Introducing… Defending Enterprises
Have you taken part in our hacking enterprises training course? Our engaging 2-day ‘Defending Enterprises’ cyber threat hunting training is the natural counterpart.
Price/availability: See our events schedule for availability
Perfect for: Individuals and teams looking to expand their cyber security skills and knowledge
At In.security, our intensive cyber threat hunting simulation has been designed to teach knowledge and skills required to rapidly identify and detect malicious activity in your network.
Our trainers conduct an enterprise breach where you can gain the practical experience you need and be prepared for a real-life attack. From setup and configuration to threat hunting, monitoring and alerting, guard your organisation’s infrastructure against attackers and cyber threats with defending enterprises.

Cyber threat hunting course topics: What you’ll learn.
Defending enterprises covers a wide array of topics across the 2 days to ensure you gain the knowledge you need:
- MITRE ATT&CK, CAR and D3fend frameworks
- Defensive OSINT
- Logging and event data
- Overview of Kusto Query Language (KQL) and Microsoft Sentinel
- Identifying Indicators of Attack and Compromise (IOA and IOC)
- Detecting phishing attacks and living off the land (LOLBAS) abuse
- Detecting C2 traffic and beacons HTTPS/DNS
- Microsoft Defender for Endpoint (MDE)/Defender for Identity
- Detecting credential attacks (Kerberoasting, PtH, PtT, DCSync)
- Detecting Active Directory Certificate Services (AD CS) attacks
- Detecting lateral movement within a network
- Creating alerts and analytical rules in Microsoft Sentinel
- Cloud attacks
- Conditional Access Policies
- Azure Managed Service Accounts
- Authentication Token Abuse
- Consent Phishing and App Registrations

This threat hunting course includes.
- 14-days lab access after training completes
- Discord support channel access where our security consultants are available
- Completion certificate
What you need Prerequisites.
- Understanding of networking concepts
- Previous pentesting and/or SOC experience advantageous, but not required
Other training courses & workshops: View our upcoming events.
 
					Defending Enterprises – 2025 Edition
 
					Hacking Enterprises – 2025 Red Edition
Here to help: Defending Enterprises’ FAQs.
Our courses are delivered and accessible in a number of locations including: live virtual training at your premises or required location, through our training partners, and/or at special events and conferences throughout the year. You can find our scheduled events in our calendar.
Charges are dependent on the location of the course you’ve booked:
–	Via our training partners: Contact the respective training partner for all amendment/cancellation queries
–	At a conference or special event: Contact the respective conference/event coordinator for all amendment/cancellation queries
–	At your premises/required location or via live virtual training: No cancellation fee until 21 days before the course is scheduled to run, after which a 50% cancellation fee is incurred. Cancellations 7 days or less before the course is scheduled to run incur a 100% cancellation fee.
Of course – If your 14-day complementary access isn’t enough, you can purchase a 28-day extension.
 
					 
	 
			 
			