Information & Communications Technology

Threat Hunting Techniques Using the MITRE ATT&CK Framework

Teaches hypothesis-driven threat hunting mapped to the MITRE ATT&CK matrix, from telemetry analysis and adversary emulation to detection creation.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Waiting for an alert to fire assumes the adversary will trigger one, and skilled intruders spend considerable effort making sure they do not. This course teaches hypothesis-driven threat hunting structured around the MITRE ATT&CK framework: identifying which tactics and techniques current detection coverage misses, then actively searching telemetry for evidence of their use. Participants learn to use the ATT&CK Navigator to prioritise hunts, query endpoint and network telemetry for living-off-the-land and lateral movement activity, and validate whether existing tooling would actually catch a given technique using adversary emulation. Sessions cover translating threat intelligence into specific hunt hypotheses, writing clear findings reports, and converting successful manual hunts into permanent automated detections. Practical exercises include mapping a sample environment's coverage gaps on the ATT&CK matrix, running a hunting query against provided telemetry data, and emulating a known technique to test detection visibility. Participants leave with a hunting methodology template and a coverage tracking model for their own environment.

Expected Learning Outcomes

01

Prioritise hunt hypotheses using MITRE ATT&CK Navigator coverage gaps and threat intelligence.

02

Formulate testable hunt hypotheses that target specific adversary tactics and techniques.

03

Query endpoint and network telemetry to identify living-off-the-land and lateral movement activity.

04

Validate detection coverage using adversary emulation before relying on it operationally.

05

Convert successful manual hunt queries into permanent, automated detection rules.

06

Write hunt findings reports that document hypothesis, method, evidence and outcome clearly.

07

Report threat hunting programme value through coverage growth and significant findings.

Who Should Attend

01

Threat hunters and detection engineers building a hypothesis-driven hunting practice.

02

SOC analysts moving from alert triage into proactive threat hunting roles.

03

Incident responders who need structured hunting techniques for post-incident sweeps.

04

Threat intelligence analysts translating adversary reporting into hunting priorities.

05

Security engineers validating detection coverage through adversary emulation.

06

Security leaders scoping and measuring a threat hunting programme's return.

Course Modules

Select any module to see its sessions and points.

01

Foundations of Hypothesis-Driven Threat Hunting

2 sessions · 8 points

Session 1From Reactive Detection to Proactive Hunting

  • Distinguish hypothesis-driven hunting from alert-driven detection and incident response.
  • Apply the Pyramid of Pain to prioritise hunts that target adversary tactics over easily changed indicators.
  • Assess organisational hunting maturity against a recognised model before scoping a programme.
  • Define which data sources and retention periods a given hunt hypothesis requires.

Session 2Structuring Hunts Around the MITRE ATT&CK Matrix

  • Use the ATT&CK Navigator to map current detection coverage against tactics and techniques.
  • Prioritise hunt hypotheses that target techniques with the weakest existing detection coverage.
  • Translate a chosen technique and sub-technique into a specific, testable hunt hypothesis.
  • Document assumptions and expected evidence in writing before beginning the hunt.
02

Gathering and Analysing Hunting Telemetry

2 sessions · 8 points

Session 1Endpoint Telemetry and Living-off-the-Land Detection

  • Query endpoint detection and response telemetry for process and parent-child relationships.
  • Identify living-off-the-land technique abuse of legitimate administrative tools.
  • Baseline normal administrative activity to isolate genuinely anomalous behaviour.
  • Correlate endpoint findings with authentication logs to confirm suspected compromise.

Session 2Network Telemetry and Query-Based Analysis

  • Analyse network telemetry for command-and-control and lateral movement patterns.
  • Write hunting queries in common query languages against large telemetry datasets.
  • Pivot between endpoint and network data sources to build a complete activity timeline.
  • Distinguish benign anomalies from genuine indicators of adversary technique use.
03

Threat Intelligence and Adversary Emulation

2 sessions · 8 points

Session 1Driving Hunts with Threat Intelligence

  • Translate threat intelligence on relevant adversary groups into specific ATT&CK technique hypotheses.
  • Prioritise hunts by the threat actors and campaigns most relevant to the organisation's sector.
  • Distinguish durable tactic and technique intelligence from perishable indicators of compromise.
  • Incorporate sector-specific threat landscape changes into hunt cadence and prioritisation.

Session 2Validating Hunts Through Adversary Emulation

  • Use adversary emulation tooling to generate known technique activity for testing.
  • Confirm whether existing telemetry and queries would actually detect the emulated technique.
  • Identify visibility gaps exposed by emulation that no amount of querying can overcome.
  • Schedule recurring emulation to confirm hunts remain effective as environments change.
04

Reporting, Automating and Measuring Hunt Value

2 sessions · 8 points

Session 1Converting Hunt Findings into Permanent Detections

  • Write findings reports documenting hypothesis, method, evidence and outcome for each hunt.
  • Convert successful manual hunt queries into automated, permanently running detection rules.
  • Feed newly identified gaps back into the detection engineering and SOC backlog.
  • Share hunt methodology and results with peer teams to build organisational hunting capability.

Session 2Demonstrating Threat Hunting Programme Value

  • Track hunts completed, techniques covered and detections generated as core programme metrics.
  • Report coverage improvement against the ATT&CK matrix over successive quarters.
  • Present a small number of significant findings to leadership in business impact terms.
  • Build a prioritised backlog of future hunts based on residual coverage gaps and threat shifts.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course