Skills
- Azure Threat Hunting
- Cloud IR
- Entra ID
- Azure RM
- M365 Security
- Azure Telemetry
- Splunk
- MITRE ATT&CK
- Detection Engineering
- Cloud SecOps
- Identity Detection
- SOAR
Cyberwarfare Labs
Certified Azure Threat Hunter (CAz-TH) Certificate is earned by mastering the foundational domains of cybersecurity including network security, web exploitation, cloud fundamentals, vulnerability analysis, and SOC operations through hands-on local lab deployment.
Capabilities
The holder of an Certified Azure Threat Hunter (CAz-TH) Certificate possesses the capability to:
- Conduct proactive threat hunting and incident response across Azure and Microsoft 365 environments.
- Analyze Azure telemetry, including Sign-In, Audit, Activity, Resource, and Unified Audit Logs.
- Investigate suspicious authentication, identity abuse, and privilege escalation within Microsoft Entra ID.
- Map observed attacker behaviors and cloud-based threats to the MITRE ATT&CK framework.
- Investigate Azure Resource Manager activity and identify unauthorized resource manipulation.
- Analyze Microsoft 365 security events for account compromise, malicious access, and data exposure.
- Identify cloud persistence mechanisms, lateral movement, and adversary tradecraft.
- Correlate security events across Azure and Microsoft 365 using SIEM platforms such as Splunk.
- Execute structured incident response processes, including containment, eradication, and recovery.
- Operationalize threat hunting through automation, SOAR workflows, and repeatable detection methodologies.
Next Steps
This certification is best suited for Cloud Threat Hunters, Cloud Security Analysts, SOC Analysts (Azure & Microsoft 365), Incident Responders, Detection Engineers, Cloud Security Consultants, and Security Operations Engineers. Additionally, learners can advance with the following certifications:
- AzRTS – Azure Red Team Specialist → Focused on advanced offensive security operations in Microsoft Azure, including identity abuse, privilege escalation, resource exploitation, and hybrid attack paths.
- CARTS – Certified AWS Red Team Specialist → Focused on adversary tradecraft and red team methodologies within Amazon Web Services (AWS), covering identity attacks, privilege escalation, and cloud infrastructure exploitation.
- CGRTS – Certified Google Red Team Specialist → Focused on offensive security operations within Google Cloud Platform (GCP), including cloud reconnaissance, identity abuse, resource exploitation, and adversary emulation.
Earning Criteria
To earn the Certified Azure Threat Hunter (CAz-TH) Certificate, Users are required to:
- Complete all study materials via the CAz-TH Training Portal
- Successfully complete the guided Azure Threat Hunting & Investigation Labs
- Demonstrate the ability to identify, investigate, and respond to realistic Azure cloud attack scenarios
- Apply threat hunting methodologies using Azure and Microsoft 365 telemetry sources
- Successfully pass the Certified Azure Threat Hunter Practical Examination and meet the certification standards to earn a CWL Verified Certificate.
Connecting You to Advanced Cybersecurity Expertise Worldwide.
Get in touch
Cambridge, United Kingdom, CB2 9SU.