Skip to content
CertMapCertMap

OSTHOffSec Threat Hunter

OffSecSpecialty certificateSecurity Operations
Official certification page

Created per CertMap methodology · About the editorial team

Jump to …4 sections

Overview

What is OSTH?

OSTH (OffSec Threat Hunter) is the certification for the TH-200 course (Foundational Threat Hunting), aimed at SOC analysts and aspiring threat hunters. The exam is hands-on and proctored over eight hours: seven tasks worth up to ten points each, passing at 50 of 70 points. Content covers threat actor profiling, ransomware and APT scenarios, network and endpoint IOCs, and working with Suricata, CrowdStrike Falcon and Splunk. Strength: practical exam format to the OffSec standard using real tooling. Limitation: the certification is young and market recognition of the title is still building; valid for three years with a CPE requirement.

Suitable for

SOC Analysts
Threat Hunters
Incident Responders
IT Security Specialists

Quick facts

Languagesen
RecognitionGlobal
TagsDefensive · Threat Hunting · Hands-on · SOC

Key details

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€1,609
AMF (5 years)€667
CPE time value (5 years)€16,000
5-year total€18,276
CPE effort: 40 h per year · 200 h over 5 years · Valued at 80 €/h.
How is TCO calculated?

Classification

CertMap score and matching roles

Rating

Market recognition
1/3
Scheme quality
2/3
Practice evidence
3/3
Maintenance
2/3

Matching NICE roles

No NICE roles assigned.

More certifications

More certifications

This page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology · TCO methodology

Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.

Daniel Heessel, CISO of the Year 2026

1:1 with the CISO

Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.

Open consulting
OSTHView in quadrant