NSD Certified
Threat Hunter (NCTH)
The NSD Certified Threat Hunter, 52 hours program is a job oriented industry certification. The focus is on:
- MITRE’s ATT&CK Framework
- Threat Hunting approaches
- Threat Hunting techniques
- Reporting
Program available on GeM.
Unlock Lifetime Access to ISAC Certifications with Complimentary Training and Free of cost Online Internship: pay only for certification and lab costs.
Our advanced technical training program is available on demand for groups of at least 10 participants. For further details, please contact us.
Delivery Partner
Learn everything to get started Forensics Investigations.
Program Outline
- Reactive vs Proactive Response
- Goals of Threat hunting vs Goals of Incident Response
- Advantages of Threat Hunting
- Hypothesis Creation
- Tool Enabled Investigation
- Pattern Detection
- Automated Analytics
- Role of correct data
- Various approaches
- ATT&CK – MITRE’s Adversarial Tactics, Techniques, and Common Knowledge
- ATT&CK Techniques
- Working with Att&ck Navigator
- Lockheed martin kill chain
- Mapping attacker activity to kill chain
- Monitoring Tools
- Log Collection Tools
- Correlation Tools
- Threat Intelligence
- Data Analysis Tools
- Sample Data Sets
- Splunk BOTS V1
- Splunk BOTS V2
- Searching
- Clustering
- Grouping
- Stack Counting
- Labs
- SOAR Example use cases
- SIEM Examples for Automation
- Sample Templates
- Reporting Examples
- Overview of Sample Reports
Program Outcome
Use critical thinking to assess normal behavior patterns, identifying unusual network activities and potential security threats.
Understand hunting procedures, the Cyber Kill Chain, and MITRE’s ATT&CK Framework to proactively track and address threats.
Work with threat intelligence and correlation tools to connect data points and gain insights into potential security risks.
Leverage SOAR and data analysis tools to handle extensive data volumes efficiently, enhancing threat detection and response.
The course is best suited for:
- Security Researchers
- Students and Professionals keen in Forensics Investigations
- Security Teams
- Law Enforcement Agencies
- Military and police personnel
What You Get
Get 60 days access to course videos on the e-learning portal.
60 Day access to Cyberange Virtual Labs (ID/Password will be sent via email)
Get listed in the National Security Database program at the Falcon level by completing the program.
The Examination includes two free attempts, allowing candidates a second chance to improve their scores or deepen their understanding without additional costs. This benefit supports candidates in achieving certification with confidence and flexibility.
PROGRAM
Features & Benefits
Hands- On with Cyberange Virtual Labs
Get 60 Days access to Cyberange Virtual Labs for hands-on practice:
Penetration Testing Labs
Social Engineering Labs
Malware Labs
Cyber Forensic Labs
Password Cracking Labs
Bug Bounty Labs
