Microsoft Threat Hunting

Master Microsoft Threat Hunting

Go beyond alerts and become a proactive hunter. Learn hypothesis-driven threat hunting across Microsoft 365, Entra ID, Defender XDR, and Sentinel; so you can find stealthy attackers, uncover hidden compromises, and hunt like a professional before threats become breaches.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Develop and execute strong, hypothesis-driven threat hunting campaigns based on real attacker TTPs
✓Hunt proactively across Microsoft 365, Entra ID, endpoints, email, and cloud workloads using KQL and Defender XDR
✓Uncover stealthy threats, living-off-the-land techniques, and persistent compromises that evade detection
✓Translate hunting findings into high-fidelity detections, analytics rules, and automated playbooks
✓Build repeatable hunting playbooks and methodologies for your organization
✓Lead effective threat hunting operations and clearly communicate results to technical and executive stakeholders
What students say about this course

“Really appreciate how the training broke down and showed us how to find the stuff that matters and create effective trigger points for detections. Writing KQL queries to hunt for mailbox delegation changes and persistence mechanisms gave us a massive practical experience.”

Ahmad
SEC402 | Premium tier | 17 modules across 3 phases | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Hunt Methodology & Advanced Toolcraft

Module 0Course OrientationCourse Preview

What Microsoft Threat Hunting teaches: run the hypothesis-driven hunt cycle to find the stealthy attacker no alert fired on, across Entra ID, Defender XDR, and Sentinel, through ten complete hunt campaigns, and turn every hunt into a new detection. The hunt cycle you'll run, the campaigns and playbooks you walk away with, and how the course is structured. Start here.

Show 9 lessonsHide lessons
  1. 0.10.1 The Detection GapPreview
  2. 0.20.2 Why Detection Engineering Cannot Close the GapPreview
  3. 0.30.3 The M365 Threat LandscapePreview
  4. 0.40.4 Where Hunting FitsPreview
  5. 0.50.5 The Business Case for HuntingPreview
  6. 0.60.6 Organizational Readiness and Data SourcesPreview
  7. 0.70.7 The Hunter's Skillset and MaturityPreview
  8. 0.80.8 Your First 90 DaysPreview
  9. 0.9Module SummaryPreview
Module 1The Hunt Cycle, A Structured Methodology

The six-step methodology that every campaign module follows. Hypothesis formulation, scoping, iterative collection, contextual analysis, conclusion documentation, detection rule conversion, the hunt documentation standard, a complete worked example, and operational cadence with quality assurance.

Show 12 lessonsHide lessons
  1. 1.11.1 Formulating Hunt Hypotheses
  2. 1.21.2 Scoping the Hunt
  3. 1.31.3 Collection: Iterative Querying
  4. 1.41.4 Analysis: Separating Signal from Noise
  5. 1.51.5 Concluding the Hunt
  6. 1.61.6 Converting Hunts to Detection Rules
  7. 1.71.7 The Hunt Documentation Standard
  8. 1.81.8 The Hunt-to-Detection Pipeline: Worked End-to-End
  9. 1.91.9 Hunt Cadence and Scheduling
  10. 1.101.10 Hunt Quality Assurance and Metrics
  11. 1.11Module Summary
  12. 1.12Check My Knowledge

Phase 2: Hunt Campaigns

Module 6Hunting Privilege Escalation and Abuse

The third campaign module. Seven privilege escalation techniques hunted across AuditLogs, PIM logs, and directory change records: direct role assignments outside PIM, Global Admin activation anomalies, emergency access account misuse, service principal credential abuse, admin consent for privilege, security group manipulation, and conditional access weakening for elevated access. Every escalation found is an attacker who moved from user-level access to admin-level control.

Show 15 lessonsHide lessons
  1. 6.1TH6.1 The Privilege Escalation Landscape
  2. 6.2TH6.2 Hunting Role Assignments Outside PIM
  3. 6.3TH6.3 Hunting Global Admin Activation Anomalies
  4. 6.4TH6.4 Hunting Emergency Access Account Misuse
  5. 6.5TH6.5 Hunting Service Principal Credential Abuse for Escalation
  6. 6.6TH6.6 Hunting Admin Consent for Privilege Escalation
  7. 6.7TH6.7 Hunting Security Group Manipulation
  8. 6.8TH6.8 Hunting CA Weakening for Elevated Access
  9. 6.9TH6.9 Temporal Correlation. Escalation Timeline
  10. 6.10TH6.10 Building the Privilege Escalation Hunt Report
  11. 6.11TH6.11 Converting to Detection Rules
  12. 6.12TH6.12 Common Mistakes
  13. 6.13TH6.13 Privilege Escalation Hunt Operational Playbook
  14. 6.14Module Summary
  15. 6.15Check My Knowledge
Module 7Hunting Email-Based Threats

The fourth campaign module. Seven email threat techniques hunted across EmailEvents, CloudAppEvents, and authentication tables: BEC from compromised internal accounts, internal phishing from legitimate mailboxes, vendor email compromise, mail flow rule manipulation, auto-forwarding to external addresses, financial keyword interception, and email campaign correlation with authentication anomalies.

Show 14 lessonsHide lessons
  1. 7.1TH7.1 The Email Threat Landscape in M365
  2. 7.2TH7.2 Hunting BEC from Compromised Internal Accounts
  3. 7.3TH7.3 Hunting Internal Phishing from Legitimate Mailboxes
  4. 7.4TH7.4 Hunting Vendor Email Compromise
  5. 7.5TH7.5 Hunting Mail Flow Rule Manipulation
  6. 7.6TH7.6 Hunting Financial Keyword Interception
  7. 7.7TH7.7 Consolidated External Forwarding Audit
  8. 7.8TH7.8 Email Campaign Correlation with Authentication Anomalies
  9. 7.9TH7.9 Building the Email Threat Hunt Report
  10. 7.10TH7.10 Converting to Detection Rules
  11. 7.11TH7.11 Common Mistakes
  12. 7.12TH7.12 Email Threat Hunt Operational Playbook
  13. 7.13Module Summary
  14. 7.14Check My Knowledge
Module 8Hunting Data Exfiltration

The fifth campaign module. Six data exfiltration channels hunted across CloudAppEvents, SharePoint audit logs, and device telemetry: SharePoint and OneDrive bulk download anomalies, external sharing link creation, email-based data exfiltration, Teams file exfiltration, browser downloads to unmanaged devices, and multi-channel exfiltration correlation. Every finding represents data leaving your organization, either to an attacker or through an unauthorized channel.

Show 13 lessonsHide lessons
  1. 8.1TH8.1 The Data Exfiltration Landscape
  2. 8.2TH8.2 Hunting SharePoint and OneDrive Bulk Downloads
  3. 8.3TH8.3 Hunting External Sharing Link Creation
  4. 8.4TH8.4 Hunting Email-Based Data Exfiltration
  5. 8.5TH8.5 Hunting Teams File Exfiltration
  6. 8.6TH8.6 Hunting Downloads to Unmanaged Devices
  7. 8.7TH8.7 Multi-Channel Exfiltration Correlation
  8. 8.8TH8.8 Building the Data Exfiltration Hunt Report
  9. 8.9TH8.9 Converting to Detection Rules
  10. 8.10TH8.10 Common Mistakes
  11. 8.11TH8.11 Data Exfiltration Hunt Operational Playbook
  12. 8.12Module Summary
  13. 8.13Check My Knowledge
Module 9Hunting Endpoint Threats

The sixth campaign module. Seven endpoint threat techniques hunted across DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, and DeviceRegistryEvents: LOLBin abuse with network connections, process injection indicators, registry and scheduled task persistence, defense evasion (timestomping, log clearing, ASR bypass), C2 beaconing with time-series variance analysis, fileless execution, and process tree analysis.

Show 14 lessonsHide lessons
  1. 9.1TH9.1 The Endpoint Threat Landscape
  2. 9.2TH9.2 Hunting LOLBin Abuse with Network Connections
  3. 9.3TH9.3 Hunting Process Injection Indicators
  4. 9.4TH9.4 Hunting Registry and Scheduled Task Persistence
  5. 9.5TH9.5 Hunting Defense Evasion
  6. 9.6TH9.6 Hunting C2 Beaconing
  7. 9.7TH9.7 Hunting Fileless Execution
  8. 9.8TH9.8 Process Tree Analysis
  9. 9.9TH9.9 Building the Endpoint Threat Hunt Report
  10. 9.10TH9.10 Converting to Detection Rules
  11. 9.11TH9.11 Common Mistakes
  12. 9.12TH9.12 Endpoint Threat Hunt Operational Playbook
  13. 9.13Module Summary
  14. 9.14Check My Knowledge
Module 10Hunting Lateral Movement

The seventh campaign module. Seven lateral movement techniques hunted across SigninLogs, DeviceNetworkEvents, DeviceLogonEvents, and hybrid identity tables: cloud-to-cloud token reuse across applications, cloud-to-endpoint pivot correlation, RDP/SMB/WMI/PowerShell Remoting detection, service account lateral abuse, VPN pivoting from cloud compromise, NTLM and Kerberos anomalies, and Azure AD Connect abuse.

Show 14 lessonsHide lessons
  1. 10.1TH10.1 The Lateral Movement Landscape
  2. 10.2TH10.2 Hunting Cloud Token Reuse Across Applications
  3. 10.3TH10.3 Hunting Cloud-to-Endpoint Pivot
  4. 10.4TH10.4 Hunting RDP, SMB, WMI, and PowerShell Remoting
  5. 10.5TH10.5 Hunting Service Account Lateral Abuse
  6. 10.6TH10.6 Hunting VPN Pivot. Population Analysis
  7. 10.7TH10.7 Hunting Credential Harvesting. NTLM and Kerberos Anomalies
  8. 10.8TH10.8 Hunting Azure AD Connect Abuse
  9. 10.9TH10.9 Building the Lateral Movement Hunt Report
  10. 10.10TH10.10 Converting to Detection Rules
  11. 10.11TH10.11 Common Mistakes
  12. 10.12TH10.12 Lateral Movement Hunt Operational Playbook
  13. 10.13Module Summary
  14. 10.14Check My Knowledge
Module 12Hunting Pre-Ransomware Activity

The ninth campaign module. Six pre-ransomware indicators hunted across DeviceProcessEvents, DeviceFileEvents, DeviceRegistryEvents, and DeviceNetworkEvents: reconnaissance tool execution sequences, volume shadow copy and backup disruption, credential harvesting indicators, staging directory creation, known ransomware tooling signatures, and temporal chain correlation across the full pre-encryption kill chain.

Show 13 lessonsHide lessons
  1. 12.1TH12.1 The Pre-Ransomware Landscape
  2. 12.2TH12.2 Hunting Ransomware-Specific Reconnaissance
  3. 12.3TH12.3 Hunting Backup Disruption
  4. 12.4TH12.4 Hunting Credential Harvesting for Domain-Wide Deployment
  5. 12.5TH12.5 Hunting Ransomware Staging
  6. 12.6TH12.6 Hunting Known Ransomware Tooling
  7. 12.7TH12.7 Temporal Chain Correlation. The Complete Pre-Ransomware Timeline
  8. 12.8TH12.8 The Pre-Ransomware Hunt Report
  9. 12.9TH12.9 Converting Pre-Ransomware Findings to Detection Rules
  10. 12.10TH12.10 Common Pre-Ransomware Hunting Mistakes
  11. 12.11TH12.11 Pre-Ransomware Hunt Playbook
  12. 12.12Module Summary
  13. 12.13Check My Knowledge

Phase 3: Hunt Operations

Module 14Building a Hunt Program

Phase 3 begins. TH0–TH13 taught you how to hunt. TH14–TH16 teach you how to build, sustain, and scale a hunt program. This module covers cadence selection, prioritization frameworks, staffing models, the hunt-to-detection pipeline, SOC integration, and the hunt program charter, the document that formalizes the program and secures leadership support.

Show 10 lessonsHide lessons
  1. 14.1TH14.1 Hunt Cadence Models
  2. 14.2TH14.2 Hunt Prioritization Framework
  3. 14.3TH14.3 Staffing Models
  4. 14.4TH14.4 The Hunt-to-Detection Pipeline
  5. 14.5TH14.5 SOC Integration and Budget Justification
  6. 14.6TH14.6 The Hunt Program Charter
  7. 14.7TH14.7 Hunt Tooling and Workspace Organization
  8. 14.8TH14.8 Program Maturity Roadmap
  9. 14.9Module Summary
  10. 14.10Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

Hunt queries by domain, each with the fields that carry the decision and what the result does not establish.

Show 12 lessonsHide lessons
  1. 1Hunt Query Patterns
  2. 2Identity
  3. 3Cloud Persistence
  4. 4Privilege Escalation
  5. 5Email
  6. 6Data Exfiltration
  7. 7Endpoint
  8. 8Lateral Movement
  9. 9Application and API
  10. 10Pre-Ransomware
  11. 11Insider
  12. 12Tables, Codes and Coverage
ResourcesCookbooks

Six runbooks: executing a hunt, converting findings to detections, working an advisory, sprints, the backlog, and reporting.

Show 6 lessonsHide lessons
  1. 1Running a Hunt
  2. 2Converting a Finding to a Detection
  3. 3Working a Threat Advisory
  4. 4Running a Hunt Sprint
  5. 5Building the Hunt Backlog
  6. 6Reporting to Leadership
ResourcesLab Setup

Building an environment you can hunt in, and the constraint that separates a hunting lab from every other kind.

Show 1 lessonHide lessons
  1. 1Building the Environment
ResourcesPlaybooks

One operational playbook per hunt domain: the sequence, what to record at each step, and what escalates.

Show 10 lessonsHide lessons
  1. 1Identity
  2. 2Cloud Persistence
  3. 3Privilege Escalation
  4. 4Email
  5. 5Data Exfiltration
  6. 6Endpoint
  7. 7Lateral Movement
  8. 8Application and API
  9. 9Pre-Ransomware
  10. 10Insider
ResourcesPlayground

Resources for practicing hunting and using it at work: a corpus with history, guided investigations, the detection library, response procedures, and a DFIR toolkit.

ResourcesOperational Reference

The consolidated lookup and the step-by-step procedures from this course, in one place.

Show 2 lessonsHide lessons
  1. 1Hunt Query Quick Reference
  2. 2Threat Hunting Field Manual
ResourcesReferences & Further Reading

External sources this course draws on: vendor documentation, frameworks, standards, and research.

Course Completion

CompletionCourse Exam

Microsoft Threat Hunting end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Microsoft Threat Hunting

Course overview

The Microsoft Threat Hunting course is the core training track for hypothesis-driven hunting, designed for Detection Engineers, Security Engineers, and Hunt Team Leads. You'll gain hands-on expertise to:

✓ Develop and execute strong hunting hypotheses based on real attacker behavior and MITRE ATT&CK
✓ Hunt across identities, endpoints, email, cloud, and Microsoft 365 data using KQL and Defender XDR
✓ Uncover persistent threats, living-off-the-land techniques, and stealthy compromises
✓ Build repeatable hunting playbooks and automate detection opportunities from your hunts

By the end, you'll have the mindset, techniques, and practical skills to lead proactive threat hunting programs that significantly improve your organization's detection and response capabilities.

How this course works

A hunt is a hypothesis you can be wrong about, run against data with a stated coverage. This course runs the same cycle for every hunt it works, sixteen modules of it.

1. Write a hypothesis that can fail. If no result would change your mind, it is not a hunt. The falsifiable version is what makes an empty outcome reportable.

2. Establish how far back you can look. Retention differs by table and by license tier, and a hypothesis about six months ago is bounded by the shortest source it touches.

3. Query for the behavior, then baseline it. A result is not a finding until it has been compared against what normal looks like in your estate.

4. Check the entity before escalating. An event inside your window is not evidence your hypothesis was right. The entity check is what separates a finding from a coincidence.

5. Convert the finding into a rule, and the miss into coverage. A hunt that found something should end as a detection. A hunt that found nothing should end as a coverage statement naming what was searched.

The course closes on building the hunt program: a backlog with an order, documentation that outlives the hunter, and hunts that run without one.

What this course assumes

No minimum experience and no prerequisite course. KQL, the ATT&CK model and the M365 telemetry surface are introduced where they first matter.

What makes it go faster: a tenant with real telemetry and any prior KQL. Neither is required. Every hunt in the course runs against the Practice Hub, which holds populated tables and known answers.

What this course does not cover: incident response process, forensics and detection engineering as a program. A hunt hands off to those, and the handoff is taught rather than the destination.

Who this course is for

You're a Detection Engineer, Security Engineer, or Hunt Team Lead responsible for proactive, hypothesis-driven threat hunting in Microsoft 365 environments. This course is built for you if you want to:

✓ Move from reactive alert triage to leading professional-grade proactive hunting programs
✓ Master hypothesis-driven techniques using KQL, Defender XDR, and Microsoft Sentinel
✓ Find advanced threats that bypass your existing detections
✓ Turn hunting discoveries into lasting improvements in your detection and response capabilities

In short: if you're ready to become a highly effective threat hunter who actively finds attackers before they cause damage, this course is for you.

What you'll learn

By the end of this Microsoft Threat Hunting course you will be able to:

✓ Build and execute high-quality hunting hypotheses grounded in MITRE ATT&CK and real-world intelligence
✓ Perform advanced threat hunting across identities, endpoints, email, Teams, SharePoint, and cloud data
✓ Use KQL effectively for hunting in Microsoft Sentinel and Defender XDR
✓ Identify living-off-the-land, fileless, and stealthy attacker techniques in Microsoft 365 environments
✓ Automate repetitive hunting tasks and convert successful hunts into production detections
✓ Document, report, and operationalize hunting outcomes to mature your organization's security program

Key course takeaways

✓ Lead professional, hypothesis-driven threat hunting programs in Microsoft 365 environments
✓ Master proactive hunting techniques that consistently uncover hidden threats and compromises
✓ Translate hunting results into stronger detections, playbooks, and security improvements
✓ Significantly reduce your organization's dwell time by finding attackers earlier
✓ Build reusable hunting methodologies, queries, and playbooks for your team
✓ Become the go-to threat hunter who elevates your SOC from reactive to truly proactive

Lab Pack, Hypothesis-Driven Hunt Toolkit

Evidence (9 tables, 30-day window, ~4,000+ entries): SigninLogs, AuditLogs, OfficeActivity, DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, DeviceFileEvents, DeviceRegistryEvents, with multiple attack chains hidden in legitimate baseline noise.

Hunt query library (~70 KQL files across 10 domains): Identity, Persistence, Escalation, Email, Exfiltration, Endpoint, Lateral Movement, Application, Ransomware, Insider, and Advanced correlation queries.

10 structured hypotheses with ATT&CK mapping and success criteria. Answers deliberately withheld, you must hunt.

Program artifacts: Charter, sprint template, maturity model, metrics template, hunt report templates, ATT&CK coverage matrix.

Threat Hunting Lab Pack
~100+ files · 9 evidence tables · 70 hunt queries · 10 hypotheses · 30-day evidence window
Download Lab Pack (.zip)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches hypothesis-driven threat hunting from first principles. Familiarity with KQL and the Microsoft security stack will help you move faster, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Sentinel and Defender XDR for hands-on hunting. The lab pack provides synthetic evidence data if you cannot use a live environment.

How will the course benefit your career?

Threat hunting is one of the highest-value skills in security operations. Organizations need people who can proactively find threats that detection rules miss, not just triage alerts. This course gives you the methodology, the KQL fluency, and the hunt program framework to lead hunting operations.

The demand for threat hunters continues to grow as organizations recognize that detection rules alone cannot close the gap between attacker dwell time and discovery.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy hunt queries, detection rules, and playbooks in your production environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.