Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 14 hours
Course Outline
Introduction & Course Orientation
- Defining course objectives, expected outcomes, and lab environment setup
- Overview of EDR concepts and the OpenEDR platform architecture
- Exploring endpoint telemetry and relevant data sources
Deploying OpenEDR
- Installing OpenEDR agents on Windows and Linux endpoints
- Setting up the OpenEDR server and configuring dashboards
- Configuring basic telemetry and logging parameters
Basic Detection and Alerting
- Understanding event types and their security significance
- Configuring detection rules and alert thresholds
- Monitoring alerts and managing notifications
Event Analysis & Investigation
- Analysing events to identify suspicious patterns
- Mapping endpoint behaviours to known attack techniques
- Leveraging OpenEDR dashboards and search tools for in-depth investigation
Response & Mitigation
- Responding to alerts and containing suspicious activity
- Isolating affected endpoints and mitigating threats
- Documenting actions taken and integrating them into incident response procedures
Integration & Reporting
- Integrating OpenEDR with SIEM or other security tools
- Generating reports for management and key stakeholders
- Best practices for continuous monitoring and alert tuning
Capstone Lab & Practical Exercises
- Hands-on lab simulating real-world endpoint threats
- Applying detection, analysis, and response workflows
- Review and discussion of lab results and key lessons learned
Summary and Next Steps
Requirements
- A foundational understanding of cybersecurity principles
- Practical experience with Windows and/or Linux system administration
- Familiarity with endpoint protection or monitoring solutions
Target Audience
- IT and security professionals new to endpoint detection tools
- Cybersecurity engineers
- Security staff in small to mid-sized enterprises
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.