Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

This course is coming soon. It is not yet open for enrollment, and no payment is taken.

The outline and outcomes below reflect what this course will cover. Check back soon.

Coming soonAdvanced

Practical Threat Hunting

Hypothesis-driven hunts across endpoint and network telemetry.

By LearnDefend Security Team · Threat Hunting

About this course

Run structured hunts: form a hypothesis from a technique, query for its footprint, separate the rare-and-benign from the rare-and-malicious, and turn a confirmed finding into a durable detection.

What you'll learn

  • Turn an ATT&CK technique into a testable hunt hypothesis.
  • Use aggregation and rarity to surface outliers.
  • Validate a lead before escalating it.
  • Convert a hunt into a repeatable detection.

Course outline

  1. 1The hunting loop and hypotheses
  2. 2Rarity, stacking and frequency analysis
  3. 3Endpoint and network hunts
  4. 4From finding to detection

Prerequisites

  • SIEM search skills (Splunk or Elastic) and SOC L2-level experience.
Practical Threat Hunting | LearnDefend