This course teaches you the necessary skills to becoming a successful threat hunter. As you progress through the modules, you'll build core hunting skills such as intelligence gathering, investigation techniques and remediation methods. Upon completion, you'll have the knowledge and skills to carry out cyber threat hunting activities with an organization that will ultimately deliver proactive defenses against possible debilitating data compromise.
In this introductory module with Keatron Evans, you'll explore cyber threat hunting: defining it, skills required, hunt modeling with hypotheses, implementation benefits and more.
What's included
5 videos
Show info about module content
5 videos•Total 32 minutes
Course and instructor introduction•6 minutes
What is cyber threat hunting?•11 minutes
Implementation considerations•4 minutes
Threat hunting models•6 minutes
Benefits of threat hunting•6 minutes
Threat hunting artifacts and types
Module 2•1 hour to complete
Module details
In this module, you'll explore what's needed for a really effective threat-hunting program. You'll also learn about artifacts, indicators of compromise, tactics, techniques and procedures, the Pyramid of Pain and many more insights from Keatron.
What's included
4 videos
Show info about module content
4 videos•Total 40 minutes
Introduction to artifacts and indicators of compromise (IOCs)•4 minutes
Artifacts and types•13 minutes
Indicators of compromise•12 minutes
Tactics, techniques and procedures (TTPs)•11 minutes
Threat hunting techniques and generative AI
Module 3•1 hour to complete
Module details
Explore the concepts of anomalous activity and investigation. The purpose of this module is to help the threat hunter identify whether an anomalous activity is a threat. Explore how to investigate, walking through the information and identifying any issues right away. In this course, Keatron uses generative AI to quickly find malicious activity.
What's included
6 videos
Show info about module content
6 videos•Total 41 minutes
Introduction to techniques•4 minutes
Aggregation of data sources•6 minutes
Anomalies and baselining•5 minutes
Grouping and clustering with AI•9 minutes
Generative AI in threat hunting•6 minutes
Generative AI in practice demo•10 minutes
Threat hunting methodologies
Module 4•28 minutes to complete
Module details
In this module, you'll explore the differences between structured and unstructured hunts with Keatron. You will also get into entity-driven hunting.
What's included
4 videos
Show info about module content
4 videos•Total 28 minutes
Introduction to methodologies•4 minutes
Structured hunting (MITRE)•10 minutes
Unstructured hunting•6 minutes
Entity driven hunting•7 minutes
Threat hunting data and technologies
Module 5•1 hour to complete
Module details
In this course, Keatron will take you through different data sources that you may hunt through. These include SIEMs, EDR and XDR logs, threat intelligence platforms and several other data sources.
What's included
6 videos
Show info about module content
6 videos•Total 37 minutes
Data and technologies•6 minutes
Network data•10 minutes
Endpoint data•7 minutes
Security information and event management (SIEM)•5 minutes
Threat intelligence platforms•5 minutes
Ticketing/SOAR•3 minutes
Cyber threat hunting process
Module 6•24 minutes to complete
Module details
In this course, you will learn how to build a hunt. Keatron gets into the details of all the things the learner must consider when building out a hunt and scoping. We also discuss lessons learned and proper execution.
What's included
4 videos
Show info about module content
4 videos•Total 24 minutes
Threat hunting process introduction•5 minutes
Scoping and hypothesis development•9 minutes
Execution•6 minutes
Cyber threat hunting: Lessons learned•4 minutes
Cyber threat hunting scenarios
Module 7•1 hour to complete
Module details
In this course, you'll see how different threat hunting scenarios play out. We will use real-world examples to illustrate how we form a hypothesis all the way through lessons learned.
What's included
4 videos
Show info about module content
4 videos•Total 32 minutes
Structured hunt scenario•10 minutes
Unstructured hunt scenario•10 minutes
Entity-driven hunt scenario•7 minutes
Situation-driven hunt scenario•5 minutes
Hunting for network-based threats
Module 8•1 hour to complete
Module details
In this course, we will go on a deep dive with Keatron concerning network-based threats, including DNS, DDoS and irregular traffic, plus more. This course will include some labs and demonstrations. Locate even the hardest-to-find malware with these techniques.
What's included
5 videos
Show info about module content
5 videos•Total 35 minutes
Network threats •6 minutes
DNS abnormalities •7 minutes
Hunting for (distributed-denial-of-service) DDoS activity•5 minutes
Hunting for suspicious domains•9 minutes
Hunting for irregular traffic•8 minutes
Hunting for host-based threats
Module 9•4 hours to complete
Module details
In this course, Keatron will walk through various host-based threats and indicators. There will be labs and demonstrations that include memory forensics, PowerShell and Windows event log parsing.
What's included
9 videos1 assignment
Show info about module content
9 videos•Total 72 minutes
Host-based threats•5 minutes
Malware•6 minutes
Hunting for irregular processes•6 minutes
Detecting lateral movement•10 minutes
Hunting for malicious files•9 minutes
Database swells•8 minutes
Host triage•10 minutes
Finding a well-hidden rootkit•11 minutes
Using VirusTotal for validation•7 minutes
1 assignment•Total 180 minutes
End of course assessment•180 minutes
Instructor
Instructor ratings
Instructor ratings
We asked all learners to give feedback on our instructors based on the quality of their teaching style.
Infosec believes knowledge is power when fighting cybercrime. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and privacy training to stay cyber-safe at work and home. Learn more at infosecinstitute.com.
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."
Jennifer J.
Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."
Larry W.
Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."
Chaitanya A.
"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."
Learner reviews
4.5
139 reviews
5 stars
69.78%
4 stars
21.58%
3 stars
2.87%
2 stars
0%
1 star
5.75%
Showing 3 of 139
M
MZ
5·
Reviewed on Feb 15, 2024
Principles were broken down well, easy to follow, good content.
M
MZ
5·
Reviewed on Jan 31, 2025
The course outline is precisely concise, to-the-point and very effective. Instructor's content delivery method is very effective. I highly appreciate the entire course.
G
GG
4·
Reviewed on Apr 19, 2024
This is a good course on process, procedure and the importance of Threat Hunting. I really enjoyed it.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.