IntermediateThreat Hunting12h · 2 labs

Threat Hunting Intermediate

Advanced threat hunting: APT campaign analysis, custom detection engineering, and purple team exercises with enterprise-grade SIEM and EDR tooling.

200+ students·4.9/5 rating·High completion rate

14-day money-back guarantee · No subscription · Lifetime access

Preview the student experience

No login · Free interactive demo

Try demo →
HTKWhat's included
  • Access to all course videos and materials
  • Unlimited guided lab access with auto-validated flags
  • HTK Certificate upon completion
  • Lifetime course access with future updates
  • Flexible, self-paced learning schedule
  • 30-day satisfaction guarantee
159

One-time payment, no subscription

Join Waitlist →

2

⬡ 2 guided lab

Isolated VM environment

12h

Of content

Videos + practice + exams

4

Modules

Progressive difficulty

2–4h

Per lab session

Unlimited restarts

Lab tools you will use

SplunkLab toolElastic SIEMLab toolVelociraptorLab toolYARADetectionSigmaDetectionOSQueryLab toolSysmonLab toolCrowdStrike FalconLab toolSplunkLab toolElastic SIEMLab toolVelociraptorLab toolYARADetectionSigmaDetectionOSQueryLab toolSysmonLab toolCrowdStrike FalconLab tool
MITRE ATT&CK NavigatorLab toolKibanaLab toolWazuhSIEMChainsawLab toolHayabusaLab toolDeepBlueCLILab toolKapeLab toolEric Zimmerman ToolsLab toolMITRE ATT&CK NavigatorLab toolKibanaLab toolWazuhSIEMChainsawLab toolHayabusaLab toolDeepBlueCLILab toolKapeLab toolEric Zimmerman ToolsLab tool

Before you start — quick answers

Course Syllabus

4 course syllabus · 12h of content

What you will learn

  • Decompose APT campaigns and hunt living-off-the-land activity under realistic noise
  • Engineer custom Sigma and YARA detections and validate them with purple-team exercises
  • Produce professional hunt reports with actionable findings for SOC/DFIR teams

Hands-on Lab

Hunt advanced persistent threats across Windows, network, and cloud telemetry. Build custom Sigma and YARA rules, correlate multi-source evidence, and produce professional threat hunting reports with MITRE ATT&CK mapping.

2⬡ 2 guided lab
2–4hSession window
UnlimitedRestarts
AutoFlag validation
Experience a lab preview →

Requirements

  • ·Modern web browser
  • ·Stable internet connection
  • ·No local installation required
  • ·Basic technical English recommended

Frequently Asked Questions

Complete answers about this course, labs, certificates, and refunds

Start from the beginning?

Threat Hunting Beginner

Not ready for intermediate yet? Threat Hunting Beginner covers the foundational skills and guided labs you need before tackling the advanced material.

10h Of content1 guided lab119
View Beginner Course →
Ready to level up?

Build real Threat Hunting skills

Get hands-on with real Threat Hunting scenarios, professional-grade tools, and validated flag objectives. No prior experience needed.

From159or 199 € for the complete path
One-time payment, no recurring chargesLifetime access, course updates included14-day money-back guarantee
Threat Hunting Intermediate: Hands-on Cybersecurity Course | HackTheKnowledge