This track prepares professionals to respond to real intrusions and to hunt threats that evade conventional detection. It is taught with the same low-level perspective we apply in research — responders who understand how attacks are built investigate them far more effectively.
Students who want to continue into full malware reverse engineering after this track should look at the reverse engineering track, which begins where Incident Response and Threat Hunting 2 leaves off.
Recommended Order
6 courses · 140 hoursA structured path from first response to advanced threat hunting. The first three courses form the Threat Hunter Professional level and are best taken in order; the remaining courses build on them.
Malicious Documents Analysis
Analysis of the malicious documents most often used as the initial attack vector against companies. Students learn to extract the indicators of compromise that reveal the next stage of the infection chain.
Network Threat Analysis
An introductory incident response course on analysing captured network traffic. Designed as a supplement to Incident Response and Threat Hunting 1 and 2, it takes a deep dive into PCAP analysis from several perspectives.
Incident Response and Threat Hunting 1
An introduction to the incident response and threat hunting world: setting up the right tools, the core concepts and practical steps, and digital forensics investigation. Starts with Windows logging, Sysmon and ETW and the investigations built on them.
Incident Response and Threat Hunting 2
Advanced techniques for detecting and triaging sophisticated malware threats, taught through a completely practical approach. The techniques here also teach students to collect the artifacts needed before reverse engineering begins.
Incident Response: Ransomware Investigation
Understanding, detecting, defending against and analysing real ransomware scenarios, covering incident response and threat hunting on infected systems, basic defence measures, detection, and the commands used during an investigation.
Windows Live and Crash Dump Analysis
Intensive WinDbg coverage for analysing live systems and crash dumps. A valuable complement for responders who need to investigate at the kernel level.
Certification
- Blackstorm Threat Hunter Professional — after Malicious Documents Analysis, Network Threat Analysis and IR & Threat Hunting 1
- Blackstorm Threat Hunter Expert — after IR & Threat Hunting 2 and Ransomware Investigation
Dates and enrolment
Scheduled dates for every course in this track are listed on the training page, together with format, payment and enrolment details.