Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Review of course objectives, expected outcomes, and the lab environment setup
- An overview of EDR concepts and the architectural design of the OpenEDR platform
- Comprehending endpoint telemetry and associated data sources
Deploying OpenEDR
- Installation of OpenEDR agents across Windows and Linux endpoints
- Configuration of initial telemetry settings and logging mechanisms
Fundamental Detection and Alerting
- Understanding the nature of event types and their operational significance
- Setting detection rules and establishing appropriate thresholds
- Monitoring the flow of alerts and notifications
Event Analysis & Investigation
- Scrutinizing events for indicative patterns of suspicion
- Correlating endpoint behaviors with prevalent attack techniques
- Utilizing OpenEDR dashboards and search utilities for thorough investigation
Response & Mitigation
- Addressing alerts and managing suspicious activity effectively
- Isolating compromised endpoints and mitigating associated threats
- Documenting actions taken and integrating them into incident response protocols
Integration & Reporting
- Connecting OpenEDR with SIEM systems and other security tools
- Producing reports tailored for management and key stakeholders
- Applying best practices for sustained monitoring and alert optimization
Capstone Lab & Practical Exercises
- Engaging in a hands-on lab that simulates real-world endpoint threats
- Implementing detection, analysis, and response workflows in a practical setting
- Critical review and discussion of lab outcomes and key takeaways
Summary and Future Directions
Requirements
- A foundational understanding of core cybersecurity concepts
- Practical experience in Windows and/or Linux system administration
- Familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security professionals commencing their journey with endpoint detection tools
- Cybersecurity engineers
- Security staff within small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.