence, and privilege escalation patterns

Detection Engineering & Optimization

  • Crafting detection rules based on event correlation and behavioral baselines
  • Testing and tuning rules to minimize false positives and assess effectiveness
  • Developing reusable signatures and analytic content across the environment

Incident Response & Root Cause Analysis with OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody standards
  • Incorporating findings into IR playbooks and remediation workflows

Automation, Orchestration & Integrations

  • Automating routine hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Scaling telemetry, data retention, and operational best practices for enterprise use

Advanced Scenarios & Red Team Collaboration

  • Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
  • Case studies: Real-world hunting scenarios and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
  • Presenting findings and proposing mitigations
  • Course conclusion, distribution of materials, and suggested next steps

Requirements

  • Foundational knowledge of endpoint security principles
  • Practical experience in log analysis and basic administration of Linux or Windows systems
  • Awareness of standard attack methodologies and incident response procedures

Target Audience

  • Security Operations Center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers managing detection engineering and telemetry

Testimonials (2)

Upcoming Courses

Related Categories