Threat Tradecraft: Detecting Today's TTPs
Threat-informed defense for practitioners: learn today's attacker tactics, techniques, and procedures — mapped to MITRE ATT&CK — and turn each one into a detection. Cover identity & cloud intrusions, AI-era tradecraft, endpoint living-off-the-land & EDR evasion, lateral movement & C2, and ransomware/extortion. Build a reusable TTP detection playbook. For SOC analysts, threat hunters, and detection engineers. Defensive throughout.
"We stopped chasing indicators and started detecting tradecraft: an ATT&CK-mapped TTP playbook — behavior, telemetry, detection logic, and response — that we validate and keep current"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
The ATT&CK-driven mindset — hunt behavior, not just bad hashes
Adversaries change hashes and domains cheaply; they change how they operate slowly and painfully — so the highest-value detections target technique, not indicator.
- 2
Initial access & identity — the new perimeter is a login
Modern intrusions rarely 'break in' — they log in. Identity is the perimeter now, so the highest-signal early detections live in your IdP, cloud audit, and email telemetry.
- 3
AI-era tradecraft — when the content signals stop working
AI lets adversaries make lures flawless and personal at scale, so the old 'bad grammar' tells fail — defenders must shift to behavioral, relational, and verification signals.
- 4
Execution, persistence & defense evasion — living off the land
Modern intrusions increasingly avoid custom malware, abusing trusted OS tools and running in memory — so process lineage and command-line context become your sharpest detections.
- 5
Discovery, lateral movement & C2 — the quiet middle of an intrusion
Between the first foothold and the payoff, adversaries map, pivot, and phone home — the east-west and callback signals here are where you turn a foothold into a caught intrusion.
- 6
Impact — ransomware, extortion & the living playbook
The payoff stage — exfiltration, backup destruction, and encryption — is loud and late; catching the pre-impact staging is what saves the org, and a living playbook keeps you current.
Production patterns you'll master
Synthetic data included
- TTP detection playbook template
- ATT&CK technique-to-detection mapping
- Detection data-source guide
- Assume-breach response runbook
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your threat tradecraft: detecting today's ttps?
First course free. $20 per course after that.