TH-200 · OSTH · For security teams
TH-200: what the course covers - and what we add.
TH-200 (OSTH) covers threat hunting: forming hypotheses, data sources, hunting attacker behaviour rather than signatures, and turning findings into durable detections.
Who it is for
Analysts moving from reactive alert handling to hypothesis-driven threat hunting.
Course content (official scope)
- →Hypothesis-driven hunting
- →Data sources and coverage
- →Behaviour-based hunting
- →From finding to detection rule
Course content, labs and the OSTH exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.
What Exploit Labs adds
- +Joint hunting sprints with our operators against your own telemetry
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseFor individual practitioners
Individual licence, access duration, exam attempts and preparation - start here.
See individual licences