Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Aurora EDR

Premium room

Familiarise with the use of a Sigma-based EDR tool, Aurora.

medium

60 min

9,183

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Introduction

This room will introduce you to EDRs and Aurora, a Sigma-based tool for writing detection alerts via Windows Event logs.

Learning Objectives

The objectives of this room are:

  • Introduce EDRs and their functionalities.
  • Introduce Event Tracing for Windows.
  • Learn about Aurora and its functionalities to write alerts using event logs. 
  • Investigate suspicious events detected by Aurora.

Prerequisites

It is advisable to check out the following module and rooms before embarking on this room.

Answer the questions below
Ready for the room.