Course Outline
Introduction & Course Orientation
- Overview of course goals, expected outcomes, and lab environment preparation.
- High-level view of EDR architecture and key OpenEDR components.
- Recap of the MITRE ATT&CK framework and core threat-hunting principles.
Deploying OpenEDR & Collecting Telemetry
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Managing server components, data ingestion pipelines, and storage requirements.
- Setting up telemetry sources, event normalization, and data enrichment.
Interpreting Endpoint Telemetry & Event Modeling
- Analysis of key endpoint event types and their mapping to ATT&CK techniques.
- Strategies for event filtering, correlation, and noise reduction.
- Deriving reliable detection signals from low-fidelity telemetry data.
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing ATT&CK Navigator and documenting mapping decisions.
- Prioritizing techniques for hunting based on risk profiles and telemetry availability.
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations.
- Developing hunt playbooks and iterative discovery workflows.
- Hands-on labs: detecting lateral movement, persistence, and privilege escalation patterns.
Detection Engineering & Optimization
- Crafting detection rules using event correlation and behavioral baselines.
- Testing rules, tuning to minimize false positives, and assessing effectiveness.
- Developing reusable signatures and analytic content across the environment.
Incident Response & Root Cause Analysis using OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline construction.
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
- Integrating insights into IR playbooks and remediation processes.
Automation, Orchestration & Integrations
- Automating routine hunts and alert enrichment through scripts and connectors.
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing scaling, retention, and operational needs for enterprise deployments.
Advanced Scenarios & Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
- Reviewing case studies involving real-world hunts and post-incident reviews.
- Establishing continuous improvement cycles for detection coverage.
Capstone Lab & Presentations
- Guided capstone project: executing a full hunt from hypothesis to containment and root cause analysis.
- Participant presentations showcasing findings and recommended mitigations.
- Course conclusion, distribution of materials, and suggestions for further learning.
Requirements
- Solid understanding of endpoint security fundamentals.
- Practical experience with log analysis and basic Linux/Windows administration.
- Knowledge of common attack vectors and incident response concepts.
Target Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident response specialists.
- Security engineers overseeing detection engineering and telemetry.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.