TH-200: Foundational Threat Hunting - on the way to OSTH.
TH-200 (OSTH) covers threat hunting: forming hypotheses, data sources and coverage, hunting attacker behaviour rather than signatures, and turning findings into durable detections.

- Certification
- OSTH - OffSec Threat Hunter
- Level
- Intermediate
- Discipline
- Defend
- Audience
- For security teams
Who this course is for
Analysts moving from reactive alert handling to hypothesis-driven threat hunting.
Not the right course yet if
- -Your team has no central logging yet - build telemetry first
- →Derive hunts from explicit hypotheses rather than instinct
- →Assess telemetry coverage and name the gaps
- →Convert findings into reusable detections
- ·Experience with log data or a SIEM
- ·Understanding of common attack techniques
Not sure whether you meet them? We run a short placement conversation before you buy.
What TH-200 covers.
- Hypothesis-driven hunting
- Data sources and coverage
- Behaviour-based hunting
Course content, labs and the OSTH exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Challenge labs with pre-compromised environments where attacker activity has to be found.
Exam and credential
Practical exam with hunting tasks and a report. Passing awards the OSTH certification.
The packages that include TH-200.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Joint hunting sprints with our operators against your own telemetry
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
OSDA builds the analysis base and OSTH sits on top. For most teams that is the right order.
Not for the course. For the transfer into daily work we run hunts on your own telemetry.
Not sure whether TH-200 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more