Advanced Cyber Threat Hunting and Incident Response Training Course
| Course code | SD-CS-002 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitimate credentials, living-off-the-land binaries, cloud administration tools and short-lived infrastructure that does not trigger simple signature-based alerts. This course prepares experienced analysts to turn ambiguous signals across endpoint, network, identity and cloud data into evidence-led hunting hypotheses, validated findings and defensible incident decisions.
Participants work through a repeatable threat-hunting and incident-response workflow: mapping adversary behaviour to MITRE ATT&CK, baselining normal activity, writing behavioural detections, pivoting across SIEM and endpoint telemetry, and scoping compromise. They investigate credential theft, command-and-control, lateral movement, persistence, ransomware precursors and cloud account abuse using Microsoft Sentinel, Splunk Enterprise Security and Velociraptor. The course also covers evidence handling, host triage, containment choices, incident command, executive reporting and lessons-learned improvements.
Delivery combines instructor-led technical briefings with guided investigations using realistic attack data and analyst playbooks. Each participant develops a threat-hunting pack containing prioritised hypotheses, data-source requirements, ATT&CK mappings, query logic, investigation decision points and incident-report templates tailored to their own environment. They leave with a practical 30-day improvement plan for their detection and response function, plus a certificate on completion. The course is designed for practitioners who already understand core SOC monitoring and need to lead higher-confidence investigations.
Course objectives
By the end of this course, participants will be able to:
- Construct risk-prioritised threat-hunting hypotheses from threat intelligence, asset context and MITRE ATT&CK techniques
- Map endpoint, identity, network and cloud telemetry to attacker behaviours and identify visibility gaps
- Write and tune behavioural detection queries in Microsoft Sentinel and Splunk Enterprise Security
- Investigate suspicious endpoint activity with Velociraptor artefact collection and timeline analysis
- Correlate authentication, process, DNS and network evidence to scope lateral movement and persistence
- Apply an incident triage and containment decision model that preserves evidence and limits business disruption
- Produce an executive-ready incident report with attack narrative, impact assessment, remediation actions and lessons learned
- Build a 30-day threat-hunting improvement plan with measurable detection, telemetry and playbook priorities
Benefits of attending
For you
- Gain a repeatable hunting methodology for moving from threat intelligence to validated findings
- Build credibility as an investigator who can explain technical evidence and business impact to incident leaders
- Develop practical query, triage and scoping skills applicable to senior SOC and incident-response roles
- Create a portfolio-ready threat-hunting pack and incident report that demonstrate advanced operational capability
- Improve judgement on when to contain, collect evidence, escalate or close an investigation
For your organisation
- Reduce attacker dwell time by improving analysts' ability to detect behaviour beyond rule-based alerts
- Increase investigation consistency through documented hypotheses, evidence standards and escalation decisions
- Identify telemetry blind spots across identity, endpoint, network and cloud monitoring before an incident exposes them
- Improve containment decisions by balancing evidence preservation, operational impact and attack progression
- Provide management with clearer incident narratives, remediation priorities and measurable detection-improvement actions
Target competencies
Who should attend
- Senior SOC Analysts — who need to investigate weak signals and escalate incidents with defensible evidence
- Threat Hunters — who need a structured hypothesis-led method for finding adversary activity missed by alerts
- Incident Responders — who must scope, contain and document active compromises under operational pressure
- Detection Engineers — who need to convert ATT&CK techniques and investigation findings into reliable analytics
- Cyber Security Engineers — who need to improve telemetry coverage, endpoint visibility and response workflows
- Security Operations Managers — who need to assess hunting capability and prioritise investment in detection improvement
Requirements and prerequisites
Participants should have practical experience investigating security alerts in a SOC, CSIRT or security engineering role. They should understand TCP/IP, Windows event logging, basic Linux command-line use, Active Directory authentication, common attack stages and SIEM search concepts. Familiarity with KQL, SPL, EDR consoles or packet analysis is helpful because exercises use these ideas, but expert proficiency in every tool is not assumed. Participants should be comfortable reading process trees, log fields and IP or domain indicators. Malware reverse engineering, penetration-testing experience, programming and prior Velociraptor use are not required.
Training methodology
The five days alternate focused instructor demonstrations with analyst-led investigations in realistic telemetry sets. Participants formulate hunt hypotheses, search SIEM data, collect endpoint artefacts, build timelines and defend containment choices in small incident cells. Case work includes compromised credentials, suspicious PowerShell activity, lateral movement and cloud account misuse. The instructor reviews query logic, investigative pivots and reporting quality rather than simply confirming alerts. On the final day, participants convert findings into a tailored hunting pack, response playbook improvements and a 30-day implementation plan.
Course outline
Day 1: Threat hunting strategy and adversary tradecraft
- Threat hunting maturity models and operating rhythms
- Hypothesis-led hunting versus alert-driven investigation
- MITRE ATT&CK tactic, technique and sub-technique mapping
- Threat intelligence evaluation and adversary emulation inputs
- Asset criticality and risk-based hunt prioritisation
- Telemetry coverage mapping across endpoint, identity, network and cloud sources
- Hunt documentation, evidence thresholds and closure criteria
Workshop: Participants create a prioritised hunt charter that maps three business-relevant adversary behaviours to available telemetry, assumptions and success criteria.
Day 2: Detection analytics and SIEM investigation
- KQL query structure for Microsoft Sentinel investigations
- SPL search patterns in Splunk Enterprise Security
- Entity correlation across users, hosts, IP addresses and processes
- Behavioural analytics for suspicious PowerShell and LOLBins
- Authentication anomaly detection and impossible-travel validation
- DNS, proxy and firewall telemetry for command-and-control analysis
- Detection tuning with false-positive and coverage metrics
Workshop: Participants investigate a multi-source credential-abuse scenario and produce tuned KQL or SPL detections with documented exclusions and validation evidence.
Day 3: Endpoint hunting and forensic triage
- Endpoint artefact triage and volatile-data priorities
- Velociraptor collections, artefacts and targeted hunts
- Windows process-tree analysis and parent-child anomalies
- Persistence mechanisms in services, scheduled tasks and registry run keys
- File-system timelines using MACB timestamps and execution artefacts
- Lateral movement evidence in Windows event logs and remote execution traces
- Chain-of-custody records and evidence preservation decisions
Workshop: Participants use a Velociraptor-led endpoint case to collect artefacts, build an attack timeline and identify the initial foothold and persistence mechanism.
Day 4: Incident scoping, containment and command
- Incident severity assessment using business impact and adversary capability
- Compromise scoping through identity, host and network pivots
- Ransomware precursor behaviours and rapid containment priorities
- Credential reset, host isolation and network-control decision trees
- Incident command roles, technical workstreams and decision logs
- Legal, privacy and regulatory considerations for evidence handling
- Stakeholder communications for executives, IT operations and affected teams
Workshop: Teams run a timed ransomware-response tabletop, producing a scope statement, containment plan, decision log and executive situation update.
Day 5: Reporting, lessons learned and operational improvement
- Attack narrative construction from fragmented technical evidence
- Root-cause analysis and contributing-control failures
- Executive incident reporting and impact communication
- Detection-as-code review and analytic lifecycle management
- Post-incident lessons-learned facilitation methods
- Metrics for hunt yield, mean time to detect and mean time to contain
- Thirty-day improvement roadmaps for detection and response operations
Workshop: Participants present a completed threat-hunting pack and incident report, then produce a 30-day roadmap with named owners, measures and implementation priorities.
Tools & standards covered
Microsoft Sentinel, Splunk Enterprise Security, Velociraptor, MITRE ATT&CK
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Dar es Salaam · USD 3,500 -
28 Sep – 02 Oct 2026Book
Kigali · USD 3,500 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Mombasa · USD 3,200 -
26 – 30 Oct 2026Book
Dar es Salaam · USD 3,500 -
02 – 06 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
CIS Controls v8 Implementation and Assessment Training Course
Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evide…
Palo Alto Cortex XSOAR Security Automation Playbooks Training Course
Security operations teams often lose critical time moving alerts between SIEM, EDR, threat-intelligence, ticketing and messaging tools. Anal…
Kali Linux Penetration Testing Techniques Training Course
Security teams need evidence-based answers to practical questions: which systems are exposed, how an attacker could move from an initial foo…
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…