Advanced Cyber Threat Hunting and Incident Response Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-002
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitimate credentials, living-off-the-land binaries, cloud administration tools and short-lived infrastructure that does not trigger simple signature-based alerts. This course prepares experienced analysts to turn ambiguous signals across endpoint, network, identity and cloud data into evidence-led hunting hypotheses, validated findings and defensible incident decisions.

Participants work through a repeatable threat-hunting and incident-response workflow: mapping adversary behaviour to MITRE ATT&CK, baselining normal activity, writing behavioural detections, pivoting across SIEM and endpoint telemetry, and scoping compromise. They investigate credential theft, command-and-control, lateral movement, persistence, ransomware precursors and cloud account abuse using Microsoft Sentinel, Splunk Enterprise Security and Velociraptor. The course also covers evidence handling, host triage, containment choices, incident command, executive reporting and lessons-learned improvements.

Delivery combines instructor-led technical briefings with guided investigations using realistic attack data and analyst playbooks. Each participant develops a threat-hunting pack containing prioritised hypotheses, data-source requirements, ATT&CK mappings, query logic, investigation decision points and incident-report templates tailored to their own environment. They leave with a practical 30-day improvement plan for their detection and response function, plus a certificate on completion. The course is designed for practitioners who already understand core SOC monitoring and need to lead higher-confidence investigations.

Course objectives

By the end of this course, participants will be able to:

  • Construct risk-prioritised threat-hunting hypotheses from threat intelligence, asset context and MITRE ATT&CK techniques
  • Map endpoint, identity, network and cloud telemetry to attacker behaviours and identify visibility gaps
  • Write and tune behavioural detection queries in Microsoft Sentinel and Splunk Enterprise Security
  • Investigate suspicious endpoint activity with Velociraptor artefact collection and timeline analysis
  • Correlate authentication, process, DNS and network evidence to scope lateral movement and persistence
  • Apply an incident triage and containment decision model that preserves evidence and limits business disruption
  • Produce an executive-ready incident report with attack narrative, impact assessment, remediation actions and lessons learned
  • Build a 30-day threat-hunting improvement plan with measurable detection, telemetry and playbook priorities

Benefits of attending

For you

  • Gain a repeatable hunting methodology for moving from threat intelligence to validated findings
  • Build credibility as an investigator who can explain technical evidence and business impact to incident leaders
  • Develop practical query, triage and scoping skills applicable to senior SOC and incident-response roles
  • Create a portfolio-ready threat-hunting pack and incident report that demonstrate advanced operational capability
  • Improve judgement on when to contain, collect evidence, escalate or close an investigation

For your organisation

  • Reduce attacker dwell time by improving analysts' ability to detect behaviour beyond rule-based alerts
  • Increase investigation consistency through documented hypotheses, evidence standards and escalation decisions
  • Identify telemetry blind spots across identity, endpoint, network and cloud monitoring before an incident exposes them
  • Improve containment decisions by balancing evidence preservation, operational impact and attack progression
  • Provide management with clearer incident narratives, remediation priorities and measurable detection-improvement actions

Target competencies

Hypothesis-led huntingATT&CK mappingDetection engineeringEndpoint triageIncident scopingEvidence-based reporting

Who should attend

  • Senior SOC Analysts — who need to investigate weak signals and escalate incidents with defensible evidence
  • Threat Hunters — who need a structured hypothesis-led method for finding adversary activity missed by alerts
  • Incident Responders — who must scope, contain and document active compromises under operational pressure
  • Detection Engineers — who need to convert ATT&CK techniques and investigation findings into reliable analytics
  • Cyber Security Engineers — who need to improve telemetry coverage, endpoint visibility and response workflows
  • Security Operations Managers — who need to assess hunting capability and prioritise investment in detection improvement

Requirements and prerequisites

Participants should have practical experience investigating security alerts in a SOC, CSIRT or security engineering role. They should understand TCP/IP, Windows event logging, basic Linux command-line use, Active Directory authentication, common attack stages and SIEM search concepts. Familiarity with KQL, SPL, EDR consoles or packet analysis is helpful because exercises use these ideas, but expert proficiency in every tool is not assumed. Participants should be comfortable reading process trees, log fields and IP or domain indicators. Malware reverse engineering, penetration-testing experience, programming and prior Velociraptor use are not required.

Training methodology

The five days alternate focused instructor demonstrations with analyst-led investigations in realistic telemetry sets. Participants formulate hunt hypotheses, search SIEM data, collect endpoint artefacts, build timelines and defend containment choices in small incident cells. Case work includes compromised credentials, suspicious PowerShell activity, lateral movement and cloud account misuse. The instructor reviews query logic, investigative pivots and reporting quality rather than simply confirming alerts. On the final day, participants convert findings into a tailored hunting pack, response playbook improvements and a 30-day implementation plan.

Course outline

Day 1: Threat hunting strategy and adversary tradecraft

  • Threat hunting maturity models and operating rhythms
  • Hypothesis-led hunting versus alert-driven investigation
  • MITRE ATT&CK tactic, technique and sub-technique mapping
  • Threat intelligence evaluation and adversary emulation inputs
  • Asset criticality and risk-based hunt prioritisation
  • Telemetry coverage mapping across endpoint, identity, network and cloud sources
  • Hunt documentation, evidence thresholds and closure criteria

Workshop: Participants create a prioritised hunt charter that maps three business-relevant adversary behaviours to available telemetry, assumptions and success criteria.

Day 2: Detection analytics and SIEM investigation

  • KQL query structure for Microsoft Sentinel investigations
  • SPL search patterns in Splunk Enterprise Security
  • Entity correlation across users, hosts, IP addresses and processes
  • Behavioural analytics for suspicious PowerShell and LOLBins
  • Authentication anomaly detection and impossible-travel validation
  • DNS, proxy and firewall telemetry for command-and-control analysis
  • Detection tuning with false-positive and coverage metrics

Workshop: Participants investigate a multi-source credential-abuse scenario and produce tuned KQL or SPL detections with documented exclusions and validation evidence.

Day 3: Endpoint hunting and forensic triage

  • Endpoint artefact triage and volatile-data priorities
  • Velociraptor collections, artefacts and targeted hunts
  • Windows process-tree analysis and parent-child anomalies
  • Persistence mechanisms in services, scheduled tasks and registry run keys
  • File-system timelines using MACB timestamps and execution artefacts
  • Lateral movement evidence in Windows event logs and remote execution traces
  • Chain-of-custody records and evidence preservation decisions

Workshop: Participants use a Velociraptor-led endpoint case to collect artefacts, build an attack timeline and identify the initial foothold and persistence mechanism.

Day 4: Incident scoping, containment and command

  • Incident severity assessment using business impact and adversary capability
  • Compromise scoping through identity, host and network pivots
  • Ransomware precursor behaviours and rapid containment priorities
  • Credential reset, host isolation and network-control decision trees
  • Incident command roles, technical workstreams and decision logs
  • Legal, privacy and regulatory considerations for evidence handling
  • Stakeholder communications for executives, IT operations and affected teams

Workshop: Teams run a timed ransomware-response tabletop, producing a scope statement, containment plan, decision log and executive situation update.

Day 5: Reporting, lessons learned and operational improvement

  • Attack narrative construction from fragmented technical evidence
  • Root-cause analysis and contributing-control failures
  • Executive incident reporting and impact communication
  • Detection-as-code review and analytic lifecycle management
  • Post-incident lessons-learned facilitation methods
  • Metrics for hunt yield, mean time to detect and mean time to contain
  • Thirty-day improvement roadmaps for detection and response operations

Workshop: Participants present a completed threat-hunting pack and incident report, then produce a 30-day roadmap with named owners, measures and implementation priorities.

Tools & standards covered

Microsoft Sentinel, Splunk Enterprise Security, Velociraptor, MITRE ATT&CK

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

This is an intermediate-to-advanced course for people who have already worked with alerts, logs or security investigations. You should understand core networking, Windows authentication and SIEM searching; the course builds advanced hunting and response practice on that foundation.

Bring a laptop capable of accessing the live-online lab environment or classroom exercises. Training datasets and guided access to the relevant tools are provided, so access to your employer's production SIEM or EDR is not required.

It is best suited to experienced SOC analysts, threat hunters, incident responders and detection engineers who need to investigate sophisticated activity. Security managers may also attend when they are responsible for improving operational detection and response capability.

A SOC analyst course usually concentrates on alert handling, while a digital forensics course may focus deeply on evidence acquisition and examination. This course connects proactive hunting, cross-source investigation, containment decisions and operational reporting into one advanced incident workflow.

The hunt hypotheses, ATT&CK mappings, query patterns and reporting templates can be adapted to your organisation's telemetry and priority threats. The final 30-day plan helps you convert the course work into specific detection, data-coverage and playbook changes.

You will leave with a tailored threat-hunting pack, including hypotheses, telemetry requirements, detection logic and investigation decision points. You will also complete an incident report template and an improvement roadmap suitable for discussion with your SOC or security leadership.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Kigali · USD 3,500
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Mombasa · USD 3,200
    Book
  • 26 – 30 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 02 – 06 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

CIS Controls v8 Implementation and Assessment Training Course

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…

5 Days Certificate

Palo Alto Cortex XSOAR Security Automation Playbooks Training Course

Security operations teams often lose critical time moving alerts between SIEM, EDR, threat-intelligence, ticketing and messaging tools. Anal…

5 Days Certificate

Kali Linux Penetration Testing Techniques Training Course

Security teams need evidence-based answers to practical questions: which systems are exposed, how an attacker could move from an initial foo…

5 Days Certificate

Splunk Enterprise Security SIEM Operations Training Course

Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…