Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Course goals, anticipated outcomes, and lab environment preparation
  • Overview of EDR concepts and the OpenEDR platform architecture
  • Understanding endpoint telemetry and associated data sources

Deploying OpenEDR

  • Installation of OpenEDR agents on Windows and Linux endpoints
  • Setup of the OpenEDR server and user dashboards
  • Configuration of basic telemetry and logging mechanisms

Fundamental Detection and Alerting

  • Interpreting event types and their relevance to security
  • Setting detection rules and thresholds
  • Monitoring alerts and system notifications

Event Analysis & Investigation

  • Identifying suspicious patterns within event data
  • Correlating endpoint behaviors with common attack techniques
  • Utilizing OpenEDR dashboards and search utilities for deep-dive investigations

Response & Mitigation

  • Addressing alerts and suspicious activities promptly
  • Isolating affected endpoints and neutralizing threats
  • Documenting response actions and aligning them with incident response protocols

Integration & Reporting

  • Connecting OpenEDR with SIEM or other security platforms
  • Creating reports for management and key stakeholders
  • Adopting best practices for ongoing monitoring and alert optimization

Capstone Lab & Practical Exercises

  • Hands-on simulation of real-world endpoint threats
  • Application of detection, analysis, and response workflows
  • Debrief on lab results and key takeaways

Summary and Next Steps

Requirements

  • Foundational knowledge of cybersecurity concepts
  • Practical experience in Windows and/or Linux administration
  • Prior exposure to endpoint protection or monitoring utilities

Target Audience

  • IT and security professionals new to endpoint detection tools
  • Cybersecurity engineers
  • Security personnel in small to mid-sized enterprises

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories