Selkobase certification index

OffSec Threat Hunter: Complete Certification, Exam and Preparation Guide

See what OSTH tests, what it takes, and whether it fits your goals

Validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings. Examine the OSTH assessment, preparation demands, pricing, prerequisites, renewal expectations, and skills it can demonstrate. Compare the credential with adjacent options from OffSec before deciding whether it belongs in your professional development plan.

View the OSTH certificationOffSecSearch Certifications by Filters

Credential overview

OffSec Threat Hunter: What the certification covers and who it suits

OffSec Threat Hunter validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings.

OffSec Threat Hunter validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings. Candidates learn to proactively search for attacker activity and use the results to strengthen detection and response.

Threat huntingDetection engineeringSOCTelemetry analysisOffSec

Who should take it

Consider OSTH if you enjoy investigating adversary behavior and want to develop a proactive blue-team specialty. It is a strong fit for practitioners who can combine technical evidence with analytical patience and concise communication.

Best for

OSTH suits SOC analysts, detection engineers, incident responders, threat-intelligence practitioners, security researchers, and blue-team professionals who want a more proactive role. It is especially useful for candidates who already understand alerts and logs but want to learn how to investigate weak signals or unobserved adversary behavior systematically.

Why it matters

OSTH can demonstrate a focused proactive-defense capability for analysts and responders moving beyond reactive alert triage. It is valuable for organizations improving detection maturity, while its real impact depends on the candidate’s ability to turn hunts into clearer detections, better telemetry, and useful operational learning.

Requirements

Candidates should have cybersecurity fundamentals, familiarity with common attacker techniques, networking and operating-system knowledge, and some experience with logs or telemetry. Preparation should build the habit of asking focused questions, identifying data gaps, documenting investigative choices, and avoiding the temptation to label activity malicious without enough evidence.

Best fit

Who OffSec Threat Hunter is best suited for

OSTH suits SOC analysts, detection engineers, incident responders, threat-intelligence practitioners, security researchers, and blue-team professionals who want a more proactive role. It is especially useful for candidates who already understand alerts and logs but want to learn how to investigate weak signals or unobserved adversary behavior systematically.

Who should take it

Consider OSTH if you enjoy investigating adversary behavior and want to develop a proactive blue-team specialty. It is a strong fit for practitioners who can combine technical evidence with analytical patience and concise communication.

Best for

OSTH suits SOC analysts, detection engineers, incident responders, threat-intelligence practitioners, security researchers, and blue-team professionals who want a more proactive role. It is especially useful for candidates who already understand alerts and logs but want to learn how to investigate weak signals or unobserved adversary behavior systematically.

Career value

Career value of OffSec Threat Hunter

OSTH supports threat hunter, detection engineer, SOC analyst, incident responder, cyber threat analyst, and proactive defense roles. It can help candidates demonstrate an analytical blue-team specialty, while real hunt experience, data fluency, and detection improvements remain important proof of value.

OSTH can demonstrate a focused proactive-defense capability for analysts and responders moving beyond reactive alert triage. It is valuable for organizations improving detection maturity, while its real impact depends on the candidate’s ability to turn hunts into clearer detections, better telemetry, and useful operational learning.

Learning outcomes

OffSec Threat Hunter: Skills and learning outcomes the certification is designed to validate

Use the OffSec Threat Hunter outcomes as a capability checklist. For every major topic, ask whether you can apply it independently, justify a choice, recognise a poor approach, and communicate the result in the kind of work the credential supports.

  • Develop focused threat-hunting hypotheses from attacker behavior
  • Select and analyze telemetry relevant to an investigative question
  • Identify suspicious patterns and test them against context
  • Document findings and uncertainty in a concise operational form
  • Use hunt outcomes to improve detections and defensive visibility

Tags and keywords

Certification tags and search topics

Threat huntingDetection engineeringSOCTelemetry analysisOffSecOffSec OSTHOffSec Threat Hunterthreat hunting certificationproactive threat detectiontelemetry analysis trainingSOC threat hunter

Reference

Quick facts

Provider
OffSec
Code
OSTH
Level
Associate
Credential type
Professional certification
Active exams
1
Known price
$1,749
Study time
140-260h
Last verified
Sep 8, 2026
Official page

Provider

OffSec

Exam details

OffSec Threat Hunter: Exam structure and assessed capability

Knowing the subject is only part of preparing for OffSec Threat Hunter. Examine how the exam presents scenarios, decisions, tools, and technical concepts, then practise retrieving and applying that knowledge under realistic assessment conditions.

TH-200

OSTH certification exam

Eight-hour proctored practical threat-hunting assessment

Official exam
Type
Practical
Delivery
Online
Duration
480 min

Exam sections

01

OSTH

The osth area tests whether a candidate can move from recognition to correct action. It includes the reasoning, workflow awareness, and failure analysis needed when working with validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSTH certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Work through one straightforward and one ambiguous example of osth. For the ambiguous case, state the assumptions you need, choose an approach, and describe how you would verify that choice.

02

Threat Hunting

Within OSTH certification exam, threat hunting is treated as an applied capability rather than an isolated definition. Candidates should be ready to interpret context, identify an appropriate next step, and account for the operational goals behind validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings.

Question notes

Candidates may encounter threat hunting through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Create a comparison sheet for the main options, commands, controls, or methods associated with threat hunting. Test the distinctions against realistic cases so similar-looking choices do not become guesswork.

03

Blue Team

OSTH certification exam examines how candidates understand and apply blue team within the wider credential scope. This area connects core concepts to the decisions, dependencies, and consequences practitioners encounter when carrying out the work described by validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSTH certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Map blue team to the preceding and following stages of the real workflow. This exposes dependencies that isolated flashcards miss and makes it easier to reason through unfamiliar combinations on assessment day.

04

Cyber Threat Hunting

This area concentrates on cyber threat hunting as it appears in realistic tasks and scenarios. Candidates need to recognize the relevant inputs, choose a defensible approach, and understand how the result supports validates systematic threat hunting through hypothesis development, telemetry analysis, detection of suspicious behavior, investigation, and concise findings.

Question notes

Candidates may encounter cyber threat hunting through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Simulate the constraints of OSTH certification exam while practising cyber threat hunting. Limit references, capture evidence as you work, and reserve time to check completeness so technique and exam execution improve together.

Study effort

OffSec Threat Hunter: Preparation strategy and expected study effort

Your OffSec Threat Hunter study plan should reflect both the exam blueprint and your starting experience. Spend less time rereading familiar concepts and more time applying unfamiliar ones, explaining decisions, and correcting mistakes revealed by practice.

Study time

140-260h

Difficulty

Recommended experience

12 months

Practice exam useful
Hands-on lab useful

Exam cost

OffSec Threat Hunter: Exam price and the full cost of earning the certification

Use the structured fee rows for the latest known amount and compare region, tax, voucher, or membership notes before registering.

$1,749

United States

Standard priceTax may vary

Prerequisites

What to know before starting OffSec Threat Hunter

Candidates should have cybersecurity fundamentals, familiarity with common attacker techniques, networking and operating-system knowledge, and some experience with logs or telemetry. Preparation should build the habit of asking focused questions, identifying data gaps, documenting investigative choices, and avoiding the temptation to label activity malicious without enough evidence.

Career fit

Roles and skills connected to this certification

Explore the roles and skills most directly connected to this certification, then use those paths to compare adjacent credentials.

RoleThreat Hunter

A threat hunter proactively searches security telemetry for signs of malicious activity that automated detections or routine monitoring may not yet reveal.

3 certificationsExplore
RoleSecurity Operations Analyst

Security operations analysts monitor, triage, investigate, and respond to security alerts and incidents in defensive environments, playing a key role in protecting organizational assets.

44 certificationsExplore
RoleIncident Responder

Incident responders are cybersecurity professionals responsible for the triage, containment, investigation, and coordinated recovery process following security breaches and technical compromises.

30 certificationsExplore
RoleSecurity Analyst

Security analysts investigate threats, analyze security alerts and risk signals, and support defensive monitoring and control validation activities.

89 certificationsExplore
SkillThreat Hunting

The practice of proactively searching through networks, endpoints, and datasets to identify and isolate advanced threats that have evaded existing security controls.

3 certificationsExplore
SkillInformation Security

Implementing measures to protect digital assets, systems, networks, and sensitive information from unauthorized access, use, disclosure, disruption, modification, or destruction.

104 certificationsExplore
SkillSecurity Engineering

Implementing and validating technical security controls, systems, platforms, and processes to protect information assets.

108 certificationsExplore
SkillThreat Detection

Threat Detection is the capability to identify malicious or suspicious activities across digital systems by leveraging monitoring, advanced analytics, and various defensive security controls.

72 certificationsExplore

Related areas

Related domains and industries

Use these subject and industry paths to understand where this credential fits inside the broader certification index.

Related certifications

Other OffSec certifications to compare

Compare other credentials from OffSec to understand nearby levels, specialties, and alternative certification paths.

OffSec

Professional certification
Featured

OffSec Certified Professional

Validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSCP / OSCP+ matches your experience and intended direction.

Study time
250-450h
Difficulty
Level
Professional

OffSec

Professional certification
Featured

OffSec Experienced Penetration Tester

Validates advanced penetration testing and red-team tradecraft for breaching mature defenses, evading controls, moving laterally, and compromising enterprise environments. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSEP matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Exploit Developer

Validates Windows user-mode exploit development, reverse engineering, custom shellcode, and bypassing modern exploit mitigations. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSED matches your experience and intended direction.

Study time
300-550h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Web Expert

Validates advanced white-box web application security through source-code review, complex vulnerability chains, custom exploit development, and rigorous reporting. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSWE matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification

Kali Linux Certified Professional

Validates practical knowledge of Kali Linux installation, configuration, package management, command-line operation, security tools, troubleshooting, and customization. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether KLCP matches your experience and intended direction.

Study time
50-100h
Difficulty
Level
Foundational

OffSec

Professional certification

OffSec AI Red Teamer

Validates practical red teaming of AI-enabled systems, including generative AI applications, agents, retrieval pipelines, model infrastructure, and cloud-connected attack surfaces. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSAI / OSAI+ matches your experience and intended direction.

Study time
120-240h
Difficulty
Level
Expert
View all provider certifications

Find the path that fits your goals across the OffSec certification catalog

Continue into individual OffSec certifications to compare what each credential covers, how candidates are assessed, and which professional goals it may support. Check the complete credential details before choosing where to invest your preparation time.