All Modules THREAT HUNTING

Threat Hunting · Complete Guide

A field-focused curriculum built from the methodologies of CrowdStrike OverWatch, Red Canary, Elastic Security, Mandiant, and the PEAK/TaHiTI/SANS frameworks. Nine chapters covering the full hunt lifecycle, including an applied LOLBin abuse hunting chapter.

9 CHAPTERS
~13 HRS CONTENT
BEGINNER → ADVANCED SKILL RANGE
JUN 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
hypothesis-driven PEAK TaHiTI ATT&CK KQL Sigma evidence scoring

ALL CHAPTERS

01
BEGINNER 25 min

Threat Hunting Foundations

The shift from reactive to proactive. SOC maturity, adversary mindset, and the prerequisites for an effective hunt program.

foundations SOC mindset
02
BEGINNER 30 min

Hypothesis Generation

The ABLE framework, ATT&CK-driven hypothesis creation, prioritization scoring, and converting threat intel reports into testable hunt plans.

ABLE ATT&CK intel
03
INTERMEDIATE 35 min

Hunting Frameworks

Sqrrl Loop, PEAK, TaHiTI, SANS PAM model, and OTRF Playbook. When to use which framework and how to combine them.

PEAK TaHiTI lifecycle
04
INTERMEDIATE 30 min

Data Sources and Telemetry

Windows Event Logs, Sysmon, EDR, DNS, proxy, identity, and cloud telemetry. The visibility gap and ATT&CK data source coverage mapping.

logs EDR Sysmon
05
INTERMEDIATE 35 min

Hunt Execution

Planning a hunt, writing hunting queries in KQL/SPL/Sigma, statistical analysis methods, pivot techniques, and iterating on findings.

KQL queries pivoting
06
INTERMEDIATE 25 min

Evidence Quality and Scoring

Admiralty System, Diamond Model, Pyramid of Pain, confidence scoring, and false positive management.

Admiralty Diamond Pyramid
07
ADVANCED 30 min

Hunt Lifecycle and Documentation

The full PEAK lifecycle applied, hunt scoping templates, outcome classification, after-action reports, and KPI measurement.

PEAK reporting KPIs
08
ADVANCED 40 min

Advanced Topics

Threat actor profiling, campaign-based hunting, ML-assisted methods, purple team validation, and building a hunt program.

ML purple team AI
09
ADVANCED 40 min

Hunting LOLBin Abuse

Hunt for certutil, mshta, regsvr32, rundll32, and BITS abuse using behavioral hypotheses, KQL and Sigma queries, and the full ABLE workflow.

LOLBins T1218 detection

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Basic Windows OS concepts — processes, registry, file system structure
  • Familiarity with log concepts: event IDs, timestamps, field structure
  • Some exposure to a SIEM or query language (KQL, SPL, or similar)
  • General understanding of the cyber kill chain or ATT&CK framework

WHAT YOU WILL KNOW AFTER

  • The full threat hunting lifecycle from scoping to after-action reporting
  • How to write testable hypotheses using ABLE and ATT&CK data sources
  • PEAK, TaHiTI, and Sqrrl Loop — when and how to apply each
  • Hunting query writing in KQL, SPL, and Sigma
  • Evidence scoring using Admiralty, Diamond Model, and Pyramid of Pain
  • How to build and measure a hunt program using KPIs

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.

VISITORS