Skip to Content

Certified Threat Hunting Professional (eCTHP)  


Request for price


Length: 5 day (40 hours)

 

Course objectives

After completing this course, students will be able to:

      • Develop Hypotheses: Create actionable hunting theories based on threat actor TTPs (Tactics, Techniques, and Procedures).
      • Master Network Analysis: Use Wireshark, Zeek, and RITA to detect C2 beacons, data exfiltration, and suspicious protocol tunneling.
      • Perform Endpoint Analysis: Hunt for "Fileless" malware, process injection, and persistence mechanisms in Windows/Linux.
      • Leverage SIEMs at Scale: Build advanced search queries in Splunk and ELK to correlate events across thousands of endpoints.
      • Utilize Forensics Tools: Use Volatility (Memory analysis) and Redline to find malicious artifacts in RAM.
      • Communicate Findings: Draft a professional Threat Hunting Report that includes remediation strategies and proposed defense improvements.



Course outlines

    • Domain 1: Introduction & Methodology
      • The Hunter Mindset: Proactive vs. Reactive.
      • Threat Hunting Maturity Model (THMM): Assessing where an organization stands.
      • Building a hunting team: Ad-hoc vs. Dedicated.
    • Domain 2: Cyber Threat Intelligence (CTI)
      • Types of Intel: Strategic, Tactical, and Operational.
      • Using YARA and OpenIOC to automate threat matching.
      • Integrating CTI feeds (MISP, AlienVault OTX) into the hunting process.
    • Domain 3: Threat Hunting Strategies
      • The Pyramid of Pain: Focusing on TTPs instead of just IP addresses/Hashes.
      • Hypothesis generation using MITRE ATT&CK and the Diamond Model.
    • Domain 4: Network Threat Hunting
      • Protocol Analysis: Hunting for anomalies in DNS, HTTP/S, and SMB traffic.
      • Identifying Lateral Movement and Command & Control (C2) channels.
      • Hunting for Webshells hiding in plain sight.
    • Domain 5: Endpoint Threat Hunting
      • Windows Internal Processes: Distinguishing "Known Normal" from "Known Evil."
      • Memory Forensics: Detecting code injection and reflective DLL loading using Volatility.
      • Advanced Logging: Utilizing Sysmon and Event Tracing for Windows (ETW).
      • Hunting with PowerShell (Kansa, Invoke-IR).
    • Domain 6: Communications & Reporting
      • Mapping findings back to the Cyber Kill Chain.
      • Recommending "Defensive Gaps" closures based on hunt results.
      • Drafting the final executive and technical reports.


Download Outlines