Get in Touch

Course Outline

Course Overview & Orientation

  • Learning objectives, anticipated outcomes, and laboratory environment configuration
  • High-level architecture of Enterprise Detection and Response (EDR) solutions and OpenEDR components for government
  • Review of the MITRE ATT&CK framework and foundational principles of threat hunting

OpenEDR Deployment & Telemetry Acquisition

  • Installation and configuration of OpenEDR agents on Windows endpoints within government networks
  • Server-side infrastructure, data ingestion pipelines, and storage requirements for secure environments
  • Configuration of telemetry sources, event normalization processes, and data enrichment strategies

Endpoint Telemetry Analysis & Event Modeling

  • Identification of critical endpoint event types, attributes, and their mapping to MITRE ATT&CK techniques
  • Event filtering methodologies, correlation strategies, and techniques for reducing operational noise
  • Development of reliable detection indicators derived from low-fidelity telemetry data

Alignment of Detections with MITRE ATT&CK

  • Translation of telemetry data into ATT&CK technique coverage analysis and identification of detection gaps
  • Utilization of ATT&CK Navigator tools and documentation of mapping rationale for auditability
  • Prioritization of threat techniques for investigation based on risk assessments and available telemetry

Threat Hunting Methodologies

  • Comparison of hypothesis-driven hunting approaches versus indicator-led investigative methods
  • Development of hunt playbooks and iterative discovery workflows for sustained operations
  • Practical laboratory exercises: identification of lateral movement, persistence mechanisms, and privilege escalation patterns

Detection Engineering & Optimization

  • Design of detection rules utilizing event correlation analysis and behavioral baseline establishment
  • Rule validation, tuning to minimize false positives, and measurement of detection effectiveness for government systems
  • Creation of reusable signatures and analytic content suitable for enterprise-wide deployment

Incident Response & Root Cause Analysis with OpenEDR

  • Utilization of OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
  • Forensic artifact collection, evidence preservation protocols, and chain-of-custody requirements
  • Integration of investigative findings into Incident Response (IR) playbooks and remediation workflows

Automation, Orchestration & System Integration

  • Automation of routine hunts and alert enrichment through scripting and API connectors for operational efficiency
  • Integration of OpenEDR with Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and threat intelligence platforms
  • Scaling telemetry ingestion, data retention policies, and operational considerations for large-scale government deployments

Advanced Use Cases & Red Team Coordination

  • Adversary behavior simulation for validation purposes: purple team exercises and ATT&CK-based emulation
  • Analysis of case studies involving real-world threat hunts and post-incident reviews
  • Design of continuous improvement cycles to enhance detection coverage and resilience

Capstone Laboratory & Final Presentations

  • Comprehensive capstone exercise: end-to-end hunt from hypothesis formulation through containment and root cause analysis using simulated scenarios
  • Participant presentations of investigative findings and recommended mitigation strategies
  • Course conclusion, distribution of reference materials, and identification of recommended next steps for ongoing development

Requirements

  • Proficiency in foundational endpoint security principles
  • Practical experience conducting log analysis and performing standard Linux or Windows system administration tasks
  • Working knowledge of prevalent threat vectors and incident response frameworks designed for government environments

Audience

  • Security operations center (SOC) analysts
  • Threat hunting specialists and incident response personnel
  • Security engineers tasked with detection engineering and telemetry management
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories