Advanced Threat Hunting and Incident Response
📅 Date: 19 – 21 November 2025
📍 Venue: Anggerik Room, Level 9, Holiday Inn Express Kuala Lumpur City Centre, 84 Jalan Raja Chulan, 50200 Kuala Lumpur
🗺️ Google Map: https://maps.app.goo.gl/Ujb9FSsWj2XGECnGA
⏰ Registration: 9.00AM. Training Time: 9:30 AM – 5:00 PM
Program Overview
This training program is designed for security analysts, incident response analysts, SOC(Security Operations Center) professionals, cyber investigators, and threat intelligence analysts. It offers an in-depth exploration of advanced threat hunting techniques and effective incident response strategies.
Participants will learn to analyze the attack techniques actually used by APT(Advanced Persistent Threat) groups and conduct attack simulations to understand how to collect threat intelligence related to these attacks. The program then focuses on converting theoretical knowledge into practical skills through scenario-based analysis exercises of real APT breach incidents.
Additionally, the curriculum covers how AI can be leveraged for collecting threat intelligence and data, providing foundational AI knowledge and demonstrating what types of AI can be utilized for these purposes.
Target Audience
- Cyber Security Analysts
- Cyber Incident Response Analysts
- SOC(Security Operations Center) Professionals
- Cyber Investigators
- Threat Hunters.
Knowledge Prerequisites
- Basic knowledge of Windows and Linux
- Basic system commands on Windows and Linux
- Basic knowledge of networks such as TCP, UDP, IP, etc
Hardware Requirements
- OS : Windows 10 or 11
- HDD : More 200GB free space
- Memory : 16GB
- Required S/W : VMWare Workstation
Trainers: Moonbeom Park & Sangsoo Jeong
Moonbeom and Sangsoo working at 78ResearchLab (http://www.78researchlab.com) in South Korea, a company specialising in the development of cyber warfare tactics and offensive and attack technologies. They analyse the cyber warfare strategies of Advanced Persistent Threat (APT) groups and conduct research on of attack techniques such as 0-day vulnerabilities and develop various cyber weapons, exploits, post-exploitation techniques that can be utilized in cyber warfare operations.

Moonbeom Park
CPO (Chief Product Officer) @78ResearchLab. Former senior researcher of KrCERT/CC & KISA

Sangsoo Jeong
Offensive vulnerability researcher @78ResearchLab. Former Red Team leader of global company
Training Agenda
Introduction to Advanced Threat Hunting
- What is threat hunting and why is it crucial?
- Transition from reactive to proactive security
- Key objectives and benefits of threat hunting
- Understanding the latest attack trends and threat landscape (in-depth analysis of Cyber Kill Chain, MITRE ATT&CK Framework)
Threat Hunting Methodologies and Techniques
- Hypothesis Based Threat Hunting : Hypothesis formulation, data collection, analysis, and validation
- IOC (Indicator of Compromise) Based Threat Hunting : Detection using known IOCs
- TTP (Tactics, Techniques, and Procedures) Based Threat Hunting : Analyzing attacker behavior patterns
- Behavior Based Threat Hunting : Detecting anomalous activities
- Key Data Sources : Endpoint logs, network trac, security appliance logs, etc
Advanced Techniques for Data Collection and Analysis
- Analyzing large volumes of logs using general commands
- Leveraging Security Information and Event Management (SIEM) Systems: Analyzing large volumes of logs using Splunk, ELK Stack, etc
- Utilizing Endpoint Detection and Response (EDR) Solutions: Advanced threat detection and analysis
- Network Forensics Tools : Analyzing network trac with Wireshark, Zeek, etc
- Advanced Search Language Proficiency : SPL (Splunk Processing Language), KQL (Kusto Query Language), etc
Hands-on Lab: Scenario-Based Threat Hunting Analysis
- Analyzing real attack scenarios based on MITRE ATT&CK (e.g., APT Attacks)
- Tracing attacker activities using provided log data
- Practical exercises in identifying anomalies and validating hypotheses
Major State-sponsored APT Attack Groups
- Analysis of key attack tactics and attack techniques
- Analysis and modeling of key attack tactics based on MITRE ATT&CK
- Analysis of major APT attack incident cases
Main attack techniques used in APT attack process
- Spear Phishing E-Mail Attack
- Exploit documentation application (MS-Office) vulnerability
- Exploit web browser application (Chrome, FireFox) vulnerability – Privilege escalation on Windows
OS - Using PowerShell for Post-Exploitation
- Advanced techniques for evading Anti-Virus detection
- DLL Injection techniques for persistence of attack state
- Key logging and reverse connection for lateral movement
Analysis of real APT attack incident cases
- Specific APT attack incident analysis and case study
- Comprehensive incident scenarios (e.g., ransomware attack, data breach)
Analysis technique for each stage of attacker’s behavior
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Exfiltration
Fundamentals and Deep Dive into AI-Powered Threat Hunting
- Differences and advantages of AI-based threat hunting versus traditional methods
- The role of AI within the threat hunting life cycle
- Overview of core competencies and tools for AI-driven threat hunting
Data Collection and Preprocessing for Threat Hunting
- Techniques for data normalization, cleaning, and feature extraction
- Methods for constructing datasets suitable for threat hunting
- Hands-on Lab : Exploring and preprocessing real security datasets
Machine Learning-Based Threat Detection and Analysis
- Identifying abnormal behaviors using clustering algorithms (K-means, DBSCAN)
- Detecting malware and phishing using Ensemble Learning (Random Forest, Gradient Boosting)
- Basics of Deep Learning (Neural Networks) and utilizing Natural Language Processing (NLP) for
threat intelligence analysis
AI-Powered APT Group Profiling Techniques
- Utilizing Text Mining and NLP to analyze threat reports (identifying attacker tactics, tools)
- Employing Graph Neural Networks (GNNs) for attack path and relationship analysis
- Behavior-based feature extraction and similarity analysis for classifying attack groups
AI-Powered Automated Threat Response (SOAR) and Orchestration
- Concepts and roles of Security Orchestration, Automation, and Response (SOAR)
- Developing AI-driven playbooks and building automated response flows
- Potential of autonomous response systems using Reinforcement Learning
- Strategies for optimizing AI models to reduce false positives and false negatives

