Advanced Hunting & Analytics
Go beyond the alert queue: hunt across endpoint, cloud, and identity; emulate real adversaries to test your coverage; and run the purple-team loop that turns findings into detections that stick.
Tuition
$499
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Frame a threat hunt as a testable hypothesis and drive it through a structured, repeatable hunt loop instead of waiting for alerts to fire
- Baseline normal behavior and use behavioral analytics and user and entity behavior analytics (UEBA) to surface rare logons, unusual processes, and risky peer-group outliers
- Build an adversary emulation plan from real tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK, then run it safely with Atomic Red Team and MITRE Caldera
- Measure detection coverage from an emulation run and pinpoint exactly which attacker techniques you can and cannot see
- Hunt across cloud control-plane logs such as Amazon Web Services CloudTrail and Microsoft Entra ID sign-in logs for attacker activity that never touches an endpoint
- Detect identity-driven attacks such as token theft, OAuth consent abuse, multi-factor authentication (MFA) fatigue, and federation abuse
- Plan and facilitate a purple-team exercise, score each technique as detected or missed, and brief the results to both red-team and blue-team stakeholders
- Turn hunt and exercise findings into version-controlled detections that you test like software (detection-as-code), and track coverage and mean time to detect (MTTD) over time
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Hypothesis-Driven Hunting and Behavioral Analytics
Reactive triage finds what your rules already know to look for; hunting finds the rest. This module turns hunting into a repeatable discipline. You frame a threat-informed hypothesis, run it through a structured hunt loop, and rate your team against a hunting maturity model. Then you learn to baseline normal behavior and apply behavioral analytics and User and Entity Behavior Analytics (UEBA) to surface the rare logons, unusual parent-child processes, and peer-group outliers that signal an intruder.
2 lessons · 5 quiz questions
- 02
Adversary Emulation with Atomic Red Team and Caldera
You cannot trust coverage you have never tested. This module shows you how to emulate real attacker behavior safely, so every hunt and detection is measured against techniques an adversary would actually use. You will translate a threat profile into an emulation plan of tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK, run individual tests with Atomic Red Team and automated chains with MITRE Caldera, and read the results as a coverage scorecard that shows exactly where your visibility ends.
2 lessons · 5 quiz questions · assignment
- 03
Hunting Across Cloud and Identity
Modern attackers rarely stop at the endpoint; they log in. This module takes your hunting into two places most detection programs are weakest: the cloud control plane and the identity provider. You will learn to read cloud audit logs such as Amazon Web Services (AWS) CloudTrail and Microsoft Entra ID sign-in and audit logs, then hunt identity-driven attacks including token theft, OAuth (Open Authorization) consent abuse, multi-factor authentication (MFA) fatigue, and federation abuse, all mapped to the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) cloud matrices.
2 lessons · 5 quiz questions
- 04
Purple Teaming and the Detection Engineering Loop
A finding you cannot detect twice is not a win yet. In this final module, red and blue work as one team: you plan and facilitate a purple-team exercise, walk each technique through together, and score it as detected, partially detected, or missed. Then you close the loop like a detection engineer, turning every gap into a version-controlled detection you can test like software, and tracking coverage and mean time to detect so your program measurably improves over time.
2 lessons · 5 quiz questions · assignment