834 words
4 minutes
eCTHP v2 Course Labs Roadmap: Threat Hunting

Overview#

This roadmap supports the eCTHP v2 course (Threat Hunting Professional) with hands-on TryHackMe labs, organized into 7 sections: fundamentals, threat hunting and detection, hunting operations and incident response, logs and SIEM with Splunk, network security and analysis, network analysis tools, and endpoint security monitoring. A references section at the end collects cheat sheets and further reading.

The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Every link opens the lab directly.

Total labs73
PlatformTryHackMe
Sections7 (plus references)

Note: two rooms, Windows Event Logs and Windows Internals, appear in more than one section because they support more than one topic, so the total counts each appearance. TryHackMe also occasionally moves rooms between free and paid, so if you find a lab that is locked, let me know and I will update the list.

Section Map#

#SectionFocusLabs
01Fundamentals & IntroLogs, threat modeling, risk, vulnerability management, and frameworks12
02Threat Hunting & DetectionThreat emulation and detection engineering12
03Threat Hunting Operations & IRHunting across the attack chain and the incident response lifecycle11
04Logs & SIEM (Splunk)Log analysis and Splunk investigations12
05Network Security & AnalysisNetwork analysis, security protocols, and architecture5
06Tools: Traffic, IDS & Packet AnalysisNetworkMiner, Snort, Zeek, Wireshark, and TShark14
07Endpoint Security MonitoringWindows internals, Sysinternals, event logs, and osquery7
08ReferencesCheat sheets and further reading7 links

Suggested Learning Path#

  1. Foundations: Fundamentals & Intro
  2. Data sources: Logs & SIEM (Splunk) -> Endpoint Security Monitoring
  3. Network visibility: Network Security & Analysis -> Tools: Traffic, IDS & Packet Analysis
  4. Detection: Threat Hunting & Detection
  5. Operations: Threat Hunting Operations & IR, which ties the earlier sections together in real hunting and response scenarios

Logs, endpoint, and network data are the raw material for every hunt, so getting comfortable with them first makes the detection and hunting sections much easier to follow.


01. Fundamentals & Intro#

Focus: Logs, threat modeling, risk, vulnerability management, and frameworks
Labs: 12

The groundwork for threat hunting: Windows event logs and internals, an introduction to threat hunting and threat modeling, risk and vulnerability management, and the frameworks (MITRE ATT&CK, Yara, MISP) that give hunters a shared language.

Fundamentals#

#LabPlatform
1Windows Event LogsTryHackMe
2Windows InternalsTryHackMe
3Introduction to Threat HuntingTryHackMe
4Threat ModellingTryHackMe

Risk & Vulnerability Management#

#LabPlatform
5Risk ManagementTryHackMe
6Vulnerability ManagementTryHackMe
7NessusTryHackMe
8OpenVASTryHackMe
9Zero LogonTryHackMe

Frameworks & Intelligence#

#LabPlatform
10MITRETryHackMe
11YaraTryHackMe
12MISPTryHackMe

02. Threat Hunting & Detection#

Focus: Threat emulation and detection engineering
Labs: 12

Emulating adversary behavior to test detections, then turning what you learn into detection rules: Atomic Red Team and Caldera for emulation, and detection engineering with Sigma, threat intelligence for the SOC, EDR, and SOAR automation.

Threat Emulation#

#LabPlatform
1Threat Emulation IntroTryHackMe
2Atomic Red TeamTryHackMe
3CalderaTryHackMe
4Atomic Bird Goes Purple #1TryHackMe
5Atomic Bird Goes Purple #2TryHackMe

Detection Engineering#

#LabPlatform
6Intro to Detection EngineeringTryHackMe
7Tactical DetectionTryHackMe
8Threat Intelligence for SOCTryHackMe
9SigmaTryHackMe
10SighuntTryHackMe
11Aurora EDRTryHackMe
12SOARTryHackMe

03. Threat Hunting Operations & IR#

Focus: Hunting across the attack chain and the incident response lifecycle
Labs: 11

Hunting adversaries from initial foothold to end game, investigating threat intelligence cases, and following the full incident response lifecycle from preparation to lessons learned.

Threat Hunting#

#LabPlatform
1Threat Hunting: FootholdTryHackMe
2Threat Hunting: PivotingTryHackMe
3Threat Hunting: EndgameTryHackMe

Threat Intelligence Investigations#

#LabPlatform
4Payment CollectorsTryHackMe
5TyposquattersTryHackMe

Incident Response Lifecycle#

#LabPlatform
6PreparationTryHackMe
7Identification and ScopingTryHackMe
8Intel Creation and ContainmentTryHackMe
9Eradication and RemediationTryHackMe
10Lessons LearnedTryHackMe

Case Study#

#LabPlatform
11TardigradeTryHackMe

04. Logs & SIEM (Splunk)#

Focus: Log analysis and Splunk investigations
Labs: 12

Turning raw logs into answers: log fundamentals and analysis, a full Splunk track from basics through SPL, dashboards, and data manipulation, and investigation challenges to test what you have learned.

Log Fundamentals#

#LabPlatform
1Intro to LogsTryHackMe
2Log OperationsTryHackMe
3Intro to Log AnalysisTryHackMe

Splunk#

#LabPlatform
4Splunk: BasicsTryHackMe
5Splunk 201TryHackMe
6Splunk: Exploring SPLTryHackMe
7Splunk: Setting up a SOC LabTryHackMe
8Splunk: Dashboards and ReportsTryHackMe
9Splunk: Data ManipulationTryHackMe
10FixitTryHackMe

Investigation Challenges#

#LabPlatform
11Investigating with SplunkTryHackMe
12BenignTryHackMe

05. Network Security & Analysis#

Focus: Network analysis, security protocols, and architecture
Labs: 5

Understanding and defending the network: analyzing Windows network activity, secure protocols, auditing and monitoring, security architecture, and a larger network challenge to apply it all.

#LabPlatform
1Windows Network AnalysisTryHackMe
2Network Security ProtocolsTryHackMe
3Auditing and MonitoringTryHackMe
4Intro to Security ArchitectureTryHackMe
5HoloTryHackMe

06. Tools: Traffic, IDS & Packet Analysis#

Focus: NetworkMiner, Snort, Zeek, Wireshark, and TShark
Labs: 14

The core network analysis toolkit for a threat hunter: traffic analysis fundamentals and NetworkMiner, intrusion detection with Snort and Zeek, and packet analysis with Wireshark and TShark, each with hands-on challenges.

Traffic Analysis & NetworkMiner#

#LabPlatform
1Traffic Analysis EssentialsTryHackMe
2NetworkMinerTryHackMe

Snort#

#LabPlatform
3SnortTryHackMe
4Snort Challenge 1TryHackMe
5Snort Challenge 2TryHackMe

Zeek#

#LabPlatform
6ZeekTryHackMe
7Zeek ExercisesTryHackMe

Wireshark#

#LabPlatform
8Wireshark: The BasicsTryHackMe
9Wireshark: Packet OperationsTryHackMe
10Wireshark: Traffic AnalysisTryHackMe

TShark#

#LabPlatform
11TShark: The BasicsTryHackMe
12TShark: CLI Wireshark FeaturesTryHackMe
13TShark Challenge ITryHackMe
14TShark Challenge IITryHackMe

07. Endpoint Security Monitoring#

Focus: Windows internals, Sysinternals, event logs, and osquery
Labs: 7

Monitoring what happens on a host: endpoint security fundamentals, Windows internals, Sysinternals, event logs, and osquery, capped with two investigation exercises.

#LabPlatform
1Intro to Endpoint SecurityTryHackMe
2Windows InternalsTryHackMe
3SysinternalsTryHackMe
4Windows Event LogsTryHackMe
5Osquery: The BasicsTryHackMe
6Monday MonitorTryHackMe
7RetractedTryHackMe

08. References#

Cheat sheets, workshop material, and further reading that complement the labs.

#ResourceType
1eCTHPv2 CertificationCertification page
2Tcpdump Cheat Sheet (PacketLife)Cheat sheet
3Wireshark Display Filters (PacketLife)Cheat sheet
4RITA Cheat Sheet (Active Countermeasures)Cheat sheet
5OMFW 2012 Case (Volatility Foundation)Workshop material
6Detecting the Elusive: Active Directory Threat Hunting (BSidesCharm 2017)Slides
7JPCERT/CC Tool Analysis Result SheetReference

Tips for Getting the Most Out of These Labs#

  • Hunt with a hypothesis. Before opening a log or a packet capture, write down what you expect to find and why. That habit is what separates hunting from browsing.
  • Take notes on every lab: the query, the artifact, and the reasoning behind it, so you can come back to them later.
  • Save your queries. Splunk searches, Sigma rules, and Wireshark filters you write become your personal hunting library.
  • Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.

These labs are for learning and practice in the provided lab environments only. Only hunt in environments and on data you are authorized to analyze.

eCTHP v2 Course Labs Roadmap: Threat Hunting
https://bad-glitch.github.io/posts/labs/ecthp---labs/ecthp/
Author
Amr Abdel Hamide
Published at
2026-09-19