Advanced Security Operations & Threat Hunting
Four days inside a live enterprise under attack — and every day drops a new, complex attack chain into the range for you to take apart. You'll build detections, hunt adversaries, and run forensics at fleet scale across a real investigation stack — LimaCharlie, OpenSearch, Arkime, and Velociraptor — then close out the course by running a full incident response against an active intrusion.
- 4 attack chains to investigate
- 20+ hands-on labs
- 4 tool investigation stack
- 1 IR capstone
-
Day 01
Detection Engineering
The detection lifecycle from raw telemetry to tested rule. Profile credential theft, lateral movement, and persistence tradecraft, then write Sigma, YARA, Suricata, and LimaCharlie detections that catch it.
-
Day 02
Threat Hunting
Hypothesis-driven hunting across endpoint and network telemetry — C2 channels, evasive PowerShell, anti-forensics — plus GenAI-assisted detection engineering and real-world case studies like Volt Typhoon.
-
Day 03
Forensics at Scale
Velociraptor across the fleet: hunt artifacts enterprise-wide, stack for rarity, and pivot from a phishing email to host-level evidence — Autoruns, Prefetch, ShimCache, and memory.
-
Day 04
Live IR Capstone
An intel drop lands and it's your incident. Run the full response lifecycle against an active intrusion in the range — identification through containment, eradication, and lessons learned.
Every student gets their own seat in the ASOTH range — a simulated enterprise with live adversaries — and leaves with DDI's analyst cheatsheets, lab guides, and a curated resource library.
I paid for this 100% out of pocket, investing in myself, and it was worth every penny.
ASOTH student · Black Hat USA 2025


