Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Course goals, anticipated outcomes, and setting up the lab environment.
- A broad overview of EDR concepts and the OpenEDR platform architecture.
- Grasping the nuances of endpoint telemetry and its various data sources.
OpenEDR Deployment
- Installing OpenEDR agents on Windows and Linux endpoints.
- Setting up the OpenEDR server and customizing dashboards.
- Establishing basic telemetry and logging configurations.
Basic Detection and Alerting
- Interpreting different event types and their operational significance.
- Configuring detection rules and defining alert thresholds.
- Monitoring alerts and managing notifications.
Event Analysis & Investigation
- Scrutinizing events to uncover suspicious patterns.
- Correlating endpoint behaviors with known attack techniques.
- Utilizing OpenEDR dashboards and search utilities for deep-dive investigations.
Response & Mitigation
- Taking action on alerts and suspicious activities.
- Isolating compromised endpoints and mitigating active threats.
- Recording actions taken and integrating findings into incident response protocols.
Integration & Reporting
- Connecting OpenEDR with SIEM platforms and other security tools.
- Creating reports suitable for management and key stakeholders.
- Implementing best practices for ongoing monitoring and alert tuning.
Capstone Lab & Practical Exercises
- Simulating real-world endpoint threats in a hands-on lab environment.
- Executing detection, analysis, and response workflows.
- Reviewing lab outcomes and discussing key lessons learned.
Summary and Next Steps
Requirements
- Foundational knowledge of core cybersecurity principles.
- Prior experience managing Windows and/or Linux systems.
- Familiarity with endpoint protection or monitoring solutions.
Target Audience
- IT and security professionals new to endpoint detection tools.
- Cybersecurity engineers.
- Security teams in small to mid-sized enterprises.
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.