Get in Touch
 Duration 21 hours

Course Outline

Course Introduction & Orientation

  • Defining course goals, expected outcomes, and preparing the lab environment
  • Overview of EDR architecture and core OpenEDR components
  • Recap of the MITRE ATT&CK framework and foundational threat-hunting principles

Implementing OpenEDR & Gathering Telemetry

  • Setting up and configuring OpenEDR agents on Windows systems
  • Managing server components, data ingestion pipelines, and storage requirements
  • Establishing telemetry sources, normalizing events, and enriching data

Analyzing Endpoint Telemetry & Event Modeling

  • Identifying key endpoint event types and fields, and mapping them to ATT&CK techniques
  • Applying event filtering, correlation strategies, and methods to reduce noise
  • Deriving reliable detection signals from less reliable telemetry sources

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator and documenting mapping choices
  • Prioritizing techniques for hunting based on risk levels and data availability

Approaches to Threat Hunting

  • Comparing hypothesis-driven hunting with indicator-led investigations
  • Developing hunt playbooks and iterative discovery processes
  • Practical labs: detecting lateral movement, persistence, and privilege escalation patterns

Developing & Tuning Detections

  • Crafting detection rules using event correlation and behavioral baselines
  • Testing and refining rules to minimize false positives and assess effectiveness
  • Creating signatures and analytic content that can be reused across the environment

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and timeline attacks
  • Collecting forensic artifacts, preserving evidence, and maintaining chain of custody
  • Integrating results into IR playbooks and remediation procedures

Automation, Orchestration & Integration

  • Automating standard hunts and alert enrichment through scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Addressing telemetry scaling, retention, and operational needs for enterprise settings

Advanced Scenarios & Red Team Interaction

  • Validating defenses by simulating adversary actions: purple-team exercises and ATT&CK-based emulation
  • Reviewing case studies: real-world hunts and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Final Capstone Lab & Presentations

  • Supervised capstone: executing a full hunt from hypothesis to containment and root cause analysis in lab scenarios
  • Presenting findings and suggesting mitigations
  • Course conclusion, distribution of materials, and suggested next steps

Requirements

  • A solid grasp of endpoint security basics
  • Hands-on experience with log analysis and fundamental Linux/Windows administration
  • Knowledge of standard attack methods and incident response principles

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories