Get in Touch
 Duration 21 hours

Course Outline

Introduction and Course Overview

  • Defining course goals, expected results, and setting up the lab environment.
  • An overview of high-level EDR architecture and the core components of OpenEDR.
  • A refresher on the MITRE ATT&CK framework and the basics of threat hunting.

OpenEDR Deployment and Telemetry Gathering

  • Installing and setting up OpenEDR agents on Windows-based endpoints.
  • Managing server components, data ingestion pipelines, and storage requirements.
  • Setting up telemetry sources, normalizing events, and enriching data.

Interpreting Endpoint Telemetry and Event Modeling

  • Exploring key endpoint event types and fields, and their relevance to ATT&CK techniques.
  • Strategies for event filtering, correlation, and minimizing noise.
  • Generating reliable detection signals from low-fidelity telemetry data.

Aligning Detections with MITRE ATT&CK

  • Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
  • Utilizing the ATT&CK Navigator and recording mapping decisions for clarity.
  • Prioritizing specific techniques for hunting based on risk levels and data availability.

Threat Hunting Strategies and Methods

  • Comparing hypothesis-driven hunting with indicator-led investigation approaches.
  • Developing hunt playbooks and implementing iterative discovery processes.
  • Practical hunting labs focused on detecting lateral movement, persistence, and privilege escalation.

Detection Engineering and Optimization

  • Formulating detection rules through event correlation and behavioral baselining.
  • Testing rules, adjusting for false positives, and evaluating effectiveness.
  • Developing signatures and analytic content for consistent use across the environment.

Incident Response and Root Cause Analysis via OpenEDR

  • Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
  • Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
  • Integrating insights into incident response playbooks and remediation procedures.

Automation, Orchestration, and System Integration

  • Automating routine hunting tasks and alert enrichment through scripts and connectors.
  • Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
  • Addressing telemetry scaling, retention policies, and operational needs for enterprise setups.

Advanced Scenarios and Red Team Collaboration

  • Simulating adversary actions for validation through purple-team exercises and ATT&CK-based emulation.
  • Examining case studies involving real-world hunts and post-incident reviews.
  • Establishing continuous improvement loops to enhance detection coverage.

Capstone Project and Presentations

  • A guided capstone exercise involving a complete hunt cycle, from hypothesis to containment and root cause analysis, using lab scenarios.
  • Participants presenting their findings and suggested mitigation strategies.
  • Course conclusion, distribution of materials, and advice on next steps.

Requirements

  • A solid grasp of fundamental endpoint security concepts.
  • Practical experience in log analysis and basic administration of Linux and Windows systems.
  • Knowledge of prevalent attack techniques and core incident response principles.

Intended Audience

  • Security Operations Center (SOC) analysts.
  • Threat hunters and incident response specialists.
  • Security engineers tasked with detection engineering and telemetry management.

Testimonials (2)

Related Categories