Prioritise hunt hypotheses using MITRE ATT&CK Navigator coverage gaps and threat intelligence.
Threat Hunting Techniques Using the MITRE ATT&CK Framework
Teaches hypothesis-driven threat hunting mapped to the MITRE ATT&CK matrix, from telemetry analysis and adversary emulation to detection creation.
Course Overview
Waiting for an alert to fire assumes the adversary will trigger one, and skilled intruders spend considerable effort making sure they do not. This course teaches hypothesis-driven threat hunting structured around the MITRE ATT&CK framework: identifying which tactics and techniques current detection coverage misses, then actively searching telemetry for evidence of their use. Participants learn to use the ATT&CK Navigator to prioritise hunts, query endpoint and network telemetry for living-off-the-land and lateral movement activity, and validate whether existing tooling would actually catch a given technique using adversary emulation. Sessions cover translating threat intelligence into specific hunt hypotheses, writing clear findings reports, and converting successful manual hunts into permanent automated detections. Practical exercises include mapping a sample environment's coverage gaps on the ATT&CK matrix, running a hunting query against provided telemetry data, and emulating a known technique to test detection visibility. Participants leave with a hunting methodology template and a coverage tracking model for their own environment.
Expected Learning Outcomes
Formulate testable hunt hypotheses that target specific adversary tactics and techniques.
Query endpoint and network telemetry to identify living-off-the-land and lateral movement activity.
Validate detection coverage using adversary emulation before relying on it operationally.
Convert successful manual hunt queries into permanent, automated detection rules.
Write hunt findings reports that document hypothesis, method, evidence and outcome clearly.
Report threat hunting programme value through coverage growth and significant findings.
Who Should Attend
Threat hunters and detection engineers building a hypothesis-driven hunting practice.
SOC analysts moving from alert triage into proactive threat hunting roles.
Incident responders who need structured hunting techniques for post-incident sweeps.
Threat intelligence analysts translating adversary reporting into hunting priorities.
Security engineers validating detection coverage through adversary emulation.
Security leaders scoping and measuring a threat hunting programme's return.
Course Modules
Select any module to see its sessions and points.
01Foundations of Hypothesis-Driven Threat Hunting
2 sessions · 8 points
Session 1From Reactive Detection to Proactive Hunting
- Distinguish hypothesis-driven hunting from alert-driven detection and incident response.
- Apply the Pyramid of Pain to prioritise hunts that target adversary tactics over easily changed indicators.
- Assess organisational hunting maturity against a recognised model before scoping a programme.
- Define which data sources and retention periods a given hunt hypothesis requires.
Session 2Structuring Hunts Around the MITRE ATT&CK Matrix
- Use the ATT&CK Navigator to map current detection coverage against tactics and techniques.
- Prioritise hunt hypotheses that target techniques with the weakest existing detection coverage.
- Translate a chosen technique and sub-technique into a specific, testable hunt hypothesis.
- Document assumptions and expected evidence in writing before beginning the hunt.
02Gathering and Analysing Hunting Telemetry
2 sessions · 8 points
Session 1Endpoint Telemetry and Living-off-the-Land Detection
- Query endpoint detection and response telemetry for process and parent-child relationships.
- Identify living-off-the-land technique abuse of legitimate administrative tools.
- Baseline normal administrative activity to isolate genuinely anomalous behaviour.
- Correlate endpoint findings with authentication logs to confirm suspected compromise.
Session 2Network Telemetry and Query-Based Analysis
- Analyse network telemetry for command-and-control and lateral movement patterns.
- Write hunting queries in common query languages against large telemetry datasets.
- Pivot between endpoint and network data sources to build a complete activity timeline.
- Distinguish benign anomalies from genuine indicators of adversary technique use.
03Threat Intelligence and Adversary Emulation
2 sessions · 8 points
Session 1Driving Hunts with Threat Intelligence
- Translate threat intelligence on relevant adversary groups into specific ATT&CK technique hypotheses.
- Prioritise hunts by the threat actors and campaigns most relevant to the organisation's sector.
- Distinguish durable tactic and technique intelligence from perishable indicators of compromise.
- Incorporate sector-specific threat landscape changes into hunt cadence and prioritisation.
Session 2Validating Hunts Through Adversary Emulation
- Use adversary emulation tooling to generate known technique activity for testing.
- Confirm whether existing telemetry and queries would actually detect the emulated technique.
- Identify visibility gaps exposed by emulation that no amount of querying can overcome.
- Schedule recurring emulation to confirm hunts remain effective as environments change.
04Reporting, Automating and Measuring Hunt Value
2 sessions · 8 points
Session 1Converting Hunt Findings into Permanent Detections
- Write findings reports documenting hypothesis, method, evidence and outcome for each hunt.
- Convert successful manual hunt queries into automated, permanently running detection rules.
- Feed newly identified gaps back into the detection engineering and SOC backlog.
- Share hunt methodology and results with peer teams to build organisational hunting capability.
Session 2Demonstrating Threat Hunting Programme Value
- Track hunts completed, techniques covered and detections generated as core programme metrics.
- Report coverage improvement against the ATT&CK matrix over successive quarters.
- Present a small number of significant findings to leadership in business impact terms.
- Build a prioritised backlog of future hunts based on residual coverage gaps and threat shifts.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
