Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Overview

  • Course goals, anticipated results, and preparation of the lab environment
  • Broad overview of EDR architecture and the constituent parts of OpenEDR
  • Recap of the MITRE ATT&CK framework and core threat-hunting principles

OpenEDR Implementation & Telemetry Gathering

  • Setup and configuration of OpenEDR agents on Windows endpoints
  • Server components, data ingestion pipelines, and storage requirements
  • Setting up telemetry sources, normalising events, and enhancing data

Interpreting Endpoint Telemetry & Event Modelling

  • Essential endpoint event types, fields, and their alignment with ATT&CK techniques
  • Strategies for event filtering, correlation, and reducing noise
  • Generating dependable detection signals from low-fidelity telemetry

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilising ATT&CK Navigator and recording mapping decisions
  • Prioritising techniques for hunting based on risk levels and telemetry availability

Threat Hunting Approaches

  • Hypothesis-driven hunting compared to indicator-led investigations
  • Developing hunt playbooks and iterative discovery processes
  • Practical hunting labs: detecting lateral movement, persistence, and privilege escalation trends

Detection Engineering & Optimisation

  • Formulating detection rules through event correlation and behavioral baselines
  • Testing rules, fine-tuning to minimise false positives, and assessing impact
  • Developing signatures and analytic content for reuse across the environment

Incident Response & Root Cause Analysis via OpenEDR

  • Employing OpenEDR to triage alerts, probe incidents, and timeline attacks
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
  • Integrating insights into IR playbooks and remediation processes

Automation, Orchestration & Integration

  • Automating standard hunts and enriching alerts via scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Scaling telemetry, retention, and operational aspects for enterprise rollouts

Advanced Scenarios & Red Team Collaboration

  • Simulating adversary behavior for verification: purple-team exercises and ATT&CK-based emulation
  • Case studies: real-world hunts and post-incident reviews
  • Establishing continuous improvement cycles for detection coverage

Capstone Project & Presentations

  • Guided capstone: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios
  • Participant presentations of findings and suggested mitigations
  • Course conclusion, distribution of materials, and recommended subsequent steps

Requirements

  • A solid grasp of endpoint security principles
  • Practical experience in log analysis and fundamental Linux/Windows administration
  • Knowledge of prevalent attack methodologies and incident response frameworks

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers overseeing detection engineering and telemetry management

Testimonials (2)

Related Categories