Course description

This is an advanced module designed for security analysts who want to move beyond reactive monitoring. In Threat Hunting: Proactive Defense, you will shift from waiting for alerts to actively searching for malicious activity within a network.

You will learn the Hunting Maturity Model, how to develop hypotheses based on the MITRE ATT&CK® framework, and how to use tools like ELK Stack, Splunk, and Wireshark to find "needles in the haystack." The course covers memory forensics, log analysis, and behavioral patterns that signal a breach. This module bridges the gap between basic SOC operations and advanced incident response.

What will i learn?

  • Develop Hypotheses: Create structured hunting plans based on the latest Threat Intelligence.
  • Analyze Traffic: Detect lateral movement and command-and-control (C2) beacons in network logs.
  • Endpoint Hunting: Use Sysmon and EDR telemetry to identify process injection and living-off-the-land techniques.
  • Automate Detection: Write custom YARA rules and Sigma rules to automate the discovery of known threats.
  • Report Findings: Translate technical "hunts" into actionable business risk reports for stakeholders.

Requirements

  • Foundational Knowledge: Solid understanding of TCP/IP, Windows/Linux internals, and common attack vectors.
  • Prerequisites: Completion of Certified Network Defender or SOC Analyst Tier 1 (or equivalent experience).
  • Environment: Access to a virtualized lab environment (Kali Linux, REMnux, or Windows Server).

Frequently asked question

Incident Response starts after an alert is triggered. Threat Hunting is the proactive search for threats that haven't triggered an alert yet.

While you don't need to be a software engineer, basic scripting (Python or PowerShell) is highly recommended for automating data analysis.

Yes. We include a dedicated section on hunting for threats within AWS and Azure log environments (CloudTrail, GuardDuty).

faramaye Ireoluwa Victor

₦600000

Lectures

0

Skill level

Advanced

Expiry period

2 Months

Certificate

Yes

Share this course

Related courses