Course objectives
After completing this course, students will be able to:
- Develop Hypotheses: Create actionable hunting theories based on threat actor TTPs (Tactics, Techniques, and Procedures).
- Master Network Analysis: Use Wireshark, Zeek, and RITA to detect C2 beacons, data exfiltration, and suspicious protocol tunneling.
- Perform Endpoint Analysis: Hunt for "Fileless" malware, process injection, and persistence mechanisms in Windows/Linux.
- Leverage SIEMs at Scale: Build advanced search queries in Splunk and ELK to correlate events across thousands of endpoints.
- Utilize Forensics Tools: Use Volatility (Memory analysis) and Redline to find malicious artifacts in RAM.
- Communicate Findings: Draft a professional Threat Hunting Report that includes remediation strategies and proposed defense improvements.
Course outlines
- Domain 1: Introduction & Methodology
- The Hunter Mindset: Proactive vs. Reactive.
- Threat Hunting Maturity Model (THMM): Assessing where an organization stands.
- Building a hunting team: Ad-hoc vs. Dedicated.
- Domain 2: Cyber Threat Intelligence (CTI)
- Types of Intel: Strategic, Tactical, and Operational.
- Using YARA and OpenIOC to automate threat matching.
- Integrating CTI feeds (MISP, AlienVault OTX) into the hunting process.
- Domain 3: Threat Hunting Strategies
- The Pyramid of Pain: Focusing on TTPs instead of just IP addresses/Hashes.
- Hypothesis generation using MITRE ATT&CK and the Diamond Model.
- Domain 4: Network Threat Hunting
- Protocol Analysis: Hunting for anomalies in DNS, HTTP/S, and SMB traffic.
- Identifying Lateral Movement and Command & Control (C2) channels.
- Hunting for Webshells hiding in plain sight.
- Domain 5: Endpoint Threat Hunting
- Windows Internal Processes: Distinguishing "Known Normal" from "Known Evil."
- Memory Forensics: Detecting code injection and reflective DLL loading using Volatility.
- Advanced Logging: Utilizing Sysmon and Event Tracing for Windows (ETW).
- Hunting with PowerShell (Kansa, Invoke-IR).
- Domain 6: Communications & Reporting
- Mapping findings back to the Cyber Kill Chain.
- Recommending "Defensive Gaps" closures based on hunt results.
- Drafting the final executive and technical reports.