Threat Hunting Labs
Threat Hunting Labs is a hands-on investigation training platform for threat hunters, detection engineers, incident responders, and SOC analysts. Learners investigate intrusion evidence using the kinds of search, analysis, and reporting workflows used in security operations.
The platform is built around practical cases and focused Flash Hunts. Each investigation asks learners to examine telemetry, test hypotheses, follow evidence across events, and explain what happened. Guided support is available where a case provides it, while scoring and debriefs help learners understand both their conclusions and their investigative process.
Practice evidence-led threat hunting
Browse the mission catalog to find investigations across endpoint, identity, cloud, email, and network evidence. Public catalog pages explain the available content and access requirements. Starting or continuing learner activities may require signing in and holding the appropriate free, subscriber, team, or event entitlement.
Explore Threat Hunting Labs
- Browse threat hunting cases and Flash Hunts
- Learn how the investigation labs work
- Review plans and access options
- Read frequently asked questions
- Read practical threat hunting articles
AI agents and other automated clients can request a Markdown representation of this homepage with the Accept: text/markdown header. See llms.txt for specific when-to-use guidance and the sitemap for published public resources.