Threat Hunting Foundations
Difficulty
Threat Hunting Foundations provides an introduction to proactive threat detection and mitigation practices. Explore threat actor behavior, hunting methodologies, network and endpoint analysis, and custom hunting strategies to empower security professionals in identifying and neutralizing threats effectively.
6
modules
24
hours of content
24
real-world skills
Learning Objectives
- Analyze the goals, techniques, and tools of common threat actors, including ransomware groups and APTs
- Examine network and endpoint data to identify malicious activity
- Understand threat hunting methodologies, investigative processes, and mindset
- Develop clear communication and reporting skills for effective threat intelligence sharing
Who is it for?
- Aspiring threat hunters seeking foundational skills
- Security analysts looking to advance their threat detection capabilities
- SOC team members aiming to master proactive threat identification
Showcase your skills with an OffSec Learning Badge
Proficiency
Proven knowledge of fundamental skills needed to protect their organization’s assets
Industry recognition
A valuable OffSec credential demonstrating your commitment to cybersecurity
Hands-on skill
Demonstrated ability to proactively improve their organization’s security posture
Threat Hunting Foundations FAQ
-
Are there any prerequisites for Threat Hunting Foundations?
There are no formal prerequisites, but completion of or equivalent knowledge in the following learning modules and paths is recommended:
-
Is Threat Hunting Foundations good for beginners?
Yes, this learning path is designed to provide a strong foundation for those new to the field, while also offering valuable insights for those with some experience.
-
Threat Hunting Foundations: NIST Work Roles
- Data Analysis
- Systems Security Analysis
- Defensive Cybersecurity
- Digital Forensics
- Incident Response
- Insider Threat Analysis
- Threat Analysis
- Vulnerability Analysis
-
Threat Hunting Foundations: NIST TKS’s
- Knowledge of privacy policies and procedures
- Knowledge of cybersecurity vulnerabilities
- Knowledge of system vulnerabilities
- Knowledge of access control principles and practices
- Knowledge of authentication and authorization tools and techniques
- Knowledge of identity and access management (IAM) principles and practices
- Collect metrics and trending data
- Develop and implement data mining and data warehousing programs
- Skill in performing binary analysis
- Skill in implementing one-way hash functions
-
Skills learned in Threat Hunting Foundations
- Threat hunting
- Malware analysis
- Malware behavior analysis
- Threat intel sharing
- Incident response support
- Log analysis
- Incident documentation
- Incident lifecycle management
- SIEM threat detection
- SIEM analysis
- SIEM monitoring
- Detection query tuning
- Detection rule writing
- Network traffic analysis
- Threat Intelligence-based threat hunting
- Threat Intelligence-driven threat hunting
- Threat Intelligence event correlation
- Detection signature creation
- Threat actor behavior analysis
- Threat actor profiling
- Reconnaissance and OSINT
- EDR/SIEM hunting
- Root cause analysis
- Malicious pattern detection