Cover Image for Threat Hunting: Know Normal, Find Evil
Cover Image for Threat Hunting: Know Normal, Find Evil
Avatar for TryHackMe
Presented by
TryHackMe

Threat Hunting: Know Normal, Find Evil

Google Meet
Get Tickets
Ticket Price
$200.00
Welcome! To join the event, please get your ticket below.
About Event

Who this workshop is for:

  • Security practitioners who want hands-on time building and running real threat hunts

  • SOC analysts and detection engineers who want to move from reactive alerting to proactive hunting

  • Anyone who wants a structured mindset for finding attackers who don't trigger a single alert

What's included:

  • Live, hands-on training, working in Splunk, not just a slide deck on methodology

  • Full walkthrough of a hunt from trigger to conclusion

  • Certificate of participation with CPE credits

Most defensive work is reactive. An alert fires, someone investigates, and the team responds.

But what if someone is already inside without you knowing?

According to the CrowdStrike Global Threat Report 2026, 82% of last year's intrusions involved no malware at all, just legitimate tools and stolen credentials. Verizon's 2026 DBIR points the same way: vulnerability exploitation is now the top way attackers break into networks, and AI has made finding and exploiting those vulnerabilities faster than ever. Once inside, attackers can stay undetected for a while.

Security solutions are built to catch known-bad. This kind of activity slips right past them.

This gap is where threat hunting comes in.

Instead of waiting for an alert, you assume an attacker may already be inside your network, and you go hunt them. It's a shift from responding to threats to proactively finding them.

What makes this workshop different:

  • It's built around a real hunt, from trigger to conclusion, not a theoretical framework

  • You work directly in Splunk, using the same tooling you'd hunt with on the job

  • It covers how hunting and detection complement each other, not one instead of the other

What you'll learn:

  • Why threat hunting matters now: the shift toward malware-free intrusions and AI-accelerated exploitation

  • How to adopt the threat hunter's mindset: assuming breach instead of waiting for an alert

  • How to build different types of hunts, and when to use each

  • How to take a hunt from trigger to conclusion in Splunk

  • How threat hunting complements, rather than replaces, detection

Learn directly from:
Mo'men Mahmoud, Content Engineer at TryHackMe

Avatar for TryHackMe
Presented by
TryHackMe