Train to become OSTH certified

TH-200 (OSTH)
Foundational Threat Hunting

The OffSec TH-200 teaches you the practical basics of threat hunting. You will learn how to proactively identify potential threats, uncover anomalies in systems and networks and recognize hidden attackers at an early stage. Through realistic scenarios and hands-on labs, you will develop a deep understanding of attacker behaviour and build the skills to systematically detect and analyze threats.

Included services

Your added value with the Red & Blue Alliance

  • Training with a strong practical orientation
  • Individually selected OffSec license (Course & Cert, Learn One, Learn Enterprise)
  • Professional team of trainers with many years of practical experience in IT security companies
  • Course language English – trainers are at least bilingual (DE/EN)
  • Catering included during the training days (for public face-to-face training courses)
  • Trainer support included – even after the course: Our Discord channel provides you with direct exchange with trainers, professional support and targeted guidance on your way to certification.

Aims of the training

TH-200 (OSTH)

The training enables you to actively search for threats and recognize security gaps at an early stage.

  • You carry out proactive threat hunting
  • You recognize suspicious patterns and anomalies
  • You analyze attacker behavior (TTPs)
  • You use data sources such as logs and telemetry effectively
  • You develop hypotheses and test them systematically

This allows you to identify attackers before they cause major damage.

Target group & requirements

Target group

The course is aimed at professionals who want to go beyond pure detection and actively search for threats.

  • Security Analysts (SOC Level 1/2)
  • Threat Hunter & Blue Team members
  • Incident Responder
  • IT administrators with a focus on security

Ideal for you if you want to expand your skills in the direction of proactive cyber defense.

Prerequisites

For the course, you should have a solid basic technical understanding and some security experience.

  • Basic knowledge of IT & networks
  • Understanding of Windows & Linux systems
  • Experience with logs or monitoring (recommended)
  • Basic understanding of attack techniques and threats
  • Analytical and hypothesis-based thinking

Knowledge at SOC-200 level is helpful, but not essential.

Seminar content

Contents of the TH-200 (OSTH)

The focus is on methods and techniques for proactively identifying threats.

  • Threat Hunting Methodology
    Structured approach for hypothesis-based hunting
  • Data Sources & Telemetry
    Use of logs, endpoint and network data
  • Windows Threat Hunting
    Analysis of Windows artifacts and attack traces
  • Linux Threat Hunting
    Identification of anomalies on Linux systems
  • Behavioral analysis
    Detection of conspicuous system and user behavior
  • Detection Techniques
    Development of detection rules and use cases
  • SIEM & Tooling
    Use of SIEM and analysis tools in the hunting process
  • Hunt Operations & Reporting
    Structuring, documentation and communication of results

The aim is to identify threats at an early stage and reduce them sustainably through a systematic approach.

The right license for your requirements

With Course & Cert, Learn One and Learn Enterprise, we offer three different learning models – from targeted certification to comprehensive, scalable training. The following overview shows the most important differences at a glance.

Course & Cert

The classic entry option for a single course.

  • 1 course + certification
  • 90 days Lab access
  • 1 examination attempt
  • Download the course materials

Ideal for you if you want to prepare specifically for certification

👉 In short: focused, affordable, but not very flexible

Learn One

Your annual subscription with significantly more options.

  • 1 200 or 300 level course + certification
  • 365 days Lab access
  • 2 exam attempts
  • Access to exercise environments, challenge labs and learning paths
  • Download the course materials

Ideal for you if you want to build up several skills or broaden your base

👉 In short: flexible, comprehensive, highly practice-oriented

Learn Enterprise

The corporate solution for structured team training.

  • Unlimited choice of courses
  • 6 examination attempts/certification per year
  • 365 days Lab access
  • Central management of users, progress and licenses
  • Reporting & analytics for training progress
  • Individual learning paths for different roles (e.g. SOC, Pentest, Blue Team)
  • Scalable for larger teams or entire departments

👉 In short: scalable, controllable, ideal for strategic training

Fancy more?

Find the training course that suits you!