
Threat Hunting
Hunt the Threats That Hide
Form hypotheses, query telemetry, and track adversaries that don't trigger alerts. Learn proactive hunting techniques that find what automated detection misses.
Guided by The Hunter
What it is
Threat Hunting, defined
Threat hunting is proactive: assuming a breach already slipped past your detections and going looking for it. You form a hypothesis, query telemetry, and build an evidence timeline to prove or kill it — finding the adversaries that never tripped an alert.
The career
A skill you get hired for
The most dangerous threats don't trigger alerts. The absence of alerts doesn't mean the absence of threats — hunting is how you find the ones that hide.
Builds toward
Threat Hunter
Typical salary
$148K/yr avg
Market demand
500K+ open US roles
Who you'd work alongside
- Threat hunters
- DFIR and senior blue teams
- Threat intelligence teams
- Anyone reducing dwell time with proactive hunts
The DefendTheOrg approach
How you'll learn it
Under The Hunter — who found a backdoor that had been live in a defense contractor for two years — you run hunts against real telemetry, both structured and open-ended:
Hypothesis-driven
Start from a theory of what an adversary would do, then test it against the data and follow the evidence wherever it leads.
Build the timeline
Attacks unfold in sequences. You reconstruct the narrative from scattered events across time.
Structured and unstructured
Guided hunts teach the methodology; open-ended hunts develop the instinct to notice what doesn't belong.
Stuck? Get walked through it.
Every Easy and Medium lab has a walkthrough from The Hunter — one hint at a time, with a chance to try each step yourself before the answer. You get three a week, and using one never touches your score. It teaches the reasoning, not the solution.
Try it yourself
A taste of the real lab
This is a simplified, no-signup slice of a Threat Hunting lab — make your call and see how it's graded. The real labs go deeper.
Hunt the intrusion
No alert fired. Pick the log events that form the attack chain, then name the entry technique.
Endpoint process logs
Push yourself
Where Hard and Expert labs take you
Every skill scales from your first lab to genuinely hard reasoning. Difficulty isn't a bigger wall — it's deeper thinking.
Hard
Hard hunts start from a vague hypothesis, require correlating across multiple sources, include some evasion, and stretch over a longer timeline with realistic gaps.
Expert
Expert hunts are unstructured only — multiple log sources, evasion like timestomping, log clearing, and living-off-the-land, and realistic adversary dwell time — and you build the entire narrative from scratch.
Start threat hunting training
Hands-on labs built from real engagement data. Learn by doing — guided by The Hunter.