Skip to main content
CYB-0158PractitionerCurrent Intake
X-CWAPT-P

APT Detection and Advanced Threat Hunting

4-Day Instructor-Led Programme

A four-day hands-on practitioner programme covering hypothesis-driven threat hunting for nation-state intrusions across Splunk, Microsoft Sentinel, and ELK, with daily lab exercises and a live capstone. Build the detection engineering, hunt methodology, and intelligence reporting skills to find APT actors who have already bypassed standard SIEM alerting.

Duration

4 Days

Price

$4,495

APT Detection and Advanced Threat Hunting
Duration
4 Days
Complete in 4 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

Nation-state actors average 197 days inside a network before detection. Standard SIEM alerts are designed for known-bad indicators, not patient, living-off-the-land operators who use legitimate tools, trusted processes, and compromised credentials. This four-day programme develops the threat hunting capability needed to find what alerts miss, using the same platforms deployed in enterprise and government SOC environments.

Across four days of mentor-led instruction and hands-on platform labs, participants build APT-specific detection rules in Splunk and Microsoft Sentinel, execute structured threat hunts in all three platforms, apply MITRE ATT&CK Navigator to map detection coverage and identify gaps by adversary group, and analyse network traffic and DNS patterns for C2 beaconing and anomaly indicators. Every day concludes with a practical exercise reinforcing the session content.

The programme culminates in a four-hour capstone: a live red-versus-blue hunt scenario using a simulated nation-state intrusion dataset. Participants detect, investigate, and produce a professional intelligence report under realistic time pressure. This course is aligned with MITRE ATT&CK, NCSC threat hunting guidance, and platform-specific SOC detection engineering standards.

Hands-On Learning

Full-day Splunk, Sentinel, and ELK platform labs; APT-specific detection rule building; C2 beaconing and DNS anomaly detection practicals; and a four-hour live hunt capstone exercise.

Mentor-Led Sessions

Practitioner-led detection engineering sessions with live rule review, ATT&CK coverage mapping workshops, and instructor-guided debrief of every hunt exercise output across all four days.

Career-Ready Skills

Hypothesis-driven threat hunting methodology, detection rule authoring across three SIEM platforms, ATT&CK coverage analysis, living-off-the-land detection, and intelligence report production under time pressure.

Learning Outcomes

Hunt for long-dwell nation-state intrusions using Splunk, Microsoft Sentinel, and ELK across four days of hands-on lab work.

Apply MITRE ATT&CK Navigator to build detection coverage maps and identify gaps by specific adversary group.

Detect living-off-the-land techniques, LOLBin abuse, fileless malware, and trusted process injection patterns.

Identify lateral movement, credential dumping, and C2 beaconing signatures across enterprise telemetry.

Write structured threat hunting hypotheses and execute disciplined, evidence-based hunts to completion.

Produce professional intelligence reports translating hunt findings into actionable SOC and CISO recommendations.

Design and prioritise a detection engineering programme based on threat actor likelihood and sector exposure.

Prerequisites

1

Active experience in a SOC analyst or security operations role at L2 level or above.

2

Familiarity with at least one SIEM platform and basic query language experience.

3

Understanding of common attack techniques including phishing, credential theft, and lateral movement.

Detailed Syllabus

Step-by-step learning journey from basics to professional practice

Topics Covered

  • Pre-reading: MITRE ATT&CK threat hunting methodology overview and hypothesis framework guide
  • Platform access setup: Splunk trial environment, Sentinel workspace, ELK stack lab configuration
  • Introduction to the hunt hypothesis framework and hunt log documentation standard used throughout
  • Course objectives, skill baseline assessment, and individual learning pathway alignment

Skills You'll Gain

Master these in-demand skills through hands-on practice

Hypothesis-driven threat hunting methodologySplunk SPL for detection engineeringMicrosoft Sentinel KQL query writingELK Stack threat huntingMITRE ATT&CK Navigator coverage mappingC2 beaconing and DNS anomaly detectionLiving-off-the-land technique detectionIntelligence report productionLateral movement detectionHunt library development and documentationCloud intrusion detectionSupply chain compromise hunting

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Threat HunterSOC L2 AnalystSOC L3 AnalystBlue Team LeadDetection EngineerIncident Responder
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

4 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$4,495+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised APT Detection and Advanced Threat Hunting learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Awarding Organisation
Xcademia
Credential Awarded
Certificate Of Completion

Important Information

You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.

Credential

Certificate of Completion

On successful completion of APT Detection and Advanced Threat Hunting, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.

Frequently Asked Questions

Everything you need to know about this course

Familiarity with at least one SIEM platform and basic query writing is expected. Participants do not need expertise across all three platforms, as each is taught from a hunting-focused foundation within the programme.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options