This course is coming soon. It is not yet open for enrollment, and no payment is taken.
The outline and outcomes below reflect what this course will cover. Check back soon.
Coming soonAdvanced
Practical Threat Hunting
Hypothesis-driven hunts across endpoint and network telemetry.
By LearnDefend Security Team · Threat Hunting
About this course
Run structured hunts: form a hypothesis from a technique, query for its footprint, separate the rare-and-benign from the rare-and-malicious, and turn a confirmed finding into a durable detection.
What you'll learn
- Turn an ATT&CK technique into a testable hunt hypothesis.
- Use aggregation and rarity to surface outliers.
- Validate a lead before escalating it.
- Convert a hunt into a repeatable detection.
Course outline
- 1The hunting loop and hypotheses
- 2Rarity, stacking and frequency analysis
- 3Endpoint and network hunts
- 4From finding to detection
Prerequisites
- SIEM search skills (Splunk or Elastic) and SOC L2-level experience.