IntermediateThreat Hunting12h of content · 2 guided labs750 XP

Threat Hunting Intermediate

Advanced threat hunting: APT campaign analysis, custom detection engineering, and purple team exercises with enterprise-grade SIEM and EDR tooling.

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →

2

Guided labs

Isolated VM environment

12h

Of content

Labs + practice + exams + simulations

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

HTKWhat's included
  • Full Intermediate course (video lessons + written content)
  • 2-4 guided labs — less guided, more complex than Beginner
  • Advanced per-module exams
  • HTK Intermediate certificate
  • Lifetime access, unlimited lab restarts
  • Expert instructor reviews your reports & assignments
159

One-time payment, no subscription

Start Learning →

Lab tools you will use

SplunkLab toolElastic SIEMLab toolVelociraptorLab toolYARADetectionSigmaDetectionOSQueryLab toolSysmonEndpoint logsCrowdStrike FalconLab toolSplunkLab toolElastic SIEMLab toolVelociraptorLab toolYARADetectionSigmaDetectionOSQueryLab toolSysmonEndpoint logsCrowdStrike FalconLab tool
MITRE ATT&CK NavigatorLab toolKibanaLab toolWazuhSIEMChainsawLab toolHayabusaLab toolDeepBlueCLILab toolKapeLab toolEric Zimmerman ToolsLab toolMITRE ATT&CK NavigatorLab toolKibanaLab toolWazuhSIEMChainsawLab toolHayabusaLab toolDeepBlueCLILab toolKapeLab toolEric Zimmerman ToolsLab tool

Before you start — quick answers

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Course Syllabus

4 modules · 12h of content

Each phase maps to a module in this course. Scroll to see how the curriculum builds, module by module.

1

Module 1

Intermediate

Advanced Threat Hunting & APT Analysis

  • APT campaign decomposition: initial access to exfiltration
  • Living-off-the-land techniques: LOLBins, WMI, PowerShell abuse
  • Memory forensics for threat hunting: detecting injected code
  • Module exam
2

Module 2

Intermediate

Detection Engineering with Sigma & YARA

  • Advanced Sigma rule writing: correlation, aggregation, and near-real-time rules
  • YARA rule development for file and memory scanning
  • Detection-as-code: CI/CD pipelines for detection content
  • Module exam
3

Module 3

Intermediate

Purple Team Exercises

  • Atomic Red Team and MITRE Caldera for controlled adversary simulation
  • Validating detection coverage against ATT&CK techniques
  • Gap analysis and detection backlog prioritization
  • Module exam
4

Module 4

Intermediate

Hunt Report + Intermediate Certification

  • Professional threat hunting report: executive summary, technical findings, ATT&CK heat map
  • Detection improvement roadmap and KPI tracking
  • HTK intermediate certification exam

What you will learn

  • Decompose APT campaigns and hunt living-off-the-land activity under realistic noise
  • Engineer custom Sigma and YARA detections and validate them with purple-team exercises
  • Produce professional hunt reports with actionable findings for SOC/DFIR teams

Hands-on Lab

Hunt advanced persistent threats across Windows, network, and cloud telemetry. Build custom Sigma and YARA rules, correlate multi-source evidence, and produce professional threat hunting reports with MITRE ATT&CK mapping.

2⬡ 2 guided labs
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Recommended: complete the HTK Threat Hunting Beginner course first, or have equivalent hunting experience
  • ·Working knowledge of SIEM queries, log sources, and the MITRE ATT&CK framework
  • ·Familiarity with Windows event logs, Sysmon, and basic detection logic
  • ·Stable internet connection — all SIEM/EDR lab tooling is fully pre-configured, no local setup required

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Not for beginner courses. They start from scratch with guided, step-by-step instructions.

Each lab session opens a 2–4 hour maximum VM session window. You can restart it as many times as you need — unlimited restarts are included with your purchase.

Yes. Unlimited restarts are included with your purchase. Practice as much as you want.

Yes. Your HTK certificate is issued upon completing the final lesson of the last module. Course progress is sequential — each lesson unlocks the next.

Yes. 14-day money-back if lesson progress is below 20% and you have not completed the HTK certificate path (all lessons + labs) for that course. Details in our Refund Policy.

Yes. Once purchased, you have permanent access to all course materials and future updates.

Yes. All professional tools come pre-installed and configured in the VM, no local setup needed.

Most students complete the course in 2–4 weeks studying part-time. You set your own pace.

Start from the beginning?

Threat Hunting Beginner

Not ready for intermediate yet? Threat Hunting Beginner covers the foundational skills and guided labs you need before tackling the advanced material.

10h of content1 guided lab119
View Beginner Course →
Ready to level up?

Build real Threat Hunting skills

Get hands-on with real Threat Hunting scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From159or 199 € for the complete path
One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee