WSA101 — XDR Essentials Workshop — TEHTRIS Academy
Instructor-Led · In-person · 3 Days

XDR Essentials
Workshop

Unlock the power of TEHTRIS XDR with our fast-track certification workshop, designed for beginners and taught by experienced users. A comprehensive introduction to the various user interfaces and capabilities of TEHTRIS XDR — with 16 practical labs.

Course code
WSA101
Format
In-person · 3 days
Level
Entry-level
Alignment
ENISA ECSF
16 Hands-on Labs
01

Workshop overview

The frequency and impact of attacks have drastically increased over the years, leaving companies vulnerable to data and knowledge loss, which in turn causes reputational and financial damage. Implementing new security solutions is crucial for survival in the modern era, but enterprises face the ongoing challenge of mastering new tools and processes.

Professionals seeking to understand global cybersecurity concepts, learn the benefits of various defense tools, and receive kickstart training on daily operations will find everything they need in the WSA101 XDR Essentials Workshop.

This workshop equips participants to design robust defenses and efficiently operate TEHTRIS XDR — from first install to continuous improvement cycles.

Demystify basic security detection concepts with easy-to-understand explanations, perfect for those who need a guided tour before diving into technical operations. Bring concepts to life with practical labs that provide a seamless learning experience.

02

Who should attend

People who are new to information security and in need of an introduction to security detection concepts.

Those who feel overwhelmed by the complexity of the UI and the vast quantity of solutions of the XDR Platform.

Professionals who need transversal knowledge of the TEHTRIS Stack without the need for deep operational background.

Managers who need a precise idea of the induced workload and the skillset required to operate TEHTRIS XDR.

03

Expected results & business key points

Expected results
  • Recognize the different types of security controls
  • Leverage complementary security approaches for best results
  • Understand key metrics and what they teach you in terms of improvements
  • Use the TEHTRIS XDR UI with ease
  • Implement your security policy or any pre-existing configuration
  • Perform basic security posture improvement tasks
Business key points
  • Reskill or upskill your team with vendor-agnostic security concepts
  • Maximize security operation success with standard terms and definitions
  • Reach a better overall security level by defining a strategy for security solutions
  • Increase efficiency by reducing time required for main tasks in TEHTRIS XDR
  • Take the most out of XDR metrics to mature your information security strategy
Inside the box
  • Identify common threat vectors and build an efficient defense line
  • Position security controls to maximize coverage
  • Understand TEHTRIS specifics and design your own proactive defenses
  • Leverage all XDR metrics to adopt a continuous improvement cycle
  • Access what you need, when you need it — think about your job, not the UI

Activities

  • Discover common defense tools and their purpose
  • Identify when solution cross coverage is required for efficient incident handling
  • Learn about TEHTRIS solutions specifics and how to take the maximum out of them
  • Take a guided tour of each TEHTRIS solution UI and identify valuable data
  • Explore menus and perform common tasks in the UI
04

Lab details — 16 hands-on labs

01
Install TEHTRIS EPP & EDR Agents
02
Configure your endpoint to forward events to your SIEM
03
Implement a predetermined configuration for EPP & EDR
04
Check for Endpoint Coverage and Alert Distribution
05
Implement an existing security policy in the EDR
06
Enable or Disable SIEM Rules
07
Read and Understand Alerts & Events
08
Configure, Save and Share your display Filters
09
Deal with False Positives & Update Whitelists
10
Support Incident Containment and Recovery Steps by deploying Temporary Yara and IOC
11
Make your own visualizations with TEHTRIS Analytics
12
Get more details about threats in the TEHTRIS CTI Platform
13
Configure a Mail Alert via SOAR to be notified of incidents
14
MITRE ATT&CK Coverage Mapping
15
Architecture Design workshop
16
Design a simple Incident Handling Process
05

Syllabus by day

01
Security & Defense Strategies
To operate 24/7 without interruptions, IT needs high-standard security guaranteeing Availability, Integrity, Confidentiality and Traceability. From top management to IT security policies, architectures, configurations and tooling shape your ability to deal with security issues before they impact company revenue and reputation. A clear vision of what serves what purpose in your enterprise defense strategy — and efficient communication with appropriate terminology — is the cornerstone of all security careers.
Subjects
Security Processes Risk Assessment Incident Response Detection Types Security Tooling Security Architectures TEHTRIS Approach
Hands-on / Workshop
MITRE ATT&CK Mapping Pair Matching Architecture Design
02
TEHTRIS XDR Solutions Basics
New solutions imply new capabilities and new processes. This section covers all basics — from setup and initial configuration to daily operations for TEHTRIS EDR, EPP and SIEM. Training in a safe and foolproof environment allows analysts to experiment with settings and observe how the security posture reacts. The instructor provides a fictive company profile and its policies to give guidelines for configuration, enabling an end-to-end experience of security posture implementation.
Subjects
Security in depth Firewall Rules Application Control Endpoint Performance Whitelist & FP Handling
Hands-on / Workshop
Agent Installation (EPP/EDR/SIEM) Incident Prevention Posture Policy Conversion Whitelist Management Event Filtering
03
Investigation Process & Continuous Improvement
Monitoring is only the beginning. Modern attacks are fast — with an average 20-minute window for full automated compromise, success awaits only enterprises whose defenders set events to trigger notifications and prepare automatic remediation. To maintain a long-term strong security posture, enterprises need vision. The TEHTRIS XDR embeds metrics and dashboard capabilities that you can tailor to your needs, providing insights to support control, compliance, quality and security management processes.
Subjects
Security Management Risk Management Incident Handling Continuous Improvement Automated Responses Prioritization
Hands-on / Workshop
XDR Dashboards TEHTRIS Analytics Custom Dashboard Incident Handling Process SOAR Remediations SOAR Notifications