Citadock Practical Academy
Threat Hunting
Go beyond reactive monitoring to proactively search for threats. Learn hypothesis-driven hunting methodologies, advanced log analysis techniques, attacker behaviour patterns, how to identify detection opportunities, and how to document findings for operational improvement.
Threat HuntingMITRE ATT&CKLog AnalysisDetection EngineeringHypothesis Testing
Cohort Specifics
Cohort Size
Small batch (max 20) for personalized mentor guidance
Format & Delivery
Scheduled live batches delivered online and in person, with emphasis on hands-on hunting exercises using realistic datasets and scenarios.
Verification
Verifiable portfolio projects & capstone validation
Who Is This Program For?
- ✓SOC analysts ready to advance into proactive threat hunting
- ✓Security professionals seeking advanced investigative skills
- ✓Practitioners interested in detection engineering
Core Learning Objectives
Develop and test threat hunting hypotheses
Apply advanced log analysis and correlation techniques
Understand attacker behaviour patterns and TTPs
Identify gaps in detection coverage
Create new detection opportunities from hunting findings
Document and communicate hunting results effectively
Curriculum Breakdown
01Threat hunting fundamentals and methodologies
02Hypothesis-driven hunting approaches
03Advanced log analysis and data exploration
04Attacker behaviour and tactics (MITRE ATT&CK)
05Detection gap analysis
06Building detection rules from hunting findings
07Hunting in different environments (endpoint, network, cloud)
08Documenting and reporting hunting activities
Practical Lab Exercises & Scenarios
Applied Engineering Labs
>Develop and execute a hunting hypothesis
>Analyse complex log data for indicators of compromise
>Map attacker behaviour to MITRE ATT&CK techniques
>Create detection rules from hunting discoveries
>Document a complete hunting engagement
Prerequisites
- •Understanding of SOC operations and security monitoring
- •Experience with log analysis
- •Familiarity with common security tools
Course FAQs
This course assumes foundational SOC knowledge. We recommend completing the SOC Analyst track or having equivalent experience first.
The course uses realistic datasets and lab environments designed to simulate real-world hunting scenarios.
Apply for this Course
Speak directly with a Citadock course mentor to confirm batch schedules, prerequisites, and syllabus details.
Complementary Tracks
SOC Analyst
Develop core security operations skills including monitoring, alert triage, log analysis, investigation workflows, and incident handling.
Cyber Threat Intelligence
Learn the intelligence lifecycle, indicators of compromise, OSINT fundamentals, threat enrichment, and how to apply intelligence to defensive operations.
AI & Security Automation
Automate security workflows, reduce repetitive tasks, leverage AI-assisted analysis, and build efficient security integrations with human oversight.