Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Course Overview & Orientation
- Learning objectives, anticipated outcomes, and laboratory environment configuration
- High-level architecture of Enterprise Detection and Response (EDR) solutions and OpenEDR components for government
- Review of the MITRE ATT&CK framework and foundational principles of threat hunting
OpenEDR Deployment & Telemetry Acquisition
- Installation and configuration of OpenEDR agents on Windows endpoints within government networks
- Server-side infrastructure, data ingestion pipelines, and storage requirements for secure environments
- Configuration of telemetry sources, event normalization processes, and data enrichment strategies
Endpoint Telemetry Analysis & Event Modeling
- Identification of critical endpoint event types, attributes, and their mapping to MITRE ATT&CK techniques
- Event filtering methodologies, correlation strategies, and techniques for reducing operational noise
- Development of reliable detection indicators derived from low-fidelity telemetry data
Alignment of Detections with MITRE ATT&CK
- Translation of telemetry data into ATT&CK technique coverage analysis and identification of detection gaps
- Utilization of ATT&CK Navigator tools and documentation of mapping rationale for auditability
- Prioritization of threat techniques for investigation based on risk assessments and available telemetry
Threat Hunting Methodologies
- Comparison of hypothesis-driven hunting approaches versus indicator-led investigative methods
- Development of hunt playbooks and iterative discovery workflows for sustained operations
- Practical laboratory exercises: identification of lateral movement, persistence mechanisms, and privilege escalation patterns
Detection Engineering & Optimization
- Design of detection rules utilizing event correlation analysis and behavioral baseline establishment
- Rule validation, tuning to minimize false positives, and measurement of detection effectiveness for government systems
- Creation of reusable signatures and analytic content suitable for enterprise-wide deployment
Incident Response & Root Cause Analysis with OpenEDR
- Utilization of OpenEDR for alert triage, incident investigation, and attack timeline reconstruction
- Forensic artifact collection, evidence preservation protocols, and chain-of-custody requirements
- Integration of investigative findings into Incident Response (IR) playbooks and remediation workflows
Automation, Orchestration & System Integration
- Automation of routine hunts and alert enrichment through scripting and API connectors for operational efficiency
- Integration of OpenEDR with Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and threat intelligence platforms
- Scaling telemetry ingestion, data retention policies, and operational considerations for large-scale government deployments
Advanced Use Cases & Red Team Coordination
- Adversary behavior simulation for validation purposes: purple team exercises and ATT&CK-based emulation
- Analysis of case studies involving real-world threat hunts and post-incident reviews
- Design of continuous improvement cycles to enhance detection coverage and resilience
Capstone Laboratory & Final Presentations
- Comprehensive capstone exercise: end-to-end hunt from hypothesis formulation through containment and root cause analysis using simulated scenarios
- Participant presentations of investigative findings and recommended mitigation strategies
- Course conclusion, distribution of reference materials, and identification of recommended next steps for ongoing development
Requirements
- Proficiency in foundational endpoint security principles
- Practical experience conducting log analysis and performing standard Linux or Windows system administration tasks
- Working knowledge of prevalent threat vectors and incident response frameworks designed for government environments
Audience
- Security operations center (SOC) analysts
- Threat hunting specialists and incident response personnel
- Security engineers tasked with detection engineering and telemetry management
21 Hours
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.