Train to become OSTH certified
TH-200: Foundational Threat Hunting
Starting at $1,749
Level
20041h of content
- Learn threat hunting basic concepts and skills, including using common tools like CrowdStrike Falcon and Splunk to detect network and endpoint Indicators of Compromise (IoCs) and respond to threats
- Earn the OffSec Threat Hunter (OSTH) certification upon passing the exam
Overview
TH-200 equips learners with essential skills to proactively detect and investigate cyber threats through behavioral analysis, threat actor profiling, and the use of network and endpoint indicators
TH-200: Foundational Threat Hunting equips learners with the essential skills and mindset to operate on the defensive side of cybersecurity. In today’s threat landscape, defenders must go beyond reactive security measures. Threat hunting is a proactive practice where security professionals seek out and identify threats before they can cause harm.
This course introduces the core concepts, tools, and methodologies used by enterprise defenders to detect, track, and respond to adversaries within networks and endpoints.
Learners will develop key capabilities, including:
- Understanding the threat actor landscape, with a focus on ransomware and Advanced Persistent Threats (APTs)
- Utilizing both network and endpoint Indicators of Compromise (IoCs) for proactive threat detection
- Highlighting the role of Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS), like Suricata, in monitoring for suspicious activities
- Explorations of various ransomware groups, including LockBit, CLOP, and BlackCat/ALPHV, with examples of how they exploit specific vulnerabilities
- Recognizing custom threat hunting, focusing on behavioral analysis and data correlation to detect advanced threats, using tools like CrowdStrike Falcon
TH-200 is organized into 7 modules with associated hands-on lab experiences and assessment questions. After completion of the content modules and labs, learners can work on a comprehensive Challenge Lab, which brings all of the skills they have learned in the course together and prepares them for the OSTH exam.
TH-200 is for anyone looking to build a strong foundation in threat hunting, including SOC analysts, IT security specialists, and those aiming to transition into specialized cybersecurity roles. While there are no course prerequisites, it is encouraged that learners have some experience in cybersecurity, a solid foundation in TCP/IP networking, and a familiarity with Linux and Windows operating systems.
Becoming OSTH certified
-
8-hour proctored
All exams are proctored by an OffSec employee in a private VPN
-
Hands-on labs
Identify, exploit, and report real-world vulnerabilities in live lab systems
-
Conduct a threat hunting sprint
Identify indicators of a compromise by a threat actor
-
Identify compromised systems
Assess the impact of attacker actions and determine if data has been exfiltrated or encrypted
OSTH certification
About the OSTH exam
The OffSec Threat Hunter certification demonstrates proficiency in foundational threat hunting practices
Start learning with OffSec
$2,749/year*
Best value
Learn One
Includes one year of access to one 200 or 300-level course, the associated labs, and two exam attempts
$1,749/once
Most popular
Course + Cert Bundle
Includes 90 days of access to one 200 or 300-level course, the associated labs, and a single exam attempt
Train your team with OffSec
$6,099/year*
All access
Learn Unlimited
Unlimited OffSec Learning Library access plus unlimited exam attempts for one year
Get a quote
Large teams
Learn Enterprise
Unlimited OffSec Learning Library access with flexible terms and volume discounts available
Validate your expertise.
Amplify your impact.
-
Mindset & work ethic
Instill a relentless problem-solving mindset that employers value highly in security professionals
-
Globally recognized certification
OffSec certs build elite, hands-on skills trusted by the world's top companies
-
Organization value & trust
Trusted to train skilled, consistent, and reliable security teams
-
Certified candidates win
91% of respondents prefer to hire candidates with certifications (Fortinet, 2024 Cybersecurity Skills Gap Report)

Realistic lab environments
Built to sharpen skills through practical, immersive learning
Request a free trial
-
On-demand lab access
Train anytime in up-to-date, practical, cutting-edge labs
-
Structured learning modules
Progress through clear, goal-driven topics
-
Challenge-based learning
Build skills through real-world, hands-on challenges
-
AI-powered learning assisstant
Get instant, guided help with complex topics
Success stories from the field
Excited to share that I've successfully passed OffSec's brand-new Threat Hunter (OSTH) exam! The exam was an 8-hour hands-on challenge, followed by a report on my findings, which were both graded by OffSec. I had a great time with the course, working with Splunk, CrowdStrike Falcon, and Wireshark. Big thanks to the team for creating such an awesome experience!