Get in Touch
 Duration 21 hours

Course Outline

Introduction & Course Overview

  • Defining course objectives, anticipated outcomes, and preparing the lab environment
  • High-level EDR architecture and an introduction to OpenEDR components
  • Overview of the MITRE ATT&CK framework and core threat-hunting principles

OpenEDR Deployment & Telemetry Acquisition

  • Installing and configuring OpenEDR agents on Windows endpoints
  • Configuring server components, data ingestion pipelines, and storage requirements
  • Setting up telemetry sources, event normalization, and data enrichment

Analyzing Endpoint Telemetry & Event Modeling

  • Examining key endpoint event types and fields, and mapping them to ATT&CK techniques
  • Strategies for event filtering, correlation, and minimizing noise
  • Generating reliable detection signals from low-fidelity telemetry data

Aligning Detections with MITRE ATT&CK

  • Translating telemetry into ATT&CK technique coverage and identifying detection gaps
  • Utilizing ATT&CK Navigator to document mapping decisions effectively
  • Prioritizing techniques for hunting based on risk assessment and data availability

Threat Hunting Methodologies

  • Comparing hypothesis-driven hunting with indicator-led investigations
  • Developing hunt playbooks and establishing iterative discovery processes
  • Practical hunting labs focused on identifying lateral movement, persistence, and privilege escalation

Detection Engineering & Optimization

  • Designing detection rules through event correlation and behavioral baselining
  • Testing and tuning rules to minimize false positives and evaluate effectiveness
  • Creating reusable signatures and analytic content across the environment

Incident Response & Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody standards
  • Integrating investigation findings into IR playbooks and remediation procedures

Automation, Orchestration & System Integration

  • Automating routine hunts and alert enrichment using scripts and connectors
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
  • Addressing enterprise-scale telemetry, retention, and operational needs

Advanced Use Cases & Red Team Collaboration

  • Validating defenses through purple-team exercises and ATT&CK-based adversary emulation
  • Reviewing case studies of real-world hunts and post-incident analyses
  • Establishing continuous improvement cycles for detection coverage

Capstone Lab & Presentations

  • Guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios
  • Participant presentations highlighting findings and recommended mitigations
  • Course conclusion, resource distribution, and guidance on next steps

Requirements

  • A solid grasp of endpoint security fundamentals
  • Practical experience with log analysis and basic Linux/Windows administration
  • Familiarity with prevalent attack techniques and incident response principles

Target Audience

  • Security operations center (SOC) analysts
  • Threat hunters and incident response specialists
  • Security engineers focused on detection engineering and telemetry management

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories