Offensive Security
Official Training Partner

TH-200: Foundational Threat Hunting

Learn threat hunting basic concepts and skills, including using common tools like CrowdStrike Falcon and Splunk to detect network and endpoint Indicators of Compromise (IoCs) and ...


4.5

Successfully delivered 49 sessions for over 91 professionals

Get Course Details & Pricing

Our advisor will reach out within 24 hours

Your details are safe. We never share or sell your information.
Certification OSTH
Certification Body Offensive Security
Provided By OffSec

TH-200: Foundational Threat Hunting equips learners with the essential skills and mindset to operate on the defensive side of cybersecurity. In today’s threat landscape, defenders must go beyond reactive security measures. Threat hunting is a proactive practice where security professionals seek out and identify threats before they can cause harm.

This course introduces the core concepts, tools, and methodologies used by enterprise defenders to detect, track, and respond to adversaries within networks and endpoints.

Learners will develop key capabilities, including:

  • Understanding the threat actor landscape, with a focus on ransomware and Advanced Persistent Threats (APTs)
  • Utilizing both network and endpoint Indicators of Compromise (IoCs) for proactive threat detection
  • Highlighting the role of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), like Suricata, in monitoring for suspicious activities
  • Explorations of various ransomware groups, including LockBit, CLOP, and BlackCat/ALPHV, with examples of how they exploit specific vulnerabilities
  • Recognizing custom threat hunting, focusing on behavioral analysis and data correlation to detect advanced threats, using tools like CrowdStrike Falcon

TH-200 is organized into 7 modules with associated hands-on lab experiences and assessment questions. After completion of the content modules and labs, learners can work on a comprehensive Challenge Lab, which brings all of the skills they have learned in the course together and prepares them for the OSTH exam.

TH-200 is for anyone looking to build a strong foundation in threat hunting, including SOC analysts, IT security specialists, and those aiming to transition into specialized cybersecurity roles. While there are no course prerequisites, it is encouraged that learners have some experience in cybersecurity, a solid foundation in TCP/IP networking, and a familiarity with Linux and Windows operating systems.

Understand foundational concepts and practices of threat hunting
Analyze the threat actor landscape to identify potential risks
Learn to hunt for threats using network data and traffic analysis
Conduct endpoint-based threat hunting to detect malicious activity
Explore advanced hunting techniques without relying on indicators of compromise (IoCs)
Gain hands-on experience with CrowdStrike Falcon and Splunk tools
Create structured threat hunting strategies for enterprise environments

TH-200 is ideal for:

  • Individuals looking to build a strong foundation in threat hunting
  • Those aiming to transition into specialized security roles
  • SOC Analysts
  • IT Security Specialists

While there are no formal prerequisites, it’s strongly encouraged that you have:

  • A solid foundation in TCP/IP networking
  • Familiarity with Linux and Windows operating systems
  • Basic understanding of cybersecurity concepts

Up to 40 (ISC)² CPE credits.

Learn about the different stages and types of threat hunts that enterprises use through an overview of basic objectives, concepts, and practices

Get an overview of various threat actors, with a focus on ransomware groups and Advanced Persistent Threats (APTs), and review in-depth discussions of several well-known actors

Discover how threat hunters use the Traffic Light Protocol to receive and use threat intelligence to create reports

Use Network Indicators of Compromise (IoCs) with IDS/IPS tools like Suricata to monitor for suspicious activity, identify network compromises, and build practical threat-detection skills

Hunt for threats with Endpoint IoCs and use intelligence- and hypothesis-based approaches to make your hunts more effective

Hunt for threats without relying on known IoCs and focus on behavioral analysis and data correlation to detect advanced threats with tools like CrowdStrike Falcon

Course Pricing Options

Choose the package that best fits your learning goals and professional background

Slef Paced Learning - 90 Days Access

Access for 90 Days to full on-demand e-learning, labs + exam voucher

1,950 .00 / pax
+ 18% GST
1,950 .00 / member
+ 18% GST (Exclusive Member Rate)
1,950 .00 / partner
+ 18% GST (Affiliate Rate)

Self Paced Learning - 365 Days Access

Access for 365 Days to full ondemand e-learning,labs + exam voucher

3,000 .00 / pax
+ 18% GST
3,000 .00 / member
+ 18% GST (Exclusive Member Rate)
3,000 .00 / partner
+ 18% GST (Affiliate Rate)
Early Bird Incentive Reserve your seat 30 days before batch start to automatically claim an extra 5% discount.
Group & Team Training Claim an immediate 10% discount for corporate teams or small groups exceeding 3 participants.

Send Course Enquiry

Fill out the form and we will get back to you within 24 hours

Why Choose Profice?

Italy's Leading Training Partner with a Proven Track Record

Official Partner

Authorized Training Partner delivering official certified curriculum

Expert Instructors

Certified professionals with 10+ years of real-world experience

Hands-on Labs

Real-world projects and 24/7 lab environment access

95% Pass Rate

Industry-leading certification exam success rate

Job Assistance

Dedicated placement support with 500+ hiring partners

Lifetime Support

Ongoing mentorship and community access after course completion

Ready to Transform Your Career?

Join thousands of professionals who achieved their certification goals with Profice.

2,500+ Alumni 4.8 / 5 Rating 95% Pass Rate
🇮🇹

Sei Italiano?

Are you visiting from Italy?
We have a dedicated Italian website for you!