Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction and Course Orientation
- Course objectives, expected outcomes, and setup of the lab environment.
- Overview of EDR concepts and the OpenEDR platform architecture.
- Comprehending endpoint telemetry and various data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints.
- Configuring the OpenEDR server and associated dashboards.
- Setting up basic telemetry and logging mechanisms.
Basic Detection and Alerting
- Understanding event types and their security significance.
- Configuring detection rules and alert thresholds.
- Monitoring alerts and system notifications.
Event Analysis and Investigation
- Analyzing events to identify suspicious patterns.
- Correlating endpoint behaviors with common attack techniques.
- Utilizing OpenEDR dashboards and search tools for thorough investigations.
Response and Mitigation
- Responding to alerts and observed suspicious activity.
- Isolating compromised endpoints and mitigating threats.
- Documenting actions and integrating findings into incident response processes.
Integration and Reporting
- Integrating OpenEDR with SIEMs or other security tools.
- Generating reports for management and key stakeholders.
- Best practices for continuous monitoring and alert tuning.
Capstone Lab and Practical Exercises
- Hands-on laboratory exercises simulating real-world endpoint threats.
- Applying detection, analysis, and response workflows in practice.
- Reviewing and discussing lab results and key lessons learned.
Summary and Next Steps
Requirements
- A foundational understanding of core cybersecurity concepts.
- Practical experience in Windows and/or Linux system administration.
- Familiarity with endpoint protection or monitoring tools.
Audience
- IT and security professionals beginning their journey with endpoint detection tools.
- Cybersecurity engineers.
- Security staff from small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.