TH-200: Foundational Threat Hunting
Learn threat hunting basic concepts and skills, including using common tools like CrowdStrike Falcon and Splunk to detect network and endpoint Indicators of Compromise (IoCs) and ...
- Learn threat hunting basic concepts and skills, including using common tools like CrowdStrike Falcon and Splunk to detect network and endpoint Indicators of Compromise (IoCs) and respond to threats
- Earn the OffSec Threat Hunter (OSTH) certification upon passing the exam
Get Course Details & Pricing
Our advisor will reach out within 24 hours
Enquiry Received!
Thank you! One of our training advisors will contact you within 24 hours with full details and a personalised quote.
TH-200: Foundational Threat Hunting equips learners with the essential skills and mindset to operate on the defensive side of cybersecurity. In today’s threat landscape, defenders must go beyond reactive security measures. Threat hunting is a proactive practice where security professionals seek out and identify threats before they can cause harm.
This course introduces the core concepts, tools, and methodologies used by enterprise defenders to detect, track, and respond to adversaries within networks and endpoints.
Learners will develop key capabilities, including:
- Understanding the threat actor landscape, with a focus on ransomware and Advanced Persistent Threats (APTs)
- Utilizing both network and endpoint Indicators of Compromise (IoCs) for proactive threat detection
- Highlighting the role of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), like Suricata, in monitoring for suspicious activities
- Explorations of various ransomware groups, including LockBit, CLOP, and BlackCat/ALPHV, with examples of how they exploit specific vulnerabilities
- Recognizing custom threat hunting, focusing on behavioral analysis and data correlation to detect advanced threats, using tools like CrowdStrike Falcon
TH-200 is organized into 7 modules with associated hands-on lab experiences and assessment questions. After completion of the content modules and labs, learners can work on a comprehensive Challenge Lab, which brings all of the skills they have learned in the course together and prepares them for the OSTH exam.
TH-200 is for anyone looking to build a strong foundation in threat hunting, including SOC analysts, IT security specialists, and those aiming to transition into specialized cybersecurity roles. While there are no course prerequisites, it is encouraged that learners have some experience in cybersecurity, a solid foundation in TCP/IP networking, and a familiarity with Linux and Windows operating systems.
TH-200 is ideal for:
- Individuals looking to build a strong foundation in threat hunting
- Those aiming to transition into specialized security roles
- SOC Analysts
- IT Security Specialists
While there are no formal prerequisites, it’s strongly encouraged that you have:
- A solid foundation in TCP/IP networking
- Familiarity with Linux and Windows operating systems
- Basic understanding of cybersecurity concepts
Up to 40 (ISC)² CPE credits.
Learn about the different stages and types of threat hunts that enterprises use through an overview of basic objectives, concepts, and practices
Get an overview of various threat actors, with a focus on ransomware groups and Advanced Persistent Threats (APTs), and review in-depth discussions of several well-known actors
Discover how threat hunters use the Traffic Light Protocol to receive and use threat intelligence to create reports
Use Network Indicators of Compromise (IoCs) with IDS/IPS tools like Suricata to monitor for suspicious activity, identify network compromises, and build practical threat-detection skills
Hunt for threats with Endpoint IoCs and use intelligence- and hypothesis-based approaches to make your hunts more effective
Hunt for threats without relying on known IoCs and focus on behavioral analysis and data correlation to detect advanced threats with tools like CrowdStrike Falcon
Course Pricing Options
Choose the package that best fits your learning goals and professional background
Slef Paced Learning - 90 Days Access
Access for 90 Days to full on-demand e-learning, labs + exam voucher
Self Paced Learning - 365 Days Access
Access for 365 Days to full ondemand e-learning,labs + exam voucher
Send Course Enquiry
Fill out the form and we will get back to you within 24 hours
Why Choose Profice?
Italy's Leading Training Partner with a Proven Track Record
Official Partner
Authorized Training Partner delivering official certified curriculum
Expert Instructors
Certified professionals with 10+ years of real-world experience
Hands-on Labs
Real-world projects and 24/7 lab environment access
95% Pass Rate
Industry-leading certification exam success rate
Job Assistance
Dedicated placement support with 500+ hiring partners
Lifetime Support
Ongoing mentorship and community access after course completion
Ready to Transform Your Career?
Join thousands of professionals who achieved their certification goals with Profice.