Threat Hunting
Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
What you will be able to do
- Form a testable, threat-informed hunting hypothesis and select the telemetry to test it.
- Separate benign administrative behavior from genuinely suspicious activity through baselines and pivoting.
- Reject an unsupported hypothesis correctly, and convert a confirmed finding into a detection.
Units
- 01
What Threat Hunting Is
Proactive vs reactive analysis, hunting maturity, the threat-informed mindset, and how a hunt differs from alert triage.
BeginnerAvailableWhy you are learning this
The whole path rests on understanding that a hunter starts from a hypothesis, not an alert — this module builds that reflex.
- 02
Hypotheses & Telemetry
Building testable hypotheses from intelligence, choosing the right data source, telemetry quality, and visibility gaps.
BeginnerAvailableWhy you are learning this
A weak hypothesis or the wrong data source wastes a hunt before it starts. This module is where hunts are won or lost.
- 03
Endpoint & Process Hunting
Process trees, command-line analysis, PowerShell and LOLBin hunting, rare-process and parent-child anomaly analysis.
BeginnerAvailableWhy you are learning this
Most confirmed hunts land on the endpoint. This module builds the process-reading skill that catches living-off-the-land activity.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 04
Network, DNS & Identity Hunting
Beaconing and DNS-pattern hunting, authentication anomalies, temporal correlation and multi-source pivoting.
Job-ReadyAvailableWhy you are learning this
Attackers move across the network and identity planes; this module extends the hunt beyond the single host.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 05
Baselines & Anomaly Analysis
Establishing baselines, frequency and rare-event analysis, distinguishing anomaly from malice, and refining hunts.
Job-ReadyAvailableWhy you are learning this
The hardest hunting skill is telling 'unusual' from 'malicious'. This module trains that judgment directly.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 06
ATT&CK Hunting, Documentation & Detection Handoff
ATT&CK-driven hunting, hunt scoping and documentation, turning findings into detections, the hunt-to-detection-engineering handoff — and the integrated Qasr capstone.
Job-ReadyAvailableWhy you are learning this
A hunt that produces no detection and no documentation produced nothing durable. This module closes the loop — then proves it.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
Recommended next
Threat Intelligence
Turning raw observations into assessed, actionable intelligence — with sourcing, structured analysis, and estimative language a decision-maker can act on. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
SOC Analyst L2
Step up from Tier-1 triage to Tier-2 depth: correlate across sources, hunt on a hypothesis, engineer and tune detections, and lead complex investigations. Recommended after completing SOC Analyst L1.