Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Orientation

  • Overview of course goals, expected outcomes, and lab environment preparation.
  • High-level view of EDR architecture and key OpenEDR components.
  • Recap of the MITRE ATT&CK framework and core threat-hunting principles.

Deploying OpenEDR & Collecting Telemetry

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Managing server components, data ingestion pipelines, and storage requirements.
  • Setting up telemetry sources, event normalization, and data enrichment.

Interpreting Endpoint Telemetry & Event Modeling

  • Analysis of key endpoint event types and their mapping to ATT&CK techniques.
  • Strategies for event filtering, correlation, and noise reduction.
  • Deriving reliable detection signals from low-fidelity telemetry data.

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing ATT&CK Navigator and documenting mapping decisions.
  • Prioritizing techniques for hunting based on risk profiles and telemetry availability.

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations.
  • Developing hunt playbooks and iterative discovery workflows.
  • Hands-on labs: detecting lateral movement, persistence, and privilege escalation patterns.

Detection Engineering & Optimization

  • Crafting detection rules using event correlation and behavioral baselines.
  • Testing rules, tuning to minimize false positives, and assessing effectiveness.
  • Developing reusable signatures and analytic content across the environment.

Incident Response & Root Cause Analysis using OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline construction.
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
  • Integrating insights into IR playbooks and remediation processes.

Automation, Orchestration & Integrations

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing scaling, retention, and operational needs for enterprise deployments.

Advanced Scenarios & Red Team Collaboration

  • Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
  • Reviewing case studies involving real-world hunts and post-incident reviews.
  • Establishing continuous improvement cycles for detection coverage.

Capstone Lab & Presentations

  • Guided capstone project: executing a full hunt from hypothesis to containment and root cause analysis.
  • Participant presentations showcasing findings and recommended mitigations.
  • Course conclusion, distribution of materials, and suggestions for further learning.

Requirements

  • Solid understanding of endpoint security fundamentals.
  • Practical experience with log analysis and basic Linux/Windows administration.
  • Knowledge of common attack vectors and incident response concepts.

Target Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident response specialists.
  • Security engineers overseeing detection engineering and telemetry.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories