Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Advanced Incident Response and Threat Hunting

Advanced incident response and threat hunting is about catching an intrusion while it is still happening. This course assumes you already read Windows artifacts and moves you from examining one machine to hunting across an entire estate.

You cover enterprise live response, evidence of execution, lateral movement, credential abuse, memory forensics and super timeline analysis, then close with a capstone intrusion spanning several compromised hosts.

Duration
10 weeks
Format
Live online, instructor-led
Prerequisites
Windows Forensic Analysis
Class size
Capped at 12 learners
Advanced Incident Response and Threat Hunting

What you will be able to do

  • Run live response collection across hundreds of hosts and reduce the output to leads
  • Identify execution evidence left by fileless and living off the land techniques
  • Track lateral movement through remote services, WMI, PsExec and RDP artifacts
  • Detect credential theft and abuse including pass the hash and Kerberos attacks
  • Analyse memory images for injected code, hidden processes and network state
  • Build a super timeline combining file system, registry and log evidence
  • Spot anti-forensic activity such as timestomping and selective log clearing
  • Scope an intrusion accurately enough to justify a remediation event

Course outline

6 modules

  • Hunting on a hypothesis versus responding to alerts
  • MITRE ATT&CK used as a hunting map
  • Data sources you need in place before hunting is possible
  • Stacking, frequency analysis and outlier hunting
  • Judging whether a hunt was worth running

What you need before you start

  • Working knowledge of Windows forensic artifacts, or the Windows Forensic Analysis course
  • Comfort with Windows administration, Active Directory concepts and the command line
  • A machine with 32 GB of RAM recommended, 16 GB minimum, and 300 GB free
  • Around six hours a week outside class for lab work

Who this course is for

  • Incident responders handling intrusions rather than single-host cases
  • SOC analysts moving into proactive hunting roles
  • Forensic examiners taking on network intrusion casework
  • Detection engineers who want to validate rules against real attacker behaviour
  • Consultants delivering compromise assessments

Where this leads

Prepares you for

CHFI

Awarded by EC-Council

The intrusion investigation content aligns with the incident handling and analysis domains of the Computer Hacking Forensic Investigator programme. EC-Council examines candidates and issues the CHFI credential. We deliver training toward it and award no certification of our own.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.