Course Outline
Introduction & Course Overview
- Course goals, anticipated results, and preparation of the lab environment
- Broad overview of EDR architecture and the constituent parts of OpenEDR
- Recap of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Implementation & Telemetry Gathering
- Setup and configuration of OpenEDR agents on Windows endpoints
- Server components, data ingestion pipelines, and storage requirements
- Setting up telemetry sources, normalising events, and enhancing data
Interpreting Endpoint Telemetry & Event Modelling
- Essential endpoint event types, fields, and their alignment with ATT&CK techniques
- Strategies for event filtering, correlation, and reducing noise
- Generating dependable detection signals from low-fidelity telemetry
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilising ATT&CK Navigator and recording mapping decisions
- Prioritising techniques for hunting based on risk levels and telemetry availability
Threat Hunting Approaches
- Hypothesis-driven hunting compared to indicator-led investigations
- Developing hunt playbooks and iterative discovery processes
- Practical hunting labs: detecting lateral movement, persistence, and privilege escalation trends
Detection Engineering & Optimisation
- Formulating detection rules through event correlation and behavioral baselines
- Testing rules, fine-tuning to minimise false positives, and assessing impact
- Developing signatures and analytic content for reuse across the environment
Incident Response & Root Cause Analysis via OpenEDR
- Employing OpenEDR to triage alerts, probe incidents, and timeline attacks
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols
- Integrating insights into IR playbooks and remediation processes
Automation, Orchestration & Integration
- Automating standard hunts and enriching alerts via scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Scaling telemetry, retention, and operational aspects for enterprise rollouts
Advanced Scenarios & Red Team Collaboration
- Simulating adversary behavior for verification: purple-team exercises and ATT&CK-based emulation
- Case studies: real-world hunts and post-incident reviews
- Establishing continuous improvement cycles for detection coverage
Capstone Project & Presentations
- Guided capstone: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios
- Participant presentations of findings and suggested mitigations
- Course conclusion, distribution of materials, and recommended subsequent steps
Requirements
- A solid grasp of endpoint security principles
- Practical experience in log analysis and fundamental Linux/Windows administration
- Knowledge of prevalent attack methodologies and incident response frameworks
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers overseeing detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.