← All courses
$20

Threat Tradecraft: Detecting Today's TTPs

Threat-informed defense for practitioners: learn today's attacker tactics, techniques, and procedures — mapped to MITRE ATT&CK — and turn each one into a detection. Cover identity & cloud intrusions, AI-era tradecraft, endpoint living-off-the-land & EDR evasion, lateral movement & C2, and ransomware/extortion. Build a reusable TTP detection playbook. For SOC analysts, threat hunters, and detection engineers. Defensive throughout.

"We stopped chasing indicators and started detecting tradecraft: an ATT&CK-mapped TTP playbook — behavior, telemetry, detection logic, and response — that we validate and keep current"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    The ATT&CK-driven mindset — hunt behavior, not just bad hashes

    Adversaries change hashes and domains cheaply; they change how they operate slowly and painfully — so the highest-value detections target technique, not indicator.

  2. 2

    Initial access & identity — the new perimeter is a login

    Modern intrusions rarely 'break in' — they log in. Identity is the perimeter now, so the highest-signal early detections live in your IdP, cloud audit, and email telemetry.

  3. 3

    AI-era tradecraft — when the content signals stop working

    AI lets adversaries make lures flawless and personal at scale, so the old 'bad grammar' tells fail — defenders must shift to behavioral, relational, and verification signals.

  4. 4

    Execution, persistence & defense evasion — living off the land

    Modern intrusions increasingly avoid custom malware, abusing trusted OS tools and running in memory — so process lineage and command-line context become your sharpest detections.

  5. 5

    Discovery, lateral movement & C2 — the quiet middle of an intrusion

    Between the first foothold and the payoff, adversaries map, pivot, and phone home — the east-west and callback signals here are where you turn a foothold into a caught intrusion.

  6. 6

    Impact — ransomware, extortion & the living playbook

    The payoff stage — exfiltration, backup destruction, and encryption — is loud and late; catching the pre-impact staging is what saves the org, and a living playbook keeps you current.

Production patterns you'll master

ATT&CK-Mapped DetectionThreat-Informed DefensePyramid of PainBehavior over IndicatorsTelemetry-to-Analytic PipelineDetection Validation Loop

Synthetic data included

  • TTP detection playbook template
  • ATT&CK technique-to-detection mapping
  • Detection data-source guide
  • Assume-breach response runbook

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your threat tradecraft: detecting today's ttps?

First course free. $20 per course after that.