
Threat Hunter — career path
StationX Advanced
The defender who goes looking. Security+ and SOC fundamentals first, then packet analysis, intelligence, ATT&CK and detection engineering, then CySA+ to certify it.
The path
Step 1 — Security foundation
The baseline every SOC hires for.
follows a certification path
Learn
- PathFollow the CompTIA Security+ (SY0-701) path — the entry certification for every blue-team role
Step 2 — SOC foundations
Know what a security operations centre does all day before you hunt in one.
2 courses · 15 labs
Learn
- CourseBlue Team Boot Camp: Defending Against Hackers 🔒 StationX Unlimited
6 sections · 60 lectures
- Training Overview 2
- Section 1: Introduction 3
- Section 2: Risk Analysis and Threat Intelligence 6
- Section 3: Endpoint Security 26
- Section 4: Network Security 13
- Section 5: Log Aggregation and Correlation 10
- CourseSOC for Blue Teams 🔒 StationX Unlimited
11 sections · 21 lectures
- Training Overview 2
- Section : Introduction to Cyber Defense 2
- Section : Understanding Adversary Tactics 2
- Section : Roles and Responsibilities in Cyber Operations 1
- Section : Cyber Threat Landscape and Frameworks 2
- Section : Log Analysis and Threat Detection 2
- Section : Introduction to Malware Analysis 3
- Section : Malware Analysis Techniques and Tactics 2
- Section : Malware Analysis Process 1
- Section : Network and File-Based Malware Analysis 3
- Audio Version of Training 1
Practise
- Labs+Security Operations Practitioner — 15 labs 🔒 StationX Labs+
- Design, Defend, and Respond Across an End-to-End Security Architecture [Expert]
- Enforce Segmentation and Approved Access Paths [Guided]
- Establish a Windows Hardening and Security Logging Baseline [Guided]
- Establish centralized logging by onboarding hosts and validating monitoring readiness [Guided]
- Govern, Detect, Hunt, and Respond Through an Integrated Security Operations Sprint [Advanced]
- Governance and Compliance Evidence Collection [Guided]
- Harden a JumpBox for Secure Administration [Guided]
- Hunt Threats Using Intelligence and Rule-Based Detection [Guided]
- Implement TLS and Certificate Controls for a Service [Guided]
- Integrated Hardening Sprint A: Segment, Harden, and Secure Services [Advanced]
- Prioritize Risks and Implement One Remediation [Guided]
- Reduce DVWA Exposure by Using Compensating Controls [Guided]
- Secure Privileged Access and Auditing in Active Directory [Guided]
- Threat Modeling to Controls: Identify Risks and Implement Mitigations [Guided]
- Triage, Contain, and Automate Incident Response [Guided]
Step 3 — Network analysis
Read packets and write the rule that catches the next one.
2 courses · 11 labs
Learn
- CourseMaster Wireshark 3 in 5 Days 🔒 StationX Unlimited
6 sections · 34 lectures
- Training Overview 2
- Day One 3
- Day Two 8
- Day Three 7
- Day Four 7
- Day Five 7
- CourseSnort Intrusion Detection, Rule Writing, and PCAP Analysis 🔒 StationX Unlimited
3 sections · 16 lectures
- Training Overview 2
- Lectures 1
- Hands-on Labs 13
Practise
- Labs+Introduction to Wireshark — 11 labs 🔒 StationX Labs+
- Can You Customize Profiles and Filters in Wireshark? [Advanced]
- Can You Display Customizations and Exploration of Captured Traffic by Using Wireshark? [Advanced]
- Can You Explore the Varied Uses of Wireshark? [Expert]
- Can You Extract Intercepted Files and Perform Password Attack Discovery? [Advanced]
- Implement Wireshark [Guided]
- Modify Display Filter Functionality [Guided]
- Perform an Effective Capture [Guided]
- Recreate Data Content [Guided]
- Recreate Data Flows [Guided]
- Use Display Filters [Guided]
- Use Wireshark to Discover Evidence of Network Attacks [Guided]
Step 4 — Intelligence and ATT&CK
Turn threat intelligence into hunting hypotheses mapped to the framework hunters speak.
2 courses
Learn
- CourseMITRE ATT&CK Framework Essentials 🔒 StationX Unlimited
6 sections · 35 lectures
- Training Overview 2
- Section 1: Introduction 9
- Section 2: Tactics, Techniques, and Procedures (TTP's) 12
- Section 3: Other Learning Resources 4
- Section 4: Update - Adversarial Threat Landscape for AI Systems 7
- Audio Version of Training 1
- CourseCyber Threat Intelligence - Basics & Fundamentals 🔒 StationX Unlimited
11 sections · 68 lectures
- Training Overview 2
- Introduction 4
- Definitions & Fundamentals 15
- Cyber Threat Intelligence Objectives 6
- CTI Specific Models 15
- CTI Reports - Examples 3
- Use case 1 - Ransomware group Primo-Analysis 8
- Use Case 2 - Darkweb Monitoring 8
- Use Case 3 - Adversary Controlled Infrastructure Hunting 5
- Conclusion 1
- Audio Version of the Training 1
Step 5 — Detection and AI-assisted hunting
Find rootkits and persistence by hand, then let AI speed the triage.
1 course · 12 labs
Learn
- CourseChatGPT for SOC Analyst: Master Cyber Security with AI 🔒 StationX Unlimited
7 sections · 59 lectures
- Training Overview 2
- A Sneek Peek into Cyber Security Mastery with ChatGPT 1
- Getting Started with ChatGPT for Cyber Security 17
- Advanced Prompts with ChatGPT 5 for Cyber Security Analyst 16
- Master Cloud Security with ChatGPT in Azure 11
- Enhance Incident Investigation with ChatGPT and SIEM Solution 11
- Audio Version of Training 1
Practise
- LabsRootkits & Threat Detection — 12 labs 🔒 StationX Unlimited
- Analyze Structured Exception Handler Buffer Overflow Exploit
- CTF Environment
- Creating a Case in FTK
- Detect Unauthorized Changes by Comparing to Approved Configurations
- Identify Rootkit and DLL Injection Activity
- Identifying Anomalous ARP
- Man In the Middle Crypto Attack
- Personal Security Products
- Snort Signatures, IDS Tuning, and Blocking
- Whitelisting & Suspicious File Verification
- x86 Buffer Overflows - Part 1
- x86 Buffer Overflows - Part 2
Step 6 — Certify it
The analyst certification, with the intelligence, SIEM and incident-response labs.
follows a certification path
Learn
- PathFollow the CompTIA CySA+ (CS0-003) path — the threat-intelligence, detection and SIEM labs live on this path
Where this leads
Advanced · after the job
The AI-Driven Threat Hunter
Senior roles are going to the people who can direct AI to build security solutions. When you're working in the role and ready for that step, the AI Master's Program is where it's taught — an advanced, application-only programme.
See the AI Master's Program →Application-only. A separate programme for when you're ready.