Course Outline
Course Introduction & Orientation
- Defining course goals, expected outcomes, and preparing the lab environment
- Overview of EDR architecture and core OpenEDR components
- Recap of the MITRE ATT&CK framework and foundational threat-hunting principles
Implementing OpenEDR & Gathering Telemetry
- Setting up and configuring OpenEDR agents on Windows systems
- Managing server components, data ingestion pipelines, and storage requirements
- Establishing telemetry sources, normalizing events, and enriching data
Analyzing Endpoint Telemetry & Event Modeling
- Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques
- Applying event filtering, correlation strategies, and methods to reduce noise
- Deriving reliable detection signals from less reliable telemetry sources
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator and documenting mapping choices
- Prioritizing techniques for hunting based on risk levels and data availability
Approaches to Threat Hunting
- Comparing hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and iterative discovery processes
- Practical labs: detecting lateral movement, persistence, and privilege escalation patterns
Developing & Tuning Detections
- Crafting detection rules using event correlation and behavioral baselines
- Testing and refining rules to minimize false positives and assess effectiveness
- Creating signatures and analytic content that can be reused across the environment
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attacks
- Collecting forensic artifacts, preserving evidence, and maintaining chain of custody
- Integrating results into IR playbooks and remediation procedures
Automation, Orchestration & Integration
- Automating standard hunts and alert enrichment through scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Addressing telemetry scaling, retention, and operational needs for enterprise settings
Advanced Scenarios & Red Team Interaction
- Validating defenses by simulating adversary actions: purple-team exercises and ATT&CK-based emulation
- Reviewing case studies: real-world hunts and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Final Capstone Lab & Presentations
- Supervised capstone: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
- Presenting findings and suggesting mitigations
- Course conclusion, distribution of materials, and suggested next steps
Requirements
- A solid grasp of endpoint security basics
- Hands-on experience with log analysis and fundamental Linux/Windows administration
- Knowledge of standard attack methods and incident response principles
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.