Get in Touch

Course Outline

Introduction and Course Orientation

  • Course objectives, expected learning outcomes, and configuration of the lab environment for government use
  • Overview of Endpoint Detection and Response (EDR) principles and OpenEDR platform architecture
  • Examination of endpoint telemetry sources and data collection mechanisms

OpenEDR Deployment

  • Deployment of OpenEDR agents on Windows and Linux endpoints within federal infrastructure
  • Establishment of the OpenEDR server instance and configuration of administrative dashboards
  • Configuration of baseline telemetry collection and logging protocols

Basic Detection and Alerting

  • Analysis of event types and their operational significance in cybersecurity governance
  • Development and configuration of detection rules and alert thresholds
  • Monitoring and management of security alerts and notification workflows

Event Analysis and Investigation

  • Assessment of event data to identify anomalous or suspicious patterns
  • Correlation of endpoint behaviors with known adversarial tactics and techniques
  • Utilization of OpenEDR dashboards and search capabilities for forensic investigation

Response and Mitigation

  • Execution of response procedures for confirmed alerts and suspicious activity
  • Implementation of endpoint isolation measures and threat mitigation strategies
  • Documentation of remediation actions and integration with established incident response frameworks

Integration and Reporting

  • Integration of OpenEDR with Security Information and Event Management (SIEM) systems and other security infrastructure
  • Generation of compliance and operational reports for leadership and stakeholders
  • Adoption of best practices for continuous monitoring and ongoing alert tuning

Capstone Laboratory and Practical Exercises

  • Conducting hands-on laboratory simulations addressing realistic endpoint security threats
  • Application of detection, analysis, and response workflows in practical scenarios
  • Review of laboratory outcomes and discussion of key lessons learned for future operations

Summary and Next Steps

Requirements

  • Foundational knowledge of cybersecurity principles
  • Practical experience administering Windows and/or Linux environments
  • Familiarity with endpoint protection or monitoring tools

Audience

  • IT and security professionals starting with endpoint detection tools for government entities
  • Cybersecurity engineers
  • Small to mid-sized business security staff
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories