Get in Touch
 Duration 14 hours

Course Outline

Introduction and Course Orientation

  • Course objectives, expected outcomes, and setup of the lab environment.
  • Overview of EDR concepts and the OpenEDR platform architecture.
  • Comprehending endpoint telemetry and various data sources.

OpenEDR Deployment

  • Installing OpenEDR agents on Windows and Linux endpoints.
  • Configuring the OpenEDR server and associated dashboards.
  • Setting up basic telemetry and logging mechanisms.

Basic Detection and Alerting

  • Understanding event types and their security significance.
  • Configuring detection rules and alert thresholds.
  • Monitoring alerts and system notifications.

Event Analysis and Investigation

  • Analyzing events to identify suspicious patterns.
  • Correlating endpoint behaviors with common attack techniques.
  • Utilizing OpenEDR dashboards and search tools for thorough investigations.

Response and Mitigation

  • Responding to alerts and observed suspicious activity.
  • Isolating compromised endpoints and mitigating threats.
  • Documenting actions and integrating findings into incident response processes.

Integration and Reporting

  • Integrating OpenEDR with SIEMs or other security tools.
  • Generating reports for management and key stakeholders.
  • Best practices for continuous monitoring and alert tuning.

Capstone Lab and Practical Exercises

  • Hands-on laboratory exercises simulating real-world endpoint threats.
  • Applying detection, analysis, and response workflows in practice.
  • Reviewing and discussing lab results and key lessons learned.

Summary and Next Steps

Requirements

  • A foundational understanding of core cybersecurity concepts.
  • Practical experience in Windows and/or Linux system administration.
  • Familiarity with endpoint protection or monitoring tools.

Audience

  • IT and security professionals beginning their journey with endpoint detection tools.
  • Cybersecurity engineers.
  • Security staff from small to mid-sized enterprises.

Testimonials (2)

Related Categories