Skip to content
Exploit Labs
TH-200 · OSTH · For security teams

TH-200: what the course covers - and what we add.

TH-200 (OSTH) covers threat hunting: forming hypotheses, data sources, hunting attacker behaviour rather than signatures, and turning findings into durable detections.

Who it is for

Analysts moving from reactive alert handling to hypothesis-driven threat hunting.

Course content (official scope)

  • Hypothesis-driven hunting
  • Data sources and coverage
  • Behaviour-based hunting
  • From finding to detection rule

Course content, labs and the OSTH exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.

What Exploit Labs adds
  • +Joint hunting sprints with our operators against your own telemetry

For security teams

Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.

See Learn Enterprise

For individual practitioners

Individual licence, access duration, exam attempts and preparation - start here.

See individual licences