Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Orientation
- Review of course goals, expected results, and lab environment preparation.
- Overview of EDR concepts and the architectural design of the OpenEDR platform.
- Gaining an understanding of endpoint telemetry and its data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints.
- Establishing the OpenEDR server and setting up dashboards.
- Configuring foundational telemetry and logging mechanisms.
Fundamental Detection and Alerting
- Interpreting event types and assessing their security relevance.
- Setting detection rules and alert thresholds.
- Overseeing alerts and notification channels.
Event Analysis and Investigation
- Scrutinizing events for irregular or suspicious patterns.
- Correlating endpoint behaviors with known attack vectors.
- Leveraging OpenEDR dashboards and search utilities for deep-dive investigations.
Response and Mitigation
- Executing responses to alerts and suspicious activities.
- Isolating affected endpoints and mitigating active threats.
- Documenting response actions and integrating them into the incident response process.
Integration and Reporting
- Connecting OpenEDR with SIEM solutions or other security tools.
- Creating reports for management and key stakeholders.
- Applying best practices for ongoing monitoring and alert optimization.
Capstone Lab and Practical Exercises
- Participating in a hands-on lab that simulates real-world endpoint threats.
- Applying detection, analysis, and response workflows in practice.
- Reviewing lab outcomes and discussing key takeaways.
Summary and Future Steps
Requirements
- A solid grasp of fundamental cybersecurity principles.
- Practical experience in managing Windows and/or Linux systems.
- Familiarity with endpoint protection or monitoring solutions.
Target Audience
- IT and security specialists initiating their work with endpoint detection tools.
- Cybersecurity engineers.
- Security personnel in small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.