Threat Hunting Professional (THP) is an online, self-paced training course that provides the knowledge and skills to proactively hunt for threats in your environment, across networks and endpoints. THP will train you to develop a hunting mindset, using a range of modern hunting strategies to hunt various attack techniques. THP also comes with lifetime access to course materials and flexible access to the most advanced virtual labs in threat hunting.
Highly Practical
Try hunting for different threats using a variety of tools and techniques. THP includes the most advanced virtual lab in network security: Hera Lab.
The Course at a Glance
- Build a proactive defensive mindset
- Investigate threats across your organisation’s systems and network
- Use threat intelligence or hypotheses to hunt known and unknown threats
- Examine network traffic and identify anomalous activity within it
- Perform memory forensics using Redline, Volatility and other tools to identify in-memory malware
- Use tools such as Sysmon and SilkETW to collect event logs
- Detect advanced attack techniques such as AMSI bypasses, COM hijacking and sophisticated malware evasion
- Use tools such as PowerShell, ELK and Splunk to analyse Windows events and detect attacks such as DCSync, Kerberoasting and obfuscated PowerShell commands
- Access to private forums
Course Material
- HQ video training material
- Interactive slides
- Challenges in our industry-leading virtual labs
Course Delivery
- HTML5, PDF, MP4
- Offline access available
- Access from PC, tablet and smartphone
Curriculum
- Section: Threat Hunting
Module 1: Introduction to Threat Hunting
In this module you will take your first dive into the world of threat hunting and learn what threat hunting is and what it is not. You will also learn how threat hunting relates to incident response and risk assessments.
Module 2: Threat Hunting Terminology
This module introduces a range of threat hunting terms. You will learn how to distinguish between a mindset that is largely driven by threat intelligence during hunts and one that uses digital forensic techniques and artefacts.
Module 3: Threat Intelligence
In this module we will make use of threat intelligence, covering how to obtain threat intelligence reports and the latest research you can draw on during hunts. We will also address the different threat sharing platforms and exchanges. Finally, we will look at Indicators of Compromise (IOCs), where you will learn how to build and use them in your hunts with Redline and YARA.
Module 4: The Threat Hunting Hypothesis
You would not be expected to start hunting without a plan. In this module you will learn the MITRE ATT&CK framework and the data collection and analysis needed to conduct successful hunts. You will also learn the recommended steps for starting a hunt, how to form hypotheses in a five-step process, and how to run hunts based on them. Finally, we will address the hunting metrics you can use to assess hunting activity within an organisation.
Section: Network Hunting — Network Analysis
Module 1: Introduction to Network Hunting
In this module we will cover networking fundamentals as a baseline, along with the TCP/IP stack, packets, protocols, network equipment and the tools required to inspect network traffic.
Module 2: Hunting for Suspicious Traffic
In this module we will look at each protocol individually. We will look at what is normal for a given protocol and what is not, which will help us identify the abuse of that protocol for malicious purposes.
Module 3: Web Shell Hunting
In this module we will look at a range of common and rare web shells. We will also look at tools and techniques, such as Loki, that help us hunt for web shells in our environments.
Section: Endpoint Hunting — Endpoint Analysis
Module 1: Introduction to Endpoint Hunting
In this module we will look at core Windows processes. We will examine the normal behaviour of these processes and the indicators that show when a process is being misused to conceal illegitimate activity. The importance of baselines, which we can use to flag changes on a given system, is also addressed.
Module 2: Malware Overview
In this module we will look at malware. We will discuss the different classifications of malware and the various techniques malware uses to infect our systems; in addition, we will examine how malware attempts to evade detection and establish persistence.
Module 3: Malware Hunting
In this module we will look at and discuss hunting tools, memory analysis and how to use different tools such as Redline and Volatility to identify the memory structures of attack tools and hunt for in-memory malware. We will dive into specific injection techniques and use multiple memory hunting techniques to identify them.
Module 4: Event IDs, Logging and SIEMs
In this module we will look at event logs. We will discuss what event logs are, as well as the important event IDs to monitor in order to detect particular activity in your environment. We will also look at tools such as Sysmon and PowerShell logging that extend traditional Windows logging capabilities. In addition, we will discuss and investigate advanced techniques such as unmanaged PowerShell, COM hijacking and .NET malware. Finally, we will look at how we can use tools such as the ELK stack and Splunk to assist us during hunts.
Module 5: Hunting with PowerShell
In this module we will discuss how to use PowerShell while hunting, and look at some of the existing PowerShell frameworks built specifically for incident response and threat hunting. We will also look at Microsoft Advanced Threat Analytics and Azure Advanced Threat Protection, which offer automated detection capabilities.
Prerequisites
- A solid understanding of computer networks: switches, routing, security devices, common network protocols and so on (recommended)
- An intermediate understanding of IT security topics
- An intermediate to advanced understanding of penetration testing tools and methods (recommendation: the IHRP course)
Who Can Attend
- Security operations centre analysts and engineers
- Penetration testers and red team members
- Network security engineers
- Incident response team members
- Information security consultants and IT auditors
- Managers wanting to understand how to build threat hunting teams and intelligence capabilities
Laboratuvarlar
The THP course is a practice-based curriculum with 27 hands-on labs. Integrated with Hera Lab, the most advanced virtual lab in IT security, this product offers an unmatched practical learning experience. Hera is the only virtual lab that provides each student with fully isolated access to every one of the real-world network scenarios available on the platform. Students can access Hera Lab from anywhere over VPN. The modules are accompanied by numerous hands-on labs.
Lab 1: Hunting with IoCs — Another organisation in your ISAC has shared a malicious binary with your security team. They noted that this malware was detected by one of their threat hunters. The malware was found inside various network shares within the organisation, disguising itself as a PDF file. Your manager has tasked you with building an IOC and a YARA rule to scan the network for this malware.
Lab 2: Hunting Insiders Part 1 — You are placed on a weekly hunting schedule. Using hypothesis-based hunting, you want to hunt for insider threat activity. You decide to capture network traffic from various subnets and are asked to review some daily PCAP files.
Lab 3: Hunting Insiders Part 2 — You and Charles became aware a few days ago that there are two rogue machines on the network. After speaking with management, you and Charles convince them to let you monitor the threats the next time you find them on the network, rather than eliminating them outright, because you need to learn more about these threat actors, who appear to be malicious insiders. You have multiple IOCs and are taking full packet captures to see whether there is any evidence of this malware on the network. You are now hunting based on intelligence, but remember that an adversary can change their methods — keep that in mind as you hunt.
Lab 4: Network Hunting and Forensics (NEW!) — In this lab you will practise hunting for suspicious network connections and communication. Zeek, RITA and Wireshark will be used to analyse multiple samples of malicious traffic.
Lab 5: Web Shell Hunting Part 1 — Your manager Tony sets you a hunting schedule. Once a week you need to review web servers, including those in the DMZ, for signs of suspicious activity. Your task in this lab is to look for any indication of a web shell in network traffic and on the web server.
Lab 6: Web Shell Hunting Part 2 — Your manager Tony wants to make sure you can catch even those web shells that cannot be detected by previously used tools such as LOKI, which can only detect PHP-based web shells. Tony knows this and has planned a hunting exercise to find one or more ASP and/or ASPX-based shells on an IIS server.
Lab 7: Hunting in Memory (NEW!) — Lab 1: The organisation you work for wants you to conduct a memory threat hunt on a randomly selected machine. As a hunting exercise to keep you sharp, the IT security manager has tasked you specifically with looking for anomalous connections and memory injections. Lab 2: The organisation also wants you to conduct a memory threat hunt on a Linux machine. As a hunting exercise to keep you sharp, the IT security manager has tasked you specifically with looking for the presence of Linux rootkits.
Lab 8: Hunting for Process Injection and Proactive API Monitoring (NEW!) — Attackers like to hide and inject malicious code into processes. In this lab you will learn how to hunt for various process injection techniques and how to use userland API monitoring for more effective hunts.
Lab 9: Advanced Endpoint Hunting (NEW!) — Within THP you will find two separate labs on advanced hacking techniques in endpoint-level hunting. Specifically: process doppelgänging, AMSI bypasses, parent PID spoofing, reflective DLL injection, module stomping and more.
Lab 10: Malware Hunting Part 1 — Your manager Tony wants you to take a look at the machine belonging to the CFO’s executive assistant. Email logs show a sudden increase in spam emails attempting to reach that address. Although she has completed the security awareness class, Tony does not want to take any chances. Tony gives you a Mandiant analysis file to load into Redline and see whether anything suspicious is running.
Lab 11: Malware Hunting Part 2 — Your manager Tony has received two memory files from another facility within the ISAC. These two memory files come from real incidents that occurred at their facility a few years ago. Tony wants you to analyse them to see whether you can identify any signs of code injection and/or a rootkit, in preparation for detecting APT attacks.
Lab 12: Hunting Empire — Your manager Tony wants to be sure you can detect Empire, a widely used attack tool. A hunting exercise has been planned in which you are tasked with detecting the presence of Empire on an endpoint.
Lab 13: Hunting Responder — Your manager Tony wants to be sure you can detect Responder, the widely used LLMNR, NBT-NS and MDNS poisoning tool. After a recent penetration test, Tony was also informed that a PowerShell-based Responder variant called Inveigh is being used in the wild. A hunting exercise has been planned in which you are tasked with detecting the presence of Responder or Inveigh on the network.