Course Outline
Introduction & Course Overview
- Defining course goals, expected learning outcomes, and preparing the lab environment
- Overview of EDR architecture and key OpenEDR components
- Recap of the MITRE ATT&CK framework and core threat-hunting concepts
Implementing OpenEDR & Gathering Telemetry
- Installation and configuration of OpenEDR agents on Windows endpoints
- Management of server components, data ingestion pipelines, and storage requirements
- Setting up telemetry sources, normalizing events, and enriching data
Interpreting Endpoint Telemetry & Event Modeling
- Identifying key endpoint event types and fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and minimizing noise
- Developing trustworthy detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping decisions
- Prioritizing techniques for hunting based on risk levels and data availability
Threat Hunting Approaches
- Comparing hypothesis-driven hunting with indicator-led investigations
- Creating hunt playbooks and establishing iterative discovery processes
- Practical labs: Detecting lateral movement, persistence, and privilege escalation patterns
Detection Engineering & Optimization
- Crafting detection rules based on event correlation and behavioral baselines
- Testing and tuning rules to minimize false positives and assess effectiveness
- Developing reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis with OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody standards
- Incorporating findings into IR playbooks and remediation workflows
Automation, Orchestration & Integrations
- Automating routine hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, data retention, and operational best practices for enterprise use
Advanced Scenarios & Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation
- Case studies: Real-world hunting scenarios and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone project: Executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
- Presenting findings and proposing mitigations
- Course conclusion, distribution of materials, and suggested next steps
Requirements
- Foundational knowledge of endpoint security principles
- Practical experience in log analysis and basic administration of Linux or Windows systems
- Awareness of standard attack methodologies and incident response procedures
Target Audience
- Security Operations Center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers managing detection engineering and telemetry
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.