

Threat Hunting: Know Normal, Find Evil
Who this workshop is for:
Security practitioners who want hands-on time building and running real threat hunts
SOC analysts and detection engineers who want to move from reactive alerting to proactive hunting
Anyone who wants a structured mindset for finding attackers who don't trigger a single alert
What's included:
Live, hands-on training, working in Splunk, not just a slide deck on methodology
Full walkthrough of a hunt from trigger to conclusion
Certificate of participation with CPE credits
Most defensive work is reactive. An alert fires, someone investigates, and the team responds.
But what if someone is already inside without you knowing?
According to the CrowdStrike Global Threat Report 2026, 82% of last year's intrusions involved no malware at all, just legitimate tools and stolen credentials. Verizon's 2026 DBIR points the same way: vulnerability exploitation is now the top way attackers break into networks, and AI has made finding and exploiting those vulnerabilities faster than ever. Once inside, attackers can stay undetected for a while.
Security solutions are built to catch known-bad. This kind of activity slips right past them.
This gap is where threat hunting comes in.
Instead of waiting for an alert, you assume an attacker may already be inside your network, and you go hunt them. It's a shift from responding to threats to proactively finding them.
What makes this workshop different:
It's built around a real hunt, from trigger to conclusion, not a theoretical framework
You work directly in Splunk, using the same tooling you'd hunt with on the job
It covers how hunting and detection complement each other, not one instead of the other
What you'll learn:
Why threat hunting matters now: the shift toward malware-free intrusions and AI-accelerated exploitation
How to adopt the threat hunter's mindset: assuming breach instead of waiting for an alert
How to build different types of hunts, and when to use each
How to take a hunt from trigger to conclusion in Splunk
How threat hunting complements, rather than replaces, detection
Learn directly from:
Mo'men Mahmoud, Content Engineer at TryHackMe