Get your OSTH certification with TH-200 | OffSec

Train to become OSTH certified

TH-200: Foundational Threat Hunting

Starting at $1,749

Level

200
|

41h of content

  • Learn threat hunting basic concepts and skills, including using common tools like CrowdStrike Falcon and Splunk to detect network and endpoint Indicators of Compromise (IoCs) and respond to threats
  • Earn the OffSec Threat Hunter (OSTH) certification upon passing the exam

Overview

TH-200 equips learners with essential skills to proactively detect and investigate cyber threats through behavioral analysis, threat actor profiling, and the use of network and endpoint indicators

TH-200: Foundational Threat Hunting equips learners with the essential skills and mindset to operate on the defensive side of cybersecurity. In today’s threat landscape, defenders must go beyond reactive security measures. Threat hunting is a proactive practice where security professionals seek out and identify threats before they can cause harm.

This course introduces the core concepts, tools, and methodologies used by enterprise defenders to detect, track, and respond to adversaries within networks and endpoints.

Learners will develop key capabilities, including:

  • Understanding the threat actor landscape, with a focus on ransomware and Advanced Persistent Threats (APTs)
  • Utilizing both network and endpoint Indicators of Compromise (IoCs) for proactive threat detection
  • Highlighting the role of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), like Suricata, in monitoring for suspicious activities
  • Explorations of various ransomware groups, including LockBit, CLOP, and BlackCat/ALPHV, with examples of how they exploit specific vulnerabilities
  • Recognizing custom threat hunting, focusing on behavioral analysis and data correlation to detect advanced threats, using tools like CrowdStrike Falcon

TH-200 is organized into 7 modules with associated hands-on lab experiences and assessment questions. After completion of the content modules and labs, learners can work on a comprehensive Challenge Lab, which brings all of the skills they have learned in the course together and prepares them for the OSTH exam.

TH-200 is for anyone looking to build a strong foundation in threat hunting, including SOC analysts, IT security specialists, and those aiming to transition into specialized cybersecurity roles. While there are no course prerequisites, it is encouraged that learners have some experience in cybersecurity, a solid foundation in TCP/IP networking, and a familiarity with Linux and Windows operating systems.

Becoming OSTH certified

  • 8-hour proctored

    All exams are proctored by an OffSec employee in a private VPN

  • Hands-on labs

    Identify, exploit, and report real-world vulnerabilities in live lab systems

  • Conduct a threat hunting sprint

    Identify indicators of a compromise by a threat actor

  • Identify compromised systems

    Assess the impact of attacker actions and determine if data has been exfiltrated or encrypted

OSTH certification

About the OSTH exam

The OffSec Threat Hunter certification demonstrates proficiency in foundational threat hunting practices

Start learning with OffSec

$2,749/year*

Best value

Learn One

Includes one year of access to one 200 or 300-level course, the associated labs, and two exam attempts

$1,749/once

Most popular

Course + Cert Bundle

Includes 90 days of access to one 200 or 300-level course, the associated labs, and a single exam attempt

Train your team with OffSec

$6,099/year*

All access

Learn Unlimited

Unlimited OffSec Learning Library access plus unlimited exam attempts for one year

Get a quote

Large teams

Learn Enterprise

Unlimited OffSec Learning Library access with flexible terms and volume discounts available

Validate your expertise.
Amplify your impact.

  • Mindset & work ethic

    Instill a relentless problem-solving mindset that employers value highly in security professionals

  • Globally recognized certification

    OffSec certs build elite, hands-on skills trusted by the world's top companies

  • Organization value & trust

    Trusted to train skilled, consistent, and reliable security teams

  • Certified candidates win

    91% of respondents prefer to hire candidates with certifications (Fortinet, 2024 Cybersecurity Skills Gap Report)

View of the PEN-200 syllabus in the OffSec portal

Realistic lab environments

Built to sharpen skills through practical, immersive learning

Request a free trial
View of the PEN-200 syllabus in the OffSec portal
  • On-demand lab access

    Train anytime in up-to-date, practical, cutting-edge labs

  • Structured learning modules

    Progress through clear, goal-driven topics

  • Challenge-based learning

    Build skills through real-world, hands-on challenges

  • AI-powered learning assisstant

    Get instant, guided help with complex topics

Success stories from the field

Day Johnson Security Engineer
Excited to share that I've successfully passed OffSec's brand-new Threat Hunter (OSTH) exam! The exam was an 8-hour hands-on challenge, followed by a report on my findings, which were both graded by OffSec. I had a great time with the course, working with Splunk, CrowdStrike Falcon, and Wireshark. Big thanks to the team for creating such an awesome experience!
FC
Forrest Connelly Cyber Threat Hunter

TH-200 FAQ