Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Overview
- Defining course goals, expected results, and setting up the laboratory environment
- Broad look at EDR principles and the architecture of the OpenEDR platform
- Grasp of endpoint telemetry and associated data sources
Implementing OpenEDR
- Installation of OpenEDR agents across Windows and Linux endpoints
- Configuration of the OpenEDR server and interface dashboards
- Setup of foundational telemetry and logging mechanisms
Core Detection and Alerting Mechanisms
- Understanding various event types and their security relevance
- Setting detection rules and sensitivity thresholds
- Oversight of alerts and notification systems
Event Evaluation & Investigative Procedures
- Examination of events to uncover suspicious patterns
- Correlating endpoint behaviors with standard attack methodologies
- Leveraging OpenEDR dashboards and search capabilities for deep-dive investigations
Response Strategies & Threat Containment
- Actioning alerts and investigating suspicious activities
- Quarantining endpoints and mitigating active threats
- Recording actions taken and embedding them into incident response protocols
System Integration & Reporting
- Connecting OpenEDR with SIEM platforms or other security utilities
- Creating reports for executive management and key stakeholders
- Best practices for sustained monitoring and alert refinement
Capstone Laboratory & Applied Exercises
- Practical lab session simulating real-world endpoint security threats
- Application of detection, analysis, and response procedures
- Evaluation and discussion of laboratory outcomes and key takeaways
Recap and Future Learning Paths
Requirements
- A solid grasp of fundamental cybersecurity principles
- Practical experience in Windows and/or Linux system administration
- Proficiency with endpoint protection or monitoring solutions
Intended Audience
- IT and security professionals initiating their use of endpoint detection tools
- Cybersecurity engineers
- Security personnel within small to mid-sized organizations
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.