Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Beginner Hard42 hours

Threat Hunting

Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.

Recommended first:SOC Analyst L2
Threat HuntingLog AnalysisWindows SecurityNetwork AnalysisDetection Engineering

What you will be able to do

  • Form a testable, threat-informed hunting hypothesis and select the telemetry to test it.
  • Separate benign administrative behavior from genuinely suspicious activity through baselines and pivoting.
  • Reject an unsupported hypothesis correctly, and convert a confirmed finding into a detection.

Units

  1. 01

    What Threat Hunting Is

    Proactive vs reactive analysis, hunting maturity, the threat-informed mindset, and how a hunt differs from alert triage.

    BeginnerAvailable

    Why you are learning this

    The whole path rests on understanding that a hunter starts from a hypothesis, not an alert — this module builds that reflex.

    Unit contents6
  2. 02

    Hypotheses & Telemetry

    Building testable hypotheses from intelligence, choosing the right data source, telemetry quality, and visibility gaps.

    BeginnerAvailable

    Why you are learning this

    A weak hypothesis or the wrong data source wastes a hunt before it starts. This module is where hunts are won or lost.

    Unit contents6
  3. 03

    Endpoint & Process Hunting

    Process trees, command-line analysis, PowerShell and LOLBin hunting, rare-process and parent-child anomaly analysis.

    BeginnerAvailable

    Why you are learning this

    Most confirmed hunts land on the endpoint. This module builds the process-reading skill that catches living-off-the-land activity.

    Unit contents7
  4. 04

    Network, DNS & Identity Hunting

    Beaconing and DNS-pattern hunting, authentication anomalies, temporal correlation and multi-source pivoting.

    Job-ReadyAvailable

    Why you are learning this

    Attackers move across the network and identity planes; this module extends the hunt beyond the single host.

    Unit contents7
  5. 05

    Baselines & Anomaly Analysis

    Establishing baselines, frequency and rare-event analysis, distinguishing anomaly from malice, and refining hunts.

    Job-ReadyAvailable

    Why you are learning this

    The hardest hunting skill is telling 'unusual' from 'malicious'. This module trains that judgment directly.

    Unit contents7
  6. 06

    ATT&CK Hunting, Documentation & Detection Handoff

    ATT&CK-driven hunting, hunt scoping and documentation, turning findings into detections, the hunt-to-detection-engineering handoff — and the integrated Qasr capstone.

    Job-ReadyAvailable

    Why you are learning this

    A hunt that produces no detection and no documentation produced nothing durable. This module closes the loop — then proves it.

    Unit contents7

Recommended next