Cover Image for Threat Hunting: Know Normal, Find Evil
Cover Image for Threat Hunting: Know Normal, Find Evil
Avatar for TryHackMe
Presented by
TryHackMe

Threat Hunting: Know Normal, Find Evil

Virtual
Get Tickets
Welcome! Please choose your desired ticket type:
About Event

​Who this workshop is for:

  • ​Security practitioners who want hands-on time building and running real threat hunts

  • ​SOC analysts and detection engineers who want to move from reactive alerting to proactive hunting

  • ​Anyone who wants a structured mindset for finding attackers who don't trigger a single alert

​What's included:

  • ​Live, hands-on training, working in Splunk, not just a slide deck on methodology

  • ​Full walkthrough of a hunt from trigger to conclusion

  • ​Certificate of participation with CPE credits

​Most defensive work is reactive. An alert fires, someone investigates, and the team responds.

​But what if someone is already inside without you knowing?

​According to the CrowdStrike Global Threat Report 2026, 82% of last year's intrusions involved no malware at all, just legitimate tools and stolen credentials. Verizon's 2026 DBIR points the same way: vulnerability exploitation is now the top way attackers break into networks, and AI has made finding and exploiting those vulnerabilities faster than ever. Once inside, attackers can stay undetected for a while.

​Security solutions are built to catch known-bad. This kind of activity slips right past them.

​This gap is where threat hunting comes in.

​Instead of waiting for an alert, you assume an attacker may already be inside your network, and you go hunt them. It's a shift from responding to threats to proactively finding them.

​What makes this workshop different:

  • ​It's built around a real hunt, from trigger to conclusion, not a theoretical framework

  • ​You work directly in Splunk, using the same tooling you'd hunt with on the job

  • ​It covers how hunting and detection complement each other, not one instead of the other

​What you'll learn:

  • ​Why threat hunting matters now: the shift toward malware-free intrusions and AI-accelerated exploitation

  • ​How to adopt the threat hunter's mindset: assuming breach instead of waiting for an alert

  • ​How to build different types of hunts, and when to use each

  • ​How to take a hunt from trigger to conclusion in Splunk

  • ​How threat hunting complements, rather than replaces, detection

​Learn directly from:
Mo'men Mahmoud, Content Engineer at TryHackMe

Avatar for TryHackMe
Presented by
TryHackMe