Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.
1Threat Hunting Fundamentals & Adversary Behavior
- •Reactive vs. proactive detection: why hunting matters
- •MITRE ATT&CK framework: tactics, techniques, and procedures
- •Threat intelligence-driven vs. hypothesis-driven hunting
- •Module theory exam
2Log Sources & Telemetry Collection
- •Windows event logs: Security, Sysmon, PowerShell logging
- •Network telemetry: DNS, proxy, NetFlow
- •Configuring collection with Sysmon and OSQuery
- •Module exam
3Hunting Techniques & Tools
- •Splunk and Elastic SIEM: queries, dashboards, and correlations
- •Sigma rules: writing and converting detection logic
- •Identifying persistence, lateral movement, and C2 patterns
- •Module exam
4Reporting & Certification Exam
- •Documenting hunt findings: timelines, IOCs, and recommendations
- •Measuring hunt program maturity and effectiveness
- •HTK final certification exam