Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Overview

  • Course goals, learning outcomes, and preparation of the lab environment.
  • Overview of EDR architecture and key OpenEDR components.
  • Recap of the MITRE ATT&CK framework and core threat-hunting concepts.

Deploying OpenEDR and Collecting Telemetry

  • Installation and configuration of OpenEDR agents on Windows endpoints.
  • Management of server components, data ingestion pipelines, and storage strategies.
  • Setup of telemetry sources, event normalization, and data enrichment processes.

Analyzing Endpoint Telemetry and Event Modeling

  • Examination of critical endpoint event types and fields, and their alignment with ATT&CK techniques.
  • Strategies for event filtering, correlation, and minimizing noise.
  • Deriving reliable detection signals from low-fidelity telemetry data.

Aligning Detections with MITRE ATT&CK

  • Converting telemetry data into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing the ATT&CK Navigator and documenting mapping decisions.
  • Prioritizing techniques for hunting based on risk assessment and telemetry availability.

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting versus indicator-led investigations.
  • Development of hunt playbooks and iterative discovery processes.
  • Practical hunting labs focusing on lateral movement, persistence, and privilege escalation patterns.

Detection Engineering and Optimization

  • Crafting detection rules utilizing event correlation and behavioral baselines.
  • Testing and tuning rules to minimize false positives and assess effectiveness.
  • Developing reusable signatures and analytic content for the broader environment.

Incident Response and Root Cause Analysis using OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline construction.
  • Collection of forensic artifacts, evidence preservation, and chain-of-custody management.
  • Integrating investigative findings into incident response playbooks and remediation procedures.

Automation, Orchestration, and Integration

  • Automating routine hunts and alert enrichment through scripts and connectors.
  • Integrating OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Scaling telemetry, managing retention, and addressing operational needs for enterprise deployments.

Advanced Scenarios and Red Team Collaboration

  • Simulating adversary behavior for validation through purple-team exercises and ATT&CK-based emulation.
  • Review of case studies involving real-world hunts and post-incident analyses.
  • Establishing continuous improvement cycles for detection coverage.

Capstone Lab and Presentations

  • Guided capstone exercise: executing a full hunt from hypothesis through containment and root cause analysis using lab scenarios.
  • Participant presentations detailing findings and recommended mitigations.
  • Course conclusion, distribution of materials, and suggestions for next steps.

Requirements

  • Foundational knowledge of endpoint security principles.
  • Practical experience in log analysis and basic administration of Linux and Windows systems.
  • Familiarity with standard attack vectors and incident response methodologies.

Intended Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident responders.
  • Security engineers focused on detection engineering and telemetry management.

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories