eCTHP Certification
Certified Threat Hunting Professional
eCTHP is a professional-level certification that proves your threat hunting and threat identification capabilities. Students are tested through real-world scenarios modeled after cutting-edge malware that simulates corporate network vulnerabilities.
The Exam
INE Security’s eCTHP is the only certification for Threat Hunters that evaluates your abilities inside a fully featured and real-world environment.
Candidates are provided with a real world engagement within INE’s Virtual Labs. Once valid credentials are provided for the certification platform, the candidate can perform the tests from the comfort of their home or office. An Internet connection and VPN software is necessary to carry out the exam.
Knowledge Domains
By obtaining the eCTHP, your skills in the following areas will be assessed and certified:
- Network packet/traffic analysis
- Data enrichment with Threat Intelligence
- Data correlation
- In-depth knowledge of tools such as Wireshark, Redline & IOC editor
- IOC-based threat hunting
- Memory analysis/forensics
- Windows/Linux event analysis
- Log analysis
- Detection of any stage of the “Cyber Kill Chain” (Information Gathering, Exploitation, Post-exploitation)
Prerequisites
The eCTHP is a certification for individuals with a highly technical understanding of networks, systems and cyber attacks. Everyone can attempt the certification exam, however here are the advised skills necessary for a successful outcome:
- Letter of engagement and the basics related to a threat hunting engagement
- Advanced networking concepts
- Threat hunting processes and methodologies
- Packet/traffic analysis
- Enriching data with Threat Intelligence
- Familiarly with tools such as Wireshark, Redline, IOC editor, Sysmon & Volatility
- How to detect all stages of the “Cyber Kill Chain”
- Familiarity with IOC-based hunting
- Ability in analyzing memory dumps
- Good understanding of Windows events
- Ability in analyzing logs
- Manual threat detection through process analysis
- Ability in correlating data from various sources
Expiration
The current version of the eCTHP certification does not have an expiration date.
Certification Process
There are two ways to get certified.
Purchase an INE subscription and take the Threat Hunting Professional learning path.
The Threat Hunting Professional path takes you from a basic-intermediate understanding of penetration testing to a professional level. The Learning Path prepares you for the eCTHP exam with the necessary theory and a number of hands-on practical sessions in Hera Lab. Hera virtual lab in VPN, is the same environment in which you will perform your tests for the eCTHP exam.
OR
Attempt the certification without training
Feel confident in your threat hunting capabilities? INE Security offers certification vouchers for cyber security experts who feel as if they do not need the accompanying training. However, studying for the eCTHP exam by purchasing a subscription to INE’s training is highly recommended. If you’re ready for the exam now, click the link below to purchase your test.