Citadock Practical Academy

Threat Hunting

Go beyond reactive monitoring to proactively search for threats. Learn hypothesis-driven hunting methodologies, advanced log analysis techniques, attacker behaviour patterns, how to identify detection opportunities, and how to document findings for operational improvement.

Threat HuntingMITRE ATT&CKLog AnalysisDetection EngineeringHypothesis Testing
Cohort Specifics
Cohort Size
Small batch (max 20) for personalized mentor guidance
Format & Delivery
Scheduled live batches delivered online and in person, with emphasis on hands-on hunting exercises using realistic datasets and scenarios.
Verification
Verifiable portfolio projects & capstone validation

Who Is This Program For?

  • ✓SOC analysts ready to advance into proactive threat hunting
  • ✓Security professionals seeking advanced investigative skills
  • ✓Practitioners interested in detection engineering

Core Learning Objectives

Develop and test threat hunting hypotheses
Apply advanced log analysis and correlation techniques
Understand attacker behaviour patterns and TTPs
Identify gaps in detection coverage
Create new detection opportunities from hunting findings
Document and communicate hunting results effectively

Curriculum Breakdown

01Threat hunting fundamentals and methodologies
02Hypothesis-driven hunting approaches
03Advanced log analysis and data exploration
04Attacker behaviour and tactics (MITRE ATT&CK)
05Detection gap analysis
06Building detection rules from hunting findings
07Hunting in different environments (endpoint, network, cloud)
08Documenting and reporting hunting activities

Practical Lab Exercises & Scenarios

Applied Engineering Labs
>Develop and execute a hunting hypothesis
>Analyse complex log data for indicators of compromise
>Map attacker behaviour to MITRE ATT&CK techniques
>Create detection rules from hunting discoveries
>Document a complete hunting engagement

Prerequisites

  • •Understanding of SOC operations and security monitoring
  • •Experience with log analysis
  • •Familiarity with common security tools

Course FAQs

This course assumes foundational SOC knowledge. We recommend completing the SOC Analyst track or having equivalent experience first.
The course uses realistic datasets and lab environments designed to simulate real-world hunting scenarios.
Apply for this Course

Speak directly with a Citadock course mentor to confirm batch schedules, prerequisites, and syllabus details.

🔒 Citadock Security maintains strict confidentiality. We never sell your data or spam your inbox.