Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Introduction
- Defining course goals, expected results, and setting up the lab environment
- A high-level view of EDR principles and the OpenEDR platform architecture
- Gaining insight into endpoint telemetry and its underlying data sources
Deploying OpenEDR
- Installing OpenEDR agents across Windows and Linux environments
- Establishing the OpenEDR server infrastructure and user dashboards
- Setting up initial telemetry collection and logging mechanisms
Initial Detection & Alert Configuration
- Interpreting various event types and understanding their security relevance
- Establishing detection rules and defining threshold limits
- Overseeing alerts and managing notification channels
Analyzing Events & Conducting Investigations
- Examining events to uncover suspicious patterns of behavior
- Correlating endpoint activities with known attack methodologies
- Leveraging OpenEDR dashboards and search utilities for thorough investigation
Response Strategies & Mitigation
- Taking action on alerts and investigating suspicious activities
- Quarantining compromised endpoints and neutralizing active threats
- Recording response actions and embedding them into the incident response framework
System Integration & Reporting
- Connecting OpenEDR with SIEM platforms or other security stack components
- Creating comprehensive reports for leadership and key stakeholders
- Applying best practices for ongoing monitoring and optimizing alert accuracy
Capstone Lab & Practical Application
- Participating in hands-on labs that replicate real-world endpoint threat scenarios
- Implementing complete detection, analysis, and response procedures
- Reflecting on lab outcomes and discussing key takeaways
Wrap-up & Future Directions
Requirements
- Foundational knowledge of cybersecurity principles
- Practical experience in administering Windows and/or Linux systems
- Familiarity with existing endpoint protection or monitoring solutions
Target Audience
- IT and security specialists beginning their journey with endpoint detection tools
- Cybersecurity engineers
- Security teams in small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.