Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Overview

  • Defining course goals, expected results, and setting up the laboratory environment
  • Broad look at EDR principles and the architecture of the OpenEDR platform
  • Grasp of endpoint telemetry and associated data sources

Implementing OpenEDR

  • Installation of OpenEDR agents across Windows and Linux endpoints
  • Configuration of the OpenEDR server and interface dashboards
  • Setup of foundational telemetry and logging mechanisms

Core Detection and Alerting Mechanisms

  • Understanding various event types and their security relevance
  • Setting detection rules and sensitivity thresholds
  • Oversight of alerts and notification systems

Event Evaluation & Investigative Procedures

  • Examination of events to uncover suspicious patterns
  • Correlating endpoint behaviors with standard attack methodologies
  • Leveraging OpenEDR dashboards and search capabilities for deep-dive investigations

Response Strategies & Threat Containment

  • Actioning alerts and investigating suspicious activities
  • Quarantining endpoints and mitigating active threats
  • Recording actions taken and embedding them into incident response protocols

System Integration & Reporting

  • Connecting OpenEDR with SIEM platforms or other security utilities
  • Creating reports for executive management and key stakeholders
  • Best practices for sustained monitoring and alert refinement

Capstone Laboratory & Applied Exercises

  • Practical lab session simulating real-world endpoint security threats
  • Application of detection, analysis, and response procedures
  • Evaluation and discussion of laboratory outcomes and key takeaways

Recap and Future Learning Paths

Requirements

  • A solid grasp of fundamental cybersecurity principles
  • Practical experience in Windows and/or Linux system administration
  • Proficiency with endpoint protection or monitoring solutions

Intended Audience

  • IT and security professionals initiating their use of endpoint detection tools
  • Cybersecurity engineers
  • Security personnel within small to mid-sized organizations

Testimonials (2)

Related Categories