Overview#
This roadmap supports the eCTHP v2 course (Threat Hunting Professional) with hands-on TryHackMe labs, organized into 7 sections: fundamentals, threat hunting and detection, hunting operations and incident response, logs and SIEM with Splunk, network security and analysis, network analysis tools, and endpoint security monitoring. A references section at the end collects cheat sheets and further reading.
The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Every link opens the lab directly.
| |
|---|
| Total labs | 73 |
| Platform | TryHackMe |
| Sections | 7 (plus references) |
Note: two rooms, Windows Event Logs and Windows Internals, appear in more than one section because they support more than one topic, so the total counts each appearance. TryHackMe also occasionally moves rooms between free and paid, so if you find a lab that is locked, let me know and I will update the list.
Section Map#
| # | Section | Focus | Labs |
|---|
| 01 | Fundamentals & Intro | Logs, threat modeling, risk, vulnerability management, and frameworks | 12 |
| 02 | Threat Hunting & Detection | Threat emulation and detection engineering | 12 |
| 03 | Threat Hunting Operations & IR | Hunting across the attack chain and the incident response lifecycle | 11 |
| 04 | Logs & SIEM (Splunk) | Log analysis and Splunk investigations | 12 |
| 05 | Network Security & Analysis | Network analysis, security protocols, and architecture | 5 |
| 06 | Tools: Traffic, IDS & Packet Analysis | NetworkMiner, Snort, Zeek, Wireshark, and TShark | 14 |
| 07 | Endpoint Security Monitoring | Windows internals, Sysinternals, event logs, and osquery | 7 |
| 08 | References | Cheat sheets and further reading | 7 links |
Suggested Learning Path#
- Foundations: Fundamentals & Intro
- Data sources: Logs & SIEM (Splunk) -> Endpoint Security Monitoring
- Network visibility: Network Security & Analysis -> Tools: Traffic, IDS & Packet Analysis
- Detection: Threat Hunting & Detection
- Operations: Threat Hunting Operations & IR, which ties the earlier sections together in real hunting and response scenarios
Logs, endpoint, and network data are the raw material for every hunt, so getting comfortable with them first makes the detection and hunting sections much easier to follow.
01. Fundamentals & Intro#
Focus: Logs, threat modeling, risk, vulnerability management, and frameworks
Labs: 12
The groundwork for threat hunting: Windows event logs and internals, an introduction to threat hunting and threat modeling, risk and vulnerability management, and the frameworks (MITRE ATT&CK, Yara, MISP) that give hunters a shared language.
Risk & Vulnerability Management#
Frameworks & Intelligence#
02. Threat Hunting & Detection#
Focus: Threat emulation and detection engineering
Labs: 12
Emulating adversary behavior to test detections, then turning what you learn into detection rules: Atomic Red Team and Caldera for emulation, and detection engineering with Sigma, threat intelligence for the SOC, EDR, and SOAR automation.
03. Threat Hunting Operations & IR#
Focus: Hunting across the attack chain and the incident response lifecycle
Labs: 11
Hunting adversaries from initial foothold to end game, investigating threat intelligence cases, and following the full incident response lifecycle from preparation to lessons learned.
Threat Intelligence Investigations#
Incident Response Lifecycle#
04. Logs & SIEM (Splunk)#
Focus: Log analysis and Splunk investigations
Labs: 12
Turning raw logs into answers: log fundamentals and analysis, a full Splunk track from basics through SPL, dashboards, and data manipulation, and investigation challenges to test what you have learned.
Investigation Challenges#
05. Network Security & Analysis#
Focus: Network analysis, security protocols, and architecture
Labs: 5
Understanding and defending the network: analyzing Windows network activity, secure protocols, auditing and monitoring, security architecture, and a larger network challenge to apply it all.
Focus: NetworkMiner, Snort, Zeek, Wireshark, and TShark
Labs: 14
The core network analysis toolkit for a threat hunter: traffic analysis fundamentals and NetworkMiner, intrusion detection with Snort and Zeek, and packet analysis with Wireshark and TShark, each with hands-on challenges.
Traffic Analysis & NetworkMiner#
07. Endpoint Security Monitoring#
Focus: Windows internals, Sysinternals, event logs, and osquery
Labs: 7
Monitoring what happens on a host: endpoint security fundamentals, Windows internals, Sysinternals, event logs, and osquery, capped with two investigation exercises.
08. References#
Cheat sheets, workshop material, and further reading that complement the labs.
Tips for Getting the Most Out of These Labs#
- Hunt with a hypothesis. Before opening a log or a packet capture, write down what you expect to find and why. That habit is what separates hunting from browsing.
- Take notes on every lab: the query, the artifact, and the reasoning behind it, so you can come back to them later.
- Save your queries. Splunk searches, Sigma rules, and Wireshark filters you write become your personal hunting library.
- Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.
These labs are for learning and practice in the provided lab environments only. Only hunt in environments and on data you are authorized to analyze.