Course Outline
Introduction and Course Overview
- Course goals, learning outcomes, and preparation of the lab environment.
- Overview of EDR architecture and key OpenEDR components.
- Recap of the MITRE ATT&CK framework and core threat-hunting concepts.
Deploying OpenEDR and Collecting Telemetry
- Installation and configuration of OpenEDR agents on Windows endpoints.
- Management of server components, data ingestion pipelines, and storage strategies.
- Setup of telemetry sources, event normalization, and data enrichment processes.
Analyzing Endpoint Telemetry and Event Modeling
- Examination of critical endpoint event types and fields, and their alignment with ATT&CK techniques.
- Strategies for event filtering, correlation, and minimizing noise.
- Deriving reliable detection signals from low-fidelity telemetry data.
Aligning Detections with MITRE ATT&CK
- Converting telemetry data into ATT&CK technique coverage and identifying detection gaps.
- Utilizing the ATT&CK Navigator and documenting mapping decisions.
- Prioritizing techniques for hunting based on risk assessment and telemetry availability.
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting versus indicator-led investigations.
- Development of hunt playbooks and iterative discovery processes.
- Practical hunting labs focusing on lateral movement, persistence, and privilege escalation patterns.
Detection Engineering and Optimization
- Crafting detection rules utilizing event correlation and behavioral baselines.
- Testing and tuning rules to minimize false positives and assess effectiveness.
- Developing reusable signatures and analytic content for the broader environment.
Incident Response and Root Cause Analysis using OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline construction.
- Collection of forensic artifacts, evidence preservation, and chain-of-custody management.
- Integrating investigative findings into incident response playbooks and remediation procedures.
Automation, Orchestration, and Integration
- Automating routine hunts and alert enrichment through scripts and connectors.
- Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Scaling telemetry, managing retention, and addressing operational needs for enterprise deployments.
Advanced Scenarios and Red Team Collaboration
- Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
- Review of case studies involving real-world hunts and post-incident analyses.
- Establishing continuous improvement cycles for detection coverage.
Capstone Lab and Presentations
- Guided capstone exercise: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
- Participant presentations detailing findings and recommended mitigations.
- Course conclusion, distribution of materials, and suggestions for next steps.
Requirements
- Foundational knowledge of endpoint security principles.
- Practical experience in log analysis and basic administration of Linux and Windows systems.
- Familiarity with standard attack vectors and incident response methodologies.
Intended Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident responders.
- Security engineers focused on detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.