Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Overview

  • Defining course objectives, expected outcomes, and preparing the lab environment.
  • Gaining an overview of EDR concepts and the architectural design of the OpenEDR platform.
  • Understanding the nuances of endpoint telemetry and various data sources.

Deploying OpenEDR

  • Installing OpenEDR agents on both Windows and Linux endpoints.
  • Establishing the OpenEDR server infrastructure and configuring dashboards.
  • Setting up basic telemetry streams and logging mechanisms.

Foundational Detection & Alerting

  • Comprehending different event types and their operational significance.
  • Defining detection rules and setting appropriate thresholds.
  • Overseeing alerts and managing notifications effectively.

Event Analysis & Investigation

  • Scrutinizing events to uncover suspicious patterns.
  • Correlating endpoint behaviors with known attack techniques.
  • Utilizing OpenEDR dashboards and search utilities for thorough investigations.

Response & Mitigation Strategies

  • Taking action on alerts and addressing suspicious activities.
  • Isolating compromised endpoints and neutralizing threats.
  • Documenting remedial actions and aligning them with incident response protocols.

Integration & Reporting

  • Connecting OpenEDR with SIEMs and other security tools.
  • Creating comprehensive reports for management and key stakeholders.
  • Adopting best practices for continuous monitoring and alert optimization.

Capstone Lab & Practical Exercises

  • Engaging in a hands-on lab that simulates real-world endpoint threats.
  • Implementing detection, analysis, and response workflows in practice.
  • Reviewing lab outcomes and discussing key lessons learned.

Summary & Path Forward

Requirements

  • A solid grasp of foundational cybersecurity principles.
  • Practical experience in administering Windows and/or Linux systems.
  • Familiarity with existing endpoint protection or monitoring solutions.

Target Audience

  • IT and security professionals new to endpoint detection tools.
  • Cybersecurity engineers seeking to expand their operational toolkit.
  • Security staff within small to mid-sized enterprises.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories