Incident Response & Threat Hunting
The program closes by turning detection into action — running a structured incident response lifecycle end to end, and hunting proactively for threats that alerts alone never surface, using the same frameworks real SOC teams rely on.
What You Will Learn
A detailed, industry-aligned breakdown of every topic covered in this module.
- Incident handling process & response lifecycle
- Preparation, containment, eradication & recovery
- Security incident playbooks vs. runbooks
- The Cyber Kill Chain and MITRE ATT&CK framework
- Cyber Threat Intelligence (CTI) and its lifecycle
- Indicators of Compromise (IOC) vs. Indicators of Attack
- Threat hunting methods & investigation tools
- Email header analysis & malware analysis basics
Tools You Will Use
Hands-on time with the same tools used in real Security Operations Centers today.
MITRE ATT&CK
Industry-standard framework of adversary tactics and techniques used to structure detection and hunting.
Kill Chain
The Cyber Kill Chain model used to map an attack's stages from reconnaissance to actions on objectives.
CyberChef
Browser-based data analysis tool used to decode, decrypt and analyse suspicious data during investigations.
Sysinternals
Windows diagnostic and forensic utility suite used to investigate processes, autoruns and system activity.
Google Dorks
Advanced search techniques used for open-source reconnaissance and exposure discovery.
IOC / IOA
Indicators of Compromise and Indicators of Attack used to detect and hunt for malicious activity.
Hands-On Labs
Production-style SOC lab scenarios, built using the same stack real security teams monitor with.
Run a full incident response lifecycle from identification through recovery.
Build an incident playbook for a specific attack scenario.
Map a simulated attack to the Cyber Kill Chain and the MITRE ATT&CK framework.
Hunt for hidden threats using MITRE ATT&CK and threat intelligence feeds.
Analyse email headers and perform basic malware analysis using CyberChef and Sysinternals.
Assessment
Knowledge Assessment
Quiz covering the incident response lifecycle, the Cyber Kill Chain, MITRE ATT&CK and IOC vs. IOA.
Practical Evaluation
Students must respond to and document a simulated multi-stage incident end to end, including a proactive threat-hunting exercise.
Projects
Industry-style deliverables added directly to your project portfolio.
Incident Response Simulation
Run through a full incident lifecycle — from identification to containment and recovery.
Threat Hunting Project
Use MITRE ATT&CK and threat intelligence feeds to proactively hunt for hidden threats.
What This Module Builds
Students learn to respond to real incidents using a structured lifecycle, and to hunt proactively using threat intelligence and industry-standard frameworks.
