Threat Hunting Foundations
Stop waiting for alerts. Hunt the threats your tools miss: form a hypothesis, dig through your own data, and turn every find into a detection that lasts.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- You will be able to explain what threat hunting is and how proactive, hypothesis-driven hunting differs from alert-driven detection.
- You will be able to run the full hunt loop, from a starting question to a documented finding and a clean handoff.
- You will be able to choose and prepare the data sources a hunt needs and state exactly what each source can and cannot reveal.
- You will be able to baseline what normal looks like in an environment so that unusual activity actually stands out.
- You will be able to build a testable hypothesis from MITRE ATT&CK, threat intelligence, and the environment in front of you.
- You will be able to use the Pyramid of Pain to aim a hunt at durable adversary behaviors instead of brittle indicators.
- You will be able to turn a proven hunt into a durable, automated detection and hand it to detection engineering.
- You will be able to measure hunt outcomes and use the results to close visibility gaps and grow your ATT&CK coverage over time.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The Hunt Loop and the Hunter's Mindset
Threat hunting starts with a question, not an alert. This module defines proactive, hypothesis-driven hunting, shows where it sits next to the Security Operations Center (SOC) and detection engineering, and walks the full hunt loop you will use for the rest of the course: ask, gather, investigate, and act. You will also place your team on a hunting maturity model, so you begin from an honest picture of where you are.
2 lessons · 5 quiz questions
- 02
Choosing and Preparing Your Data
You cannot hunt what you cannot see. This module helps you choose the data sources a hunt needs, map them to the questions you want to ask, and judge what your existing telemetry can and cannot reveal across endpoint, network, identity, and cloud. You will work with the tools that hold this data, such as a SIEM (Security Information and Event Management) platform and EDR (Endpoint Detection and Response) tooling, check your coverage against the MITRE ATT&CK data sources, and baseline normal activity so the unusual has something to stand out against.
2 lessons · 5 quiz questions · assignment
- 03
ATT&CK-Driven Hypotheses and the Pyramid of Pain
A good hunt begins with a good hypothesis. This module shows how to turn MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) techniques, threat intelligence, and knowledge of your own environment into a specific, testable claim you can prove or disprove with data. You will then use the Pyramid of Pain to aim each hunt at the adversary behaviors that are hardest to change, so your effort targets durable tactics, techniques, and procedures rather than indicators an attacker can swap out in minutes.
2 lessons · 5 quiz questions
- 04
Running the Hunt and Measuring Outcomes
This is where a hypothesis meets the data and becomes a result. You will execute a hunt end to end, document what you find, and route each outcome correctly: a real threat to incident response, a proven pattern to detection engineering as a new automated rule, and a blind spot to your data backlog. You will also learn to measure hunts with honest metrics, write a hunt report leadership will read, and grow your MITRE ATT&CK coverage so the program improves with every cycle.
2 lessons · 5 quiz questions · assignment