Endpoint Detection and Response (EDR)
All certified coursesThis course is intended to help customers understand how Qualys EDR is set up and configured to enhance the endpoint security posture by preventing, detecting, and responding to advanced threats. Learners will also understand how to investigate events and incidents and hunt for threats.
This course will teach participants to set up, configure and operate Qualys EDR. By completing this course, you should be able to meet the following objectives:
Describe what EDR is and what its main benefits and features are.
Understand the requirements for EDR and anti-malware, and how to configure Cloud Agents for EDR.
Identify the activities monitored by EDR, as well as the events and incidents they generate.
Demonstrate how to use EDR for threat hunting and anti-malware.
Define the available methods to respond to events and incidents.
Agenda
Introduction to Qualys EDR
EDR Activation and Setup
Working with Qualys EDR
Investigating Events and Incidents
Hunt for Threats
Anti-Malware
Respond to Prioritized Events
Configure Rule-Based Alerts
Correlate Prevention across Multiple Vectors
Hands-on labs or lab simulation will cover the following topics to complement the coursework:
EDR Activation and Asset Information
Exploring EDR Events
Exploring EDR Incidents
Threat Hunting in EDR
Exploring the Anti-Malware Feature in EDR
Responding to EDR Incidents
Configuring and Responding to Alerts in EDR
Incident Correlation