Loading…

Subject: Threat Hunting and Red Teaming clear filter
arrow_back View All Dates
Thursday, September 10
 

8:00am CDT

CQURE Masterclass: System Forensics, Incident Handling & Threat Hunting
LIMITED
Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Limited Capacity seats available
System Forensics followed by Threat Hunting and Incident Readiness are constantly evolving and crucial topics in the area of cybersecurity. In order to stay ahead of cyber-criminals, the knowledge of Individuals and Teams responsible for threat hunting, collecting digital evidence, and handling the incidents has to be constantly enhanced and updated.

This course offers a comprehensive, hands-on approach to mastering system forensics, incident handling, and threat hunting, equipping participants with the skills to detect, investigate, and respond to advanced cyber threats. Through case studies, practical labs, and real-world examples, participants will gain expertise in identifying and mitigating modern attacks across various environments. Key learning themes include:


1. Windows Internals & System Forensics: Understand Windows internals, including processes, threads, and permissions. Learn to gather volatile data, audit system configurations, and detect malicious or unnecessary services using tools like PowerShell


2. Malware Analysis and Incident Handling: Gain hands-on experience in analyzing malware, including static and behavioral techniques. Learn how to detect, contain, and eradicate malware, while mastering the steps for gathering evidence, preventing incidents, and recovering from attacks.


3. Network Forensics & Monitoring: Learn advanced network forensics techniques to detect data exfiltration, webshells, and lateral movement. Explore how to analyze network traffic, logs, and protocols to uncover attack indicators, and apply these skills to mitigate threats


4. Memory Forensics & Incident Response: learn how to analyze memory dumps with tools like Volatility. Understand how to detect malicious code and trace system compromises in memory, with practical examples from high-profile incidents.


5. Disk Forensics & Data Recovery: Master storage acquisition and disk forensics techniques, including image mounting, file system analysis, and recovering deleted data.


6. Advanced Threat Hunting & Detection: Develop advanced threat-hunting strategies to uncover hidden threats and internal reconnaissance. Use practical techniques for detecting privilege escalation, lateral movement, and other adversary tactics to proactively defend against advanced attacks.


This course is designed for professionals in digital forensics, incident response, and security operations who wish to deepen their expertise in modern threat detection and response. By combining in-depth technical knowledge with real-world training, participants will be equipped to effectively handle the evolving challenges in cybersecurity and incident management.


Prerequisites: To fully benefit from our masterclass System Forensics, Incident Handling and Threat Hunting, participants should have a solid background in identity management and a general understanding of IT security concepts. Skills in log analysis and a knowledge of authentication mechanisms will also be helpful. Intermediate participants will gain solid fundamentals, while advanced users can deepen their expertise and explore the latest techniques.
Trainers
avatar for Amr Thabet

Amr Thabet

Cybersecurity Expert, CQURE
Amr Thabet is a malware researcher and incident handler with over 16 years of experience, he worked in some of the Fortune 500 companies.  He is the founder of MalTrak and the author of "Mastering Malware Analysis" published by Packt Publishing. He is a speaker and an instructor... Read More →
avatar for Paula Januszkiewicz

Paula Januszkiewicz

CEO and Founder, Microsoft MVP and RD, CQURE
Paula Januszkiewicz is the Founder and CEO of CQURE and CQURE Academy, globally recognized organizations delivering cutting-edge cybersecurity consulting and advanced training since 2008. She is an Enterprise Security MVP, Microsoft Regional Director, and one of the world’s leading... Read More →
Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Microsoft Technology Center (Aon Center)

8:00am CDT

Defending Enterprises - 2026 Edition
LIMITED
Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Limited Capacity seats available
Updated for 2026, our immersive 2-day Defending Enterprises training is the natural counterpart to our popular Hacking Enterprises course.


Not only have several existing topics had major tweaks; the training includes an entirely new section on Entra ID and Azure cloud based attacks! 


You’ll play a SOC analyst in our Microsoft Sentinel cloud-based lab and try to rapidly locate IOA’s and IOC’s from a live enterprise breach executed by the trainers in real time.
Whether you’re new to Kusto Query Language (KQL) or a seasoned pro, there’s plenty for you in the 2-days! Yes, we’re using Microsoft Sentinel, but the underlying threat detection theory, logic and threat hunting approach is transferable into your own environments, whatever your preferred platform.


We look at the top 10+ methods we use in offensive engagements and show how these can be caught, along with numerous other examples and methods that go above and beyond these common TTPs!


This training goes beyond threat hunting as we peek into the world of detection engineering and the processes involved in converting logic into alerts!
With 14 hands-on exercises, many of which also featuring extra time and bonus content, you’ll gain real-world experience in the following areas:


* Introduction to Kusto Query Language (KQL)
* Reviewing popular phishing attacks and living off the land techniques
* Locating C2 traffic and beaconing activity
* Detecting persistence activities
* Digging into credential exploitation (Kerberoasting, Pass-the-Hash, Pass-the-Ticket, DCSync)
* Reviewing Active Directory Certificate Services (AD CS) attacks
* Identifying lateral movement (WinRM, SMB)
* Cloud Attacks (Entra ID Enumeration, Azure IMDS, Authentication Tokens, Conditional Access, App Registrations)
* + much more!


We know 2 days isn't a lot of time, so you'll also get 14-days FREE lab time after class and Discord access for support.

Prerequisites: Detection methods will be taught during training, however an understanding of KQL concepts would be beneficial, and previous SOC experience and/or pentesting is advantageous but not required.
Trainers
avatar for Jeroen

Jeroen "Jay" Hoof

Instructor, SANS
Jeroen Hoof is a SANS Certified Instructor Candidate for SEC504: Hacker Tools, Techniques, and Incident Handling and a Security Operations Specialist at Davinsi Labs, where he specializes in intrusion analysis, SOC operations and detection engineering. With a career spanning law enforcement investigations, SOC operations, and cyber breach response, Jeroen brings a practitioner’s perspective... Read More →
avatar for Owen Shearing

Owen Shearing

Director, In.security
Owen (@rebootuser) is a co-founder of In.security, a specialist cyber security consultancy offering technical and training services based in the UK. He has a strong background in networking and IT infrastructure, with well over two decades of experience in technical security roles... Read More →
Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Microsoft Technology Center (Aon Center)

8:01am CDT

Offense for Defense
LIMITED
Thursday September 10, 2026 8:01am - Friday September 11, 2026 5:00pm CDT
Limited Capacity seats available
Join us for Offense for Defense, a high-impact, hands-on cybersecurity course built specifically for blue team professionals, systems administrators, SOC analysts, threat hunters, and incident responders. This training arms defenders with the tactics, tools, and mindset of attackers, empowering teams to proactively identify weaknesses and design better protections, detections, and responses. All while learning from one of the most prominent names in cybersecurity instruction and enterprise penetration testing.

Prerequisites: A couple of years in IT
Trainers
avatar for Tim Medin

Tim Medin

CEO, Red Siege
Tim is the CEO and founder of Red Siege Information Security. He is the creator of the Kerberoasting. Tim was a Senior Instructor and course author (SEC560) at The SANS Institute. Tim has performed penetration tests on a wide range of organizations and technologies. Tim is an experienced... Read More →
Thursday September 10, 2026 8:01am - Friday September 11, 2026 5:00pm CDT
Microsoft Technology Center (Aon Center)
 
Blue Team Con 2026
From $0.00
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -