Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Overview
- Defining course objectives, expected outcomes, and preparing the lab environment.
- Gaining an overview of EDR concepts and the architectural design of the OpenEDR platform.
- Understanding the nuances of endpoint telemetry and various data sources.
Deploying OpenEDR
- Installing OpenEDR agents on both Windows and Linux endpoints.
- Establishing the OpenEDR server infrastructure and configuring dashboards.
- Setting up basic telemetry streams and logging mechanisms.
Foundational Detection & Alerting
- Comprehending different event types and their operational significance.
- Defining detection rules and setting appropriate thresholds.
- Overseeing alerts and managing notifications effectively.
Event Analysis & Investigation
- Scrutinizing events to uncover suspicious patterns.
- Correlating endpoint behaviors with known attack techniques.
- Utilizing OpenEDR dashboards and search utilities for thorough investigations.
Response & Mitigation Strategies
- Taking action on alerts and addressing suspicious activities.
- Isolating compromised endpoints and neutralizing threats.
- Documenting remedial actions and aligning them with incident response protocols.
Integration & Reporting
- Connecting OpenEDR with SIEMs and other security tools.
- Creating comprehensive reports for management and key stakeholders.
- Adopting best practices for continuous monitoring and alert optimization.
Capstone Lab & Practical Exercises
- Engaging in a hands-on lab that simulates real-world endpoint threats.
- Implementing detection, analysis, and response workflows in practice.
- Reviewing lab outcomes and discussing key lessons learned.
Summary & Path Forward
Requirements
- A solid grasp of foundational cybersecurity principles.
- Practical experience in administering Windows and/or Linux systems.
- Familiarity with existing endpoint protection or monitoring solutions.
Target Audience
- IT and security professionals new to endpoint detection tools.
- Cybersecurity engineers seeking to expand their operational toolkit.
- Security staff within small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.