LEVEL: INTERMEDIATE 

Full Course.
Cyber Threat Hunting

Big companies with complex IT infrastructure need to protect it – or face the consequences of being compromised.

Sophisticated attacks can bypass automatic defense unnoticed. Here’s where Security Operations Center (SOC) comes to the rescue, bringing expertise and skills of its professionals for better protection.

This updated version of Kaspersky’s course, developed by the company’s own SOC and incident investigation experts, provides comprehensive practical training in modern threat hunting methodologies.

Based on real-world experience and continuously updated expertise, the course introduces participants to threat hunting as an analytical process, the use of MITRE ATT&CK as a behavioral framework, and multiple hunting approaches, including TTP-based, IOC-based, and anomaly-based techniques.
Write your awesome label here.
Roman Nazarov
Head of Kaspersky SOC Consulting

At Kaspersky SOC Consulting, he focuses on a complex approach that includes all areas of SOC/MSS/CERT design and architecture, establishing operations and development planning. Roman is an acknowledged professional holding certificates like CISSP, CISM, CISA, GNFA, GCIH.
Write your awesome label here.
Dmitriy Uchakin
Security Researcher

Dmitriy is a SOC analyst, working in operation and research areas. He performs real-time investigations of detected threats and the analysis of fresh APT threats that were observed around the globe. He is involved in the optimization of SOC operations and in the automatization of the SOC routines through the development of Jupyter notebooks, as well as robots for repeatable actions. 
Write your awesome label here.
Sergey Soldatov
Head of Kaspersky SOC

Sergey is the Head of Kaspersky SOC, responsible for internal SOC activities at the company as well as external managed detection and response and Compromise assessment services. Sergey is a certified information systems security professional CISSP, OSCP and auditor CISA.

Training objectives

Understand why threat hunting exists and how it fits alongside detection, incident response, and threat intelligence
Assess telemetry availability and visibility gaps before starting a hunt
Hunt for identity abuse in Windows environments: credential extraction, Kerberoasting, and token impersonation
Build, test, and document hypothesis-driven hunts using MITRE ATT&CK as a behavioral reasoning framework
Translate operational threat intelligence into testable hunting hypotheses
Hunt for C2 channels, lateral movement, and data exfiltration in network traffic

Help & support

Please contact us at help.kasperskyxtraining.com if you are experiencing technical issues or need help and would like to chat with a Kaspersky expert.

Also, we invite you to join our Discord community for all the Kaspersky Expert Training learners, where you can talk with your peers, discuss courses’ exercises and much more. Click the link below and enjoy  https://discord.gg/EWVCjNzH