The Certified Threat Hunting Specialist (CTHS) is an advanced, vendor-neutral certification for SOC analysts, detection engineers and incident responders who go looking for the adversary that alerts missed. It validates that you can form a testable hypothesis from threat intelligence, know which telemetry can see a technique and whether you actually have it, stack, baseline and time-line real data to find persistence, credential theft, lateral movement and command and control, and turn every hunt into a detection the SOC keeps. The exam is computer adaptive and performance-based, and the credential is kept current through continuing education.
| Level | Advanced. A specialist credential: it goes deep on hunting and detection engineering and assumes working SOC or response experience. |
|---|---|
| Delivery model | Computer adaptive, three stages. Your score on each stage selects the difficulty of the next, so no two candidates sit the same paper. |
| Format | 120 questions. A performance-based exam that includes performance-based questions and multiple-choice questions. No vendor product knowledge required. |
| Time | 180 minutes for the whole exam, timed. Autosaves every answer. |
| Scoring | You need a score of 700 out of 900 to pass. Results are reported on a scale of 100 to 900, and 700 corresponds to answering 72% of the exam correctly. Harder questions carry more weight, so a score means the same thing on any route. Multiple-response items and PBQs are all or nothing. |
| Retakes | No waiting period after a failed first attempt. Every attempt is paid for at the exam price. See the CertLabz Certification Retake Policy. |
| Voucher validity | 12 months from purchase, for one sitting. |
| Certification validity | 3 years. Renew with 75 CEUs per cycle and the $55 annual CE fee, or pass the current exam. Renewal details. |
| Language | English. |
| Credential | PDF certificate with QR code, public verification page, LinkedIn-ready credential ID. Issuer: CertLabz Certification Board. |
| Free resources | The exam objectives PDF and the ten sample questions PDF. |
| Workforce mapping | NICE Framework work roles: Threat Analysis (PD-WRL-006), Defensive Cybersecurity (PD-WRL-001). O*NET occupations: Information Security Analysts (15-1212.00). Self-declared by CertLabz, not reviewed by NIST or CISA. See the full mapping. |
A signed, verifiable:

The CTHS is a performance-based exam: it includes performance-based questions alongside multiple-choice questions. Instead of only picking A, B, C or D, you triage a beaconing candidate list, map event patterns to techniques, sequence an investigation from one suspicious task to a fleet sweep, and tune a noisy detection without losing the true positive. Unlike the practical alternatives, it is computer adaptive, is proctored and timed, needs no course purchase, and covers the whole hunt loop from hypothesis to detection rather than one tooling stack.
PEAK, ATT&CK and the Pyramid of Pain, applied to write hunts that are bounded, testable and prioritized by real threats and real coverage gaps.
Windows event IDs, Sysmon, EDR, Zeek, DNS, identity and cloud audit logs, and the coverage, retention and time checks that make a negative result mean something.
Stacking, first-seen baselines, interval and entropy analysis, timelines and cross-source joins, refined until the result set is reviewable.
Sigma, detection as code, tuning with retesting, coverage maps, purple teaming and the report another hunter can rerun.
Every mature security operation now separates hunting from alert handling, and the people who can do it are paid accordingly: Glassdoor reports cyber threat hunters at about $156,000 in the United States. Every route is shown here at once, so nothing is hidden behind a control you have to find.
United States pay reported by Glassdoor, checked September 2026. Pay varies by location, employer and experience. No certification guarantees a salary or a job.
| CertLabz CTHS | INE eCTHP | OffSec OSTH | CompTIA CySA+ | |
|---|---|---|---|---|
| What it is | Certification exam | Practical certification exam | Practical certification exam | Certification exam |
| Computer adaptive | Yes | No | No | No |
| Hands-on component | Yes, PBQs | Yes, lab-based | Yes, 8-hour lab | Yes, PBQs |
| Vendor neutral | Yes | Yes | Yes | Yes |
| Proctored | Yes | Not published | Yes | Yes |
| Scope | Threat hunting only | Threat hunting | Threat hunting | Broad security analyst |
| Questions | 120 | 60 | Lab tasks | Up to 85 |
| Time | 180 min | 10 hours | 8 hours + 24-hour report | 165 min |
| Pass mark | 700 of 900 | Not published | 50 of 70 | 750 of 900 |
| Course required | No | No | Sold as course + exam | No |
| Exam voucher | $199 | $400 | $1,749 with course | $425 |
Compiled September 2026 from the INE Security eCTHP page and reviews of the v3 exam, the OffSec TH-200 and OSTH exam FAQs, and the CompTIA CySA+ pages. Product names and trademarks belong to their owners; CertLabz is not affiliated with any of them. Confirm current details with each provider.
Six reasons this credential is worth your time, and worth an employer's attention.
One price for the exam, set by its level. Bundles add the study guide and hands-on practice at a saving.
Secure checkout by Stripe. Prices in USD. Sign in or create a free CertLabz account at checkout.
Every form is drawn from a bank of more than 150 items to these exact weights, whichever adaptive route you take. Filter by the area you want to study.
The exam runs in three stages. Your score on each stage selects the difficulty of the next, so a strong candidate is stretched and a struggling one is measured fairly rather than swamped. No two candidates sit the same paper. Harder questions carry more weight, so a scaled score means the same thing whichever route you took.
Each exam can have up to 5 to 12 performance-based questions, drawn fresh on every attempt, alongside the multiple-choice questions. A PBQ is a task rather than a list: you triage a candidate list, map event patterns to techniques, sequence an investigation, or complete an event-ID or data-gap table. They are scored all or nothing, so partial guesses do not pass.
Yes. Telemetry is described by event, field and log type, queries are written in plain portable form, and techniques use MITRE ATT&CK names. You never need one SIEM's or one EDR's product syntax. Where a question involves a tool, it is described generically.
700 out of 900. Results are reported on a scale of 100 to 900, and 700 corresponds to answering 72% of the exam correctly.
There is no waiting period between a failed first attempt and a second attempt. Buy another voucher and sit the exam again when you are ready, and it will draw a fresh adaptive form from the bank. See the CertLabz Certification Retake Policy.
Yes, after three years. Keep it current by logging 75 CEUs during the cycle and paying the $55 annual CE fee before expiry, or by passing the current exam again.
The exam objectives PDF and the ten sample questions PDF. The CTHS Official Study Guide is a $50 ebook, included in two of the bundles. Hands-on practice comes with the All Access plan, included in the Complete bundle.
A laptop or desktop with a webcam and microphone, Chrome, Edge or Firefox, a stable connection, and a quiet private room for three hours. Phones and tablets are not supported.
CTHS is a continuing-education certification, like the CE credentials from CompTIA and ISC2. It is valid for three years from the day you pass. To keep it, log 75 continuing-education units during the cycle and pay the $55 annual CE fee before your expiry date. Or pass the current version of the exam again.
CEUs are logged from your CertLabz dashboard with supporting evidence. A certification that lapses can be reinstated only by passing the current exam.
Buy a voucher, study the objectives, sit the exam when you are ready. Your credential is issued the moment you pass.