Threat Hunting
Threat Hunting Beginner
Practical threat hunting foundations with guided hands-on labs.
119 EUR
Proactive detection, hypothesis-driven hunting, and adversary behavior analysis across endpoints and networks using SIEM, EDR, and MITRE ATT&CK frameworks.
Lab tools you will use
Practical threat hunting foundations with guided hands-on labs.
119 EUR
Intermediate threat hunting with complex real-world scenarios and professional workflow.
159 EUR
Get the Beginner + Intermediate courses bundled together and unlock exclusive extras.
Each phase maps to a course module. Scroll to assemble your full progression — from beginner fundamentals to intermediate mastery.
Phase 1
BeginnerHunting is bounded by telemetry. The first honest exercise is establishing where your visibility ends.
Phase 2
BeginnerYou cannot recognise the anomalous without a feel for the ordinary, and most false positives come from skipping this.
Phase 3
BeginnerThe query language is the instrument. This phase is about interrogating large volumes without drowning in results.
Phase 4
BeginnerRunning the loop end to end on a single technique, and writing it up so somebody else could repeat it exactly.
Phase 5
IntermediateHypotheses stop being guesswork once they are driven by documented behaviour rather than by intuition.
Phase 6
IntermediateWhat works on one host has to survive contact with an entire estate, which is a different problem.
Phase 7
IntermediateAnything you had to hunt for twice should have been a detection the first time. Here you close that loop.
Phase 8
IntermediateThe last phase is the uncomfortable one: measuring how much of the adversary playbook you would genuinely notice.
The Threat Hunting path teaches you to look for intrusions that no alert has fired on. That is the whole discipline: detection catches what somebody already anticipated, and hunting is the structured search for what nobody wrote a rule for yet.
It is hypothesis-driven from the start. Rather than staring at dashboards hoping something stands out, you learn to form a specific, testable proposition — a technique an adversary would plausibly use against this environment — then determine what evidence it would leave, go and look for exactly that, and either confirm it or rule it out. A hunt that finds nothing is still a result, provided you can say precisely what you ruled out.
The work happens across endpoint and network telemetry in a SIEM, on datasets carrying real adversary behaviour rather than synthetic alerts. Every hunt ends the way it should in practice: either an incident, or a new detection rule so the same behaviour never needs hunting again.
The path uses more tools than fit here. These are the ones that define the work.
| Tool | Category | What for |
|---|---|---|
| Splunk / Elastic SIEM | Analytics | Querying telemetry at volume, where hunts are actually executed |
| Sysmon | Endpoint telemetry | Producing the process, network and file visibility Windows lacks by default |
| Velociraptor | Endpoint hunting | Asking a question of thousands of endpoints at once and getting answers back |
| Sigma | Detection | Writing rules once in a portable format rather than per-SIEM |
| MITRE ATT&CK Navigator | Coverage | Mapping what you can actually detect versus what you assume you can |
| Chainsaw / Hayabusa | Event log analysis | Rapidly triaging Windows event logs at scale during an investigation |
| OSQuery | Endpoint state | Querying live endpoint configuration as though it were a database |
| Eric Zimmerman Tools | Forensics | Parsing the Windows artefacts that record execution and persistence |
Written so someone else can reproduce and extend the hunt
Derived from behaviour you hunted, portable across SIEM platforms
An honest picture of what your telemetry does and does not see
Including negative results, which is what makes coverage claims credible
Hunting is usually where SOC analysts go when they want to stop reacting, and it is the skill set that separates a tier-one queue role from a senior detection position.
Proactively searches for undetected intrusions across the estate
Builds and tunes the rules that catch behaviour automatically
Handles escalations and investigations the queue cannot resolve
Scopes compromises and drives containment
Complete answers about this path, labs, certificates, and refunds
Detection is automated and catches what someone anticipated. Hunting is a human, hypothesis-driven search for what no rule covers yet. They feed each other: a successful hunt should end in a new detection rule.
No. The labs provide the environment and the datasets, so you can complete the path without access to a production platform. What transfers is the method, which is not tied to any one product.
Yes, if scoped honestly. Small teams cannot hunt continuously, but a focused hunt against a specific plausible technique is achievable and often more valuable than broad monitoring nobody has time to read.
Enough to navigate it. The path uses it constantly as a shared vocabulary and to structure hypotheses, and builds familiarity as it goes — you do not need to arrive knowing technique IDs.
The reasoning it teaches is what those interviews probe: given this environment and this adversary, what would you look for and where. Being able to talk through hunts you have actually run, including ones that found nothing, is a strong signal.
No, provided it was specific. A well-scoped hunt that rules out a technique tells you something concrete about your exposure. Hunts that find nothing and cannot say what they ruled out are the failures.