Festival Season Offer15% off on all our programmes — claim it before you enrol
MODULE 5 OF 5  ·  50 Hrs  ·  5 Weeks

Incident Response & Threat Hunting

The program closes by turning detection into action — running a structured incident response lifecycle end to end, and hunting proactively for threats that alerts alone never surface, using the same frameworks real SOC teams rely on.

Who This Module Is For
Students consolidating SIEM and monitoring skills into full incident response and proactive threat-hunting capability.
Real-World Relevance
The ability to run an incident from identification through recovery — and to hunt proactively using MITRE ATT&CK — is exactly what separates a SOC Analyst who reacts to alerts from one who's ready for Incident Response and Threat Intelligence roles.
Program OverviewView Hands-On Labs
Curriculum

What You Will Learn

A detailed, industry-aligned breakdown of every topic covered in this module.

  • Incident handling process & response lifecycle
  • Preparation, containment, eradication & recovery
  • Security incident playbooks vs. runbooks
  • The Cyber Kill Chain and MITRE ATT&CK framework
  • Cyber Threat Intelligence (CTI) and its lifecycle
  • Indicators of Compromise (IOC) vs. Indicators of Attack
  • Threat hunting methods & investigation tools
  • Email header analysis & malware analysis basics
Technology Stack

Tools You Will Use

Hands-on time with the same tools used in real Security Operations Centers today.

MITRE ATT&CK

Industry-standard framework of adversary tactics and techniques used to structure detection and hunting.

Kill Chain

The Cyber Kill Chain model used to map an attack's stages from reconnaissance to actions on objectives.

CyberChef

Browser-based data analysis tool used to decode, decrypt and analyse suspicious data during investigations.

Sysinternals

Windows diagnostic and forensic utility suite used to investigate processes, autoruns and system activity.

Google Dorks

Advanced search techniques used for open-source reconnaissance and exposure discovery.

IOC / IOA

Indicators of Compromise and Indicators of Attack used to detect and hunt for malicious activity.

Practical Work

Hands-On Labs

Production-style SOC lab scenarios, built using the same stack real security teams monitor with.

01

Run a full incident response lifecycle from identification through recovery.

02

Build an incident playbook for a specific attack scenario.

03

Map a simulated attack to the Cyber Kill Chain and the MITRE ATT&CK framework.

04

Hunt for hidden threats using MITRE ATT&CK and threat intelligence feeds.

05

Analyse email headers and perform basic malware analysis using CyberChef and Sysinternals.

Evaluation

Assessment

Knowledge Assessment

Quiz covering the incident response lifecycle, the Cyber Kill Chain, MITRE ATT&CK and IOC vs. IOA.

Practical Evaluation

Students must respond to and document a simulated multi-stage incident end to end, including a proactive threat-hunting exercise.

Portfolio

Projects

Industry-style deliverables added directly to your project portfolio.

Portfolio Project 01

Incident Response Simulation

Run through a full incident lifecycle — from identification to containment and recovery.

Portfolio Project 02

Threat Hunting Project

Use MITRE ATT&CK and threat intelligence feeds to proactively hunt for hidden threats.

Module Outcome

What This Module Builds

Students learn to respond to real incidents using a structured lifecycle, and to hunt proactively using threat intelligence and industry-standard frameworks.

Maps to job roles
Incident Response Analyst (Trainee)Threat Intelligence Analyst (Junior)Junior Threat HunterSOC Analyst (L2)

Continue building your SOC analyst portfolio

You have reached the final module — explore career outcomes next.

View Career OutcomesFull Roadmap