Course Outline
Introduction and Course Overview
- Defining course goals, expected results, and setting up the lab environment.
- An overview of high-level EDR architecture and the core components of OpenEDR.
- A refresher on the MITRE ATT&CK framework and the basics of threat hunting.
OpenEDR Deployment and Telemetry Gathering
- Installing and setting up OpenEDR agents on Windows-based endpoints.
- Managing server components, data ingestion pipelines, and storage requirements.
- Setting up telemetry sources, normalizing events, and enriching data.
Interpreting Endpoint Telemetry and Event Modeling
- Exploring key endpoint event types and fields, and their relevance to ATT&CK techniques.
- Strategies for event filtering, correlation, and minimizing noise.
- Generating reliable detection signals from low-fidelity telemetry data.
Aligning Detections with MITRE ATT&CK
- Converting telemetry into ATT&CK technique coverage and identifying detection gaps.
- Utilizing the ATT&CK Navigator and recording mapping decisions for clarity.
- Prioritizing specific techniques for hunting based on risk levels and data availability.
Threat Hunting Strategies and Methods
- Comparing hypothesis-driven hunting with indicator-led investigation approaches.
- Developing hunt playbooks and implementing iterative discovery processes.
- Practical hunting labs focused on detecting lateral movement, persistence, and privilege escalation.
Detection Engineering and Optimization
- Formulating detection rules through event correlation and behavioral baselining.
- Testing rules, adjusting for false positives, and evaluating effectiveness.
- Developing signatures and analytic content for consistent use across the environment.
Incident Response and Root Cause Analysis via OpenEDR
- Leveraging OpenEDR for alert triage, incident investigation, and attack timeline reconstruction.
- Collecting forensic artifacts, preserving evidence, and adhering to chain-of-custody protocols.
- Integrating insights into incident response playbooks and remediation procedures.
Automation, Orchestration, and System Integration
- Automating routine hunting tasks and alert enrichment through scripts and connectors.
- Connecting OpenEDR with SIEM, SOAR, and threat intelligence platforms.
- Addressing telemetry scaling, retention policies, and operational needs for enterprise setups.
Advanced Scenarios and Red Team Collaboration
- Simulating adversary actions for validation through purple-team exercises and ATT&CK-based emulation.
- Examining case studies involving real-world hunts and post-incident reviews.
- Establishing continuous improvement loops to enhance detection coverage.
Capstone Project and Presentations
- A guided capstone exercise involving a complete hunt cycle, from hypothesis to containment and root cause analysis, using lab scenarios.
- Participants presenting their findings and suggested mitigation strategies.
- Course conclusion, distribution of materials, and advice on next steps.
Requirements
- A solid grasp of fundamental endpoint security concepts.
- Practical experience in log analysis and basic administration of Linux and Windows systems.
- Knowledge of prevalent attack techniques and core incident response principles.
Intended Audience
- Security Operations Center (SOC) analysts.
- Threat hunters and incident response specialists.
- Security engineers tasked with detection engineering and telemetry management.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.