← All courses
CuratedAdvanced$20

Threat Tradecraft: Detecting Today's TTPs

Threat-informed defense for practitioners: turn today's attacker TTPs — mapped to MITRE ATT&CK — into detections, and build a reusable TTP detection playbook. For SOC analysts, threat hunters, and detection engineers.

Modules

6

Verified

0

In Progress

0

What you walk away with

  • A shareable portfolio URL with your project walkthrough
  • Module-by-module timeline of everything you built
  • All the code — pipelines, guardrails, deployment configs
  • Production patterns documented on your profile
Claude CodeTypeScript

The practitioner detection course of the Alset × TheDex line. Indicators change by the hour; tradecraft doesn't. This course teaches you to detect attacker behavior — mapped to MITRE ATT&CK — across the full intrusion lifecycle: initial access and identity (MFA fatigue, adversary-in-the-middle session theft, OAuth abuse), AI-era tradecraft (AI-assisted phishing, deepfake pretexting, prompt injection against your own agents), endpoint execution/persistence/evasion (living-off-the-land, process injection, EDR evasion), discovery/lateral movement/command-and-control, and impact (ransomware and data-extortion). For each, you learn the observable behavior, the telemetry that catches it, the detection logic, and the response — assembled into a living TTP detection playbook you validate and keep current. Defensive throughout: detect and defend, never attack.

Sign in to start this course