Performing CyberOps Using Cisco Security Technologies
CBRCOR · 5 days
View course →
Every SOC eventually notices the uncomfortable gap: the alerts only cover what someone already thought to detect, and the intrusions that hurt are the ones that fired nothing. Threat hunting is the discipline that works that gap — and CBRTHD (Conducting Threat Hunting and Defending using Cisco Technologies) teaches it as a method rather than a talent: hypothesis-driven hunts, attacker-behavior frameworks, deep telemetry analysis, and the crucial last step of turning each finding into a permanent detection.
The course prepares for exam 300-220, a concentration of the Cisco CyberOps Professional certification, sitting alongside the forensics track above the CBRCOR core. It is the natural next investment for a SOC that has monitoring under control and wants to start finding what the monitoring misses.
We organize delivery through authorized partners whose instructors hunt in production environments — live online in your time zone, on site, or as a private group with scenarios matched to your telemetry stack.
Topic areas below are grouped in our own words. The full official agenda is available on request — it comes from the authorized partner as part of your quote.
| Duration | 5 days |
|---|---|
| Level | Professional |
| Prerequisites | Solid SOC analysis experience and comfort with network and endpoint telemetry; CBRCOR-level knowledge recommended |
| Certification | Prepares for exam 300-220 CBRTHD — a CyberOps Professional concentration |
| Formats | Live online (VILT), On-site at your location, Private group, Seats in scheduled groups |
| Languages | English + local-language instructors on request |
Fill in the form below — it takes a couple of minutes. Within 5 business days you compare 2–3 concrete offers — provider, instructor, dates, price below the public list. We contract and administer the delivery end to end. Details:how we work and vendor training.
Factual criteria only — level, duration, audience and certification. The right choice depends on your team's starting point and stack.
The mandatory core of CyberOps Professional: incident response, threat intel and SOC process. CBRTHD is the concentration that assumes those skills and turns them proactive. Take the core first unless the team already operates at tier 2/3 level.
The other concentration: rigorous investigation and evidence handling after an incident is confirmed. Choose CBRFIR to strengthen response; CBRTHD to find intrusions before they become incidents. Both pair with the same CBRCOR core exam.
Want to stand up a hunting program on your own telemetry — your SIEM, your EDR, your log gaps? A custom workshop on our materials runs the first real hunts in your environment and leaves the playbooks behind.
If your team needs a subset of this program — or a mix of topics from several courses — we build a custom 2–4 day intensive on our own materials, shaped by your infrastructure. One custom program typically replaces 2–3 catalog courses.
Explore custom coursesIt prepares for exam 300-220, one of the concentration exams. Combined with the core exam 350-201 (the CBRCOR course), it completes CyberOps Professional. It is the newer of the two concentrations, aimed at the proactive-defense side of SOC work.
Hunting is an advanced discipline: participants need real analysis experience — reading endpoint and network telemetry, understanding common attacker techniques. Analysts fresh from tier 1 get more value taking CBRCOR first; we can sequence both courses in one plan.
Yes. Labs use Cisco technologies, but hunting methodology — hypothesis design, behavioral frameworks, telemetry analysis, converting hunts into detections — is vendor-neutral. Teams on mixed stacks apply the method directly to their own SIEM and EDR tooling.
Alerting catches what you already know to look for; hunting searches for what slipped past every rule, driven by hypotheses about attacker behavior. The course connects both: each successful hunt is converted into a detection, so the alerting improves too.
Fill in the request form on this page — team size, format, timing. Within 5 business days you receive 2–3 options from authorized partners with vetted instructors, dates and prices below public lists.
No commitment — describe the task and we come back with concrete options, dates and prices.
Cisco, CBRTHD and course names are trademarks of their respective owners. Uptime Skills is an independent training operator and is not affiliated with or endorsed byCisco. Official courses are delivered by authorized training partners.