![]()
Threat Hunting using MITRE ATT&CK™ TTPs to Identify Adversarial Behaviors
As cyber threats become increasingly sophisticated, detecting known threats is no longer enough. How can security teams uncover adversary techniques before they escalate?
Discover the answer with Fortinet Threat Hunting.
In this hands-on workshop, participants will assume the role of a security analyst and be asked to identify any undetected threats on AcmeCorp’s network. To do this they will make use of MITRE ATT&CK™, which is a knowledge base of adversary behavior based on real-world observations.
Through practical exercises, participants will detect adversary techniques across key attack stages, including Initial Access, Persistence, Privilege Escalation and Command & Control.
What you will learn in this hands-on workshop:
![]()
- What is the MITRE ATT&CK framework and how it can be used
- What are the TTPs that threat actors use to carry out a breach
- Use FortiEDR Threat Hunting capabilities to uncover threats on the network
- Use FortiSIEM analytics to discover attacker behavior based on attack techniques
- Use FortiDecepter to find attacker activity and shorten attacker dwell time
Lab Objective:
Gain practical, hands-on experience using advanced analytics to uncover adversary techniques and identify malicious activity during a cyber security breach.
Agenda:
11:00 – 11:50 Presentation
11:50 – 12:00 Break
12:00 – 16:00 Fast Track Training Lab




