Threat Hunting Labs

Threat Hunting Labs is a hands-on investigation training platform for threat hunters, detection engineers, incident responders, and SOC analysts. Learners investigate intrusion evidence using the kinds of search, analysis, and reporting workflows used in security operations.

The platform is built around practical cases and focused Flash Hunts. Each investigation asks learners to examine telemetry, test hypotheses, follow evidence across events, and explain what happened. Guided support is available where a case provides it, while scoring and debriefs help learners understand both their conclusions and their investigative process.

Practice evidence-led threat hunting

Browse the mission catalog to find investigations across endpoint, identity, cloud, email, and network evidence. Public catalog pages explain the available content and access requirements. Starting or continuing learner activities may require signing in and holding the appropriate free, subscriber, team, or event entitlement.

Explore Threat Hunting Labs

AI agents and other automated clients can request a Markdown representation of this homepage with the Accept: text/markdown header. See llms.txt for specific when-to-use guidance and the sitemap for published public resources.