Advanced Incident Response and Threat Hunting
Advanced incident response and threat hunting is about catching an intrusion while it is still happening. This course assumes you already read Windows artifacts and moves you from examining one machine to hunting across an entire estate.
You cover enterprise live response, evidence of execution, lateral movement, credential abuse, memory forensics and super timeline analysis, then close with a capstone intrusion spanning several compromised hosts.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Windows Forensic Analysis
- Class size
- Capped at 12 learners

What you will be able to do
- Run live response collection across hundreds of hosts and reduce the output to leads
- Identify execution evidence left by fileless and living off the land techniques
- Track lateral movement through remote services, WMI, PsExec and RDP artifacts
- Detect credential theft and abuse including pass the hash and Kerberos attacks
- Analyse memory images for injected code, hidden processes and network state
- Build a super timeline combining file system, registry and log evidence
- Spot anti-forensic activity such as timestomping and selective log clearing
- Scope an intrusion accurately enough to justify a remediation event
Course outline
6 modules
- Hunting on a hypothesis versus responding to alerts
- MITRE ATT&CK used as a hunting map
- Data sources you need in place before hunting is possible
- Stacking, frequency analysis and outlier hunting
- Judging whether a hunt was worth running
What you need before you start
- Working knowledge of Windows forensic artifacts, or the Windows Forensic Analysis course
- Comfort with Windows administration, Active Directory concepts and the command line
- A machine with 32 GB of RAM recommended, 16 GB minimum, and 300 GB free
- Around six hours a week outside class for lab work
Who this course is for
- Incident responders handling intrusions rather than single-host cases
- SOC analysts moving into proactive hunting roles
- Forensic examiners taking on network intrusion casework
- Detection engineers who want to validate rules against real attacker behaviour
- Consultants delivering compromise assessments
Where this leads
Prepares you for
CHFI
Awarded by EC-Council
The intrusion investigation content aligns with the incident handling and analysis domains of the Computer Hacking Forensic Investigator programme. EC-Council examines candidates and issues the CHFI credential. We deliver training toward it and award no certification of our own.
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



