Verwandte Artikel zu Practical Threat Detection Engineering: A hands-on...

Practical Threat Detection Engineering: A hands-on guide to planning, developing, and validating detection capabilities - Softcover

Megan Roddie; Jason Deyalsingh; Gary J. Katz

 
9781801076715: Practical Threat Detection Engineering: A hands-on guide to planning, developing, and validating detection capabilities

Inhaltsangabe

Learn to build, test, and optimize high-fidelity security detections with hands-on labs, real-world scenarios, and industry frameworks like MITRE ATT&CK to master detection engineering and boost your career.

Key Features

  • Master the core principles of detection engineering, from development to validation
  • Follow practical tutorials and real-world examples to build and test detections effectively
  • Boost your career using cutting-edge, open-source tools and community-driven content

Book Description

Threat validation is the backbone of every strong security detection strategy—it ensures your detection pipeline is effective, reliable, and resilient against real-world threats.

This comprehensive guide is designed for those new to detection validation, offering clear, actionable frameworks to help you assess, test, and refine your security detections with confidence. Covering the entire detection lifecycle, from development to validation, this book provides real-world examples, hands-on tutorials, and practical projects to solidify your skills.

Beyond just technical know-how, this book empowers you to build a career in detection engineering, equipping you with the essential expertise to thrive in today’s cybersecurity landscape.

By the end of this book, you'll have the tools and knowledge to fortify your organization’s defenses, enhance detection accuracy, and stay ahead of cyber threats.

What you will learn

  • Boost your career as a detection engineer
  • Use industry tools to test and refine your security detections
  • Create effective detections to catch sophisticated threats.
  • Build a detection engineering test lab
  • Make the most of the detection engineering life cycle
  • Harness threat intelligence for detection with open-source intelligence and assessments
  • Understand the principles and concepts that form the foundation of detection engineering
  • Identify critical data sources and overcome integration challenges

Who this book is for

This book is for SOC analysts, threat hunters, security engineers, and cybersecurity professionals looking to master detection engineering. Ideal for those seeking to build, test, and optimize high-fidelity security detections.

Table of Contents

  1. Fundamentals of Detection Engineering
  2. The Detection Engineering Life Cycle
  3. Building a Detection Engineering Test Lab
  4. Detection Data Sources
  5. Investigating Detection Requirements
  6. Developing Detections Using Indicators of Compromise
  7. Developing Detections Using Behavioral Indicators
  8. Documentation and Detection Pipelines
  9. Detection Validation
  10. Leveraging Threat Intelligence
  11. Performance Management
  12. Career Guidance for Detection Engineers

Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.

Über die Autorin bzw. den Autor

Megan Roddie is an experienced information security professional with a diverse background ranging from incident response to threat intelligence to her current role as a detection engineer. Additionally, Megan is a course author and instructor with the SANS Institute where she regularly publishes research on cloud incident response and forensics. Outside of the cyber security industry, Megan trains and competes as a high-level amateur Muay Thai fighter in Austin, TX.

Jason Deyalsingh is an experienced consultant with over nine years of experience in the cyber security space. He has spent the last 5 years focused on digital forensics and incident response (DFIR). His current hobbies include playing with data and failing to learn Rust.

Gary J. Katz is still trying to figure out what to do with his life while contemplating what its purpose really is. While not spiraling into this metaphysical black hole compounded by the plagues and insanity of this world, he sometimes thinks about cyber security problems and writes them down. These ruminations are, on occasion, captured in articles and books.

Von der hinteren Coverseite

Go on a journey through the threat detection engineering lifecycle while enriching your skill set and protecting your organization Key Features: - Gain a comprehensive understanding of threat validation - Leverage open-source tools to test security detections - Harness open-source content to supplement detection and testing Book Description: Threat validation is an indispensable component of every security detection program, ensuring a healthy detection pipeline. This comprehensive detection engineering guide will serve as an introduction for those who are new to detection validation, providing valuable guidelines to swiftly bring you up to speed. The book will show you how to apply the supplied frameworks to assess, test, and validate your detection program. It covers the entire life cycle of a detection, from creation to validation, with the help of real-world examples. Featuring hands-on tutorials and projects, this guide will enable you to confidently validate the detections in your security program. This book serves as your guide to building a career in detection engineering, highlighting the essential skills and knowledge vital for detection engineers in today's landscape. By the end of this book, you'll have developed the skills necessary to test your security detection program and strengthen your organization's security measures. What You Will Learn: - Understand the detection engineering process - Build a detection engineering test lab - Learn how to maintain detections as code - Understand how threat intelligence can be used to drive detection development - Prove the effectiveness of detection capabilities to business leadership - Learn how to limit attackers' ability to inflict damage by detecting any malicious activity early Who this book is for: This book is for security analysts and engineers seeking to improve their organization's security posture by mastering the detection engineering lifecycle. To get started with this book, you'll need a basic understanding of cybersecurity concepts, along with some experience with detection and alert capabilities. Table of Contents - Fundamentals of Detection Engineering - The Detection Engineering Life Cycle - Building a Detection Engineering Test Lab - Detection Data Sources - Investigating Detection Requirements - Developing Detections Using Indicators of Compromise - Developing Detections Using Behavioral Indicators - Documentation and Detection Pipelines - Detection Validation - Leveraging Threat Intelligence - Performance Management - Career Guidance for Detection Engineers

„Über diesen Titel“ kann sich auf eine andere Ausgabe dieses Titels beziehen.