Skip to content
UptimeSkills
CiscoProfessional5 daysUpdated: July 2026

CBRTHD Training for Your Team — Conducting Threat Hunting and Defending using Cisco Technologies

Every SOC eventually notices the uncomfortable gap: the alerts only cover what someone already thought to detect, and the intrusions that hurt are the ones that fired nothing. Threat hunting is the discipline that works that gap — and CBRTHD (Conducting Threat Hunting and Defending using Cisco Technologies) teaches it as a method rather than a talent: hypothesis-driven hunts, attacker-behavior frameworks, deep telemetry analysis, and the crucial last step of turning each finding into a permanent detection.

The course prepares for exam 300-220, a concentration of the Cisco CyberOps Professional certification, sitting alongside the forensics track above the CBRCOR core. It is the natural next investment for a SOC that has monitoring under control and wants to start finding what the monitoring misses.

We organize delivery through authorized partners whose instructors hunt in production environments — live online in your time zone, on site, or as a private group with scenarios matched to your telemetry stack.

Who this course is for

  • Experienced SOC analysts moving from alert response to proactive hunting
  • Threat hunters formalizing self-taught practice into a repeatable methodology
  • Detection engineers who turn hunt findings into production analytics
  • SOC leads adding a hunting function without hiring a separate team

What your team will learn

Topic areas below are grouped in our own words. The full official agenda is available on request — it comes from the authorized partner as part of your quote.

Request full agenda

Key facts

Duration5 days
LevelProfessional
PrerequisitesSolid SOC analysis experience and comfort with network and endpoint telemetry; CBRCOR-level knowledge recommended
CertificationPrepares for exam 300-220 CBRTHD — a CyberOps Professional concentration
FormatsLive online (VILT), On-site at your location, Private group, Seats in scheduled groups
LanguagesEnglish + local-language instructors on request

Formats and how we organize it

  • Live online (VILT)
  • On-site at your location
  • Private group
  • Seats in scheduled groups

One request → three options

Fill in the form below — it takes a couple of minutes. Within 5 business days you compare 2–3 concrete offers — provider, instructor, dates, price below the public list. We contract and administer the delivery end to end. Details:how we work and vendor training.

CBRTHD vs alternatives: which to choose

Factual criteria only — level, duration, audience and certification. The right choice depends on your team's starting point and stack.

Cisco CBRCOR (CyberOps Core)

The mandatory core of CyberOps Professional: incident response, threat intel and SOC process. CBRTHD is the concentration that assumes those skills and turns them proactive. Take the core first unless the team already operates at tier 2/3 level.

Cisco CBRFIR (Forensics and Incident Response)

The other concentration: rigorous investigation and evidence handling after an incident is confirmed. Choose CBRFIR to strengthen response; CBRTHD to find intrusions before they become incidents. Both pair with the same CBRCOR core exam.

A custom intensive

Want to stand up a hunting program on your own telemetry — your SIEM, your EDR, your log gaps? A custom workshop on our materials runs the first real hunts in your environment and leaves the playbooks behind.

Need only part of CBRTHD?

If your team needs a subset of this program — or a mix of topics from several courses — we build a custom 2–4 day intensive on our own materials, shaped by your infrastructure. One custom program typically replaces 2–3 catalog courses.

Explore custom courses

CBRTHD: frequently asked questions

How does CBRTHD fit into the CyberOps Professional certification?

It prepares for exam 300-220, one of the concentration exams. Combined with the core exam 350-201 (the CBRCOR course), it completes CyberOps Professional. It is the newer of the two concentrations, aimed at the proactive-defense side of SOC work.

What experience should participants bring?

Hunting is an advanced discipline: participants need real analysis experience — reading endpoint and network telemetry, understanding common attacker techniques. Analysts fresh from tier 1 get more value taking CBRCOR first; we can sequence both courses in one plan.

We do not run an all-Cisco security stack — is the course still useful?

Yes. Labs use Cisco technologies, but hunting methodology — hypothesis design, behavioral frameworks, telemetry analysis, converting hunts into detections — is vendor-neutral. Teams on mixed stacks apply the method directly to their own SIEM and EDR tooling.

What is the difference between threat hunting and just better alerting?

Alerting catches what you already know to look for; hunting searches for what slipped past every rule, driven by hypotheses about attacker behavior. The course connects both: each successful hunt is converted into a detection, so the alerting improves too.

How do we organize CBRTHD training?

Fill in the request form on this page — team size, format, timing. Within 5 business days you receive 2–3 options from authorized partners with vetted instructors, dates and prices below public lists.

Request 2–3 CBRTHD training options — quotes within 5 business days

No commitment — describe the task and we come back with concrete options, dates and prices.

Or email us directly:mail@uptimeskills.com

Cisco, CBRTHD and course names are trademarks of their respective owners. Uptime Skills is an independent training operator and is not affiliated with or endorsed byCisco. Official courses are delivered by authorized training partners.