Get in Touch
 Duration 14 hours

Course Outline

Introduction & Course Orientation

  • Defining course objectives, expected outcomes, and lab environment setup
  • Overview of EDR concepts and the OpenEDR platform architecture
  • Exploring endpoint telemetry and relevant data sources

Deploying OpenEDR

  • Installing OpenEDR agents on Windows and Linux endpoints
  • Setting up the OpenEDR server and configuring dashboards
  • Configuring basic telemetry and logging parameters

Basic Detection and Alerting

  • Understanding event types and their security significance
  • Configuring detection rules and alert thresholds
  • Monitoring alerts and managing notifications

Event Analysis & Investigation

  • Analysing events to identify suspicious patterns
  • Mapping endpoint behaviours to known attack techniques
  • Leveraging OpenEDR dashboards and search tools for in-depth investigation

Response & Mitigation

  • Responding to alerts and containing suspicious activity
  • Isolating affected endpoints and mitigating threats
  • Documenting actions taken and integrating them into incident response procedures

Integration & Reporting

  • Integrating OpenEDR with SIEM or other security tools
  • Generating reports for management and key stakeholders
  • Best practices for continuous monitoring and alert tuning

Capstone Lab & Practical Exercises

  • Hands-on lab simulating real-world endpoint threats
  • Applying detection, analysis, and response workflows
  • Review and discussion of lab results and key lessons learned

Summary and Next Steps

Requirements

  • A foundational understanding of cybersecurity principles
  • Practical experience with Windows and/or Linux system administration
  • Familiarity with endpoint protection or monitoring solutions

Target Audience

  • IT and security professionals new to endpoint detection tools
  • Cybersecurity engineers
  • Security staff in small to mid-sized enterprises

Testimonials (2)

Upcoming Courses

Related Categories