The Hunter

Threat Hunting

Hunt the Threats That Hide

Form hypotheses, query telemetry, and track adversaries that don't trigger alerts. Learn proactive hunting techniques that find what automated detection misses.

Guided by The Hunter

What it is

Threat Hunting, defined

Threat hunting is proactive: assuming a breach already slipped past your detections and going looking for it. You form a hypothesis, query telemetry, and build an evidence timeline to prove or kill it — finding the adversaries that never tripped an alert.

The career

A skill you get hired for

The most dangerous threats don't trigger alerts. The absence of alerts doesn't mean the absence of threats — hunting is how you find the ones that hide.

Builds toward

Threat Hunter

Typical salary

$148K/yr avg

Market demand

500K+ open US roles

Who you'd work alongside

  • Threat hunters
  • DFIR and senior blue teams
  • Threat intelligence teams
  • Anyone reducing dwell time with proactive hunts

The DefendTheOrg approach

How you'll learn it

Under The Hunter — who found a backdoor that had been live in a defense contractor for two years — you run hunts against real telemetry, both structured and open-ended:

Hypothesis-driven

Start from a theory of what an adversary would do, then test it against the data and follow the evidence wherever it leads.

Build the timeline

Attacks unfold in sequences. You reconstruct the narrative from scattered events across time.

Structured and unstructured

Guided hunts teach the methodology; open-ended hunts develop the instinct to notice what doesn't belong.

The Hunter

Stuck? Get walked through it.

Every Easy and Medium lab has a walkthrough from The Hunter — one hint at a time, with a chance to try each step yourself before the answer. You get three a week, and using one never touches your score. It teaches the reasoning, not the solution.

3 walkthroughs a weekHint → try → revealNever affects your score

Try it yourself

A taste of the real lab

This is a simplified, no-signup slice of a Threat Hunting lab — make your call and see how it's graded. The real labs go deeper.

Hunt the intrusion

No alert fired. Pick the log events that form the attack chain, then name the entry technique.

Endpoint process logs

Push yourself

Where Hard and Expert labs take you

Every skill scales from your first lab to genuinely hard reasoning. Difficulty isn't a bigger wall — it's deeper thinking.

Hard

Hard hunts start from a vague hypothesis, require correlating across multiple sources, include some evasion, and stretch over a longer timeline with realistic gaps.

Expert

Expert hunts are unstructured only — multiple log sources, evasion like timestomping, log clearing, and living-off-the-land, and realistic adversary dwell time — and you build the entire narrative from scratch.

Start threat hunting training

Hands-on labs built from real engagement data. Learn by doing — guided by The Hunter.