Course Outline
Introduction & Course Overview
- Defining course objectives, anticipated outcomes, and preparing the lab environment
- High-level EDR architecture and an introduction to OpenEDR components
- Overview of the MITRE ATT&CK framework and core threat-hunting principles
OpenEDR Deployment & Telemetry Acquisition
- Installing and configuring OpenEDR agents on Windows endpoints
- Configuring server components, data ingestion pipelines, and storage requirements
- Setting up telemetry sources, event normalization, and data enrichment
Analyzing Endpoint Telemetry & Event Modeling
- Examining key endpoint event types and fields, and mapping them to ATT&CK techniques
- Strategies for event filtering, correlation, and minimizing noise
- Generating reliable detection signals from low-fidelity telemetry data
Aligning Detections with MITRE ATT&CK
- Translating telemetry into ATT&CK technique coverage and identifying detection gaps
- Utilizing ATT&CK Navigator to document mapping decisions effectively
- Prioritizing techniques for hunting based on risk assessment and data availability
Threat Hunting Methodologies
- Comparing hypothesis-driven hunting with indicator-led investigations
- Developing hunt playbooks and establishing iterative discovery processes
- Practical hunting labs focused on identifying lateral movement, persistence, and privilege escalation
Detection Engineering & Optimization
- Designing detection rules through event correlation and behavioral baselining
- Testing and tuning rules to minimize false positives and evaluate effectiveness
- Creating reusable signatures and analytic content across the environment
Incident Response & Root Cause Analysis via OpenEDR
- Leveraging OpenEDR to triage alerts, investigate incidents, and reconstruct attack timelines
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody standards
- Integrating investigation findings into IR playbooks and remediation procedures
Automation, Orchestration & System Integration
- Automating routine hunts and alert enrichment using scripts and connectors
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms
- Addressing enterprise-scale telemetry, retention, and operational needs
Advanced Use Cases & Red Team Collaboration
- Validating defenses through purple-team exercises and ATT&CK-based adversary emulation
- Reviewing case studies of real-world hunts and post-incident analyses
- Establishing continuous improvement cycles for detection coverage
Capstone Lab & Presentations
- Guided capstone exercise: executing a full hunt from hypothesis to containment and root cause analysis using lab scenarios
- Participant presentations highlighting findings and recommended mitigations
- Course conclusion, resource distribution, and guidance on next steps
Requirements
- A solid grasp of endpoint security fundamentals
- Practical experience with log analysis and basic Linux/Windows administration
- Familiarity with prevalent attack techniques and incident response principles
Target Audience
- Security operations center (SOC) analysts
- Threat hunters and incident response specialists
- Security engineers focused on detection engineering and telemetry management
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.