Effective threat investigation requires strong technical expertise, analytical skills, and a deep understanding of cyber threats and attacker techniques. It's a crucial skill for SOC analysts, enabling them to analyze different threats and identify security incident origins. This book provides insights into the most common cyber threats and various attacker techniques to help you hone your incident investigation skills.
The book begins by explaining phishing and email attack types and how to detect and investigate them, along with Microsoft log types such as Security, System, PowerShell, and their events. Next, you’ll learn how to detect and investigate attackers' techniques and malicious activities within Windows environments. As you make progress, you’ll find out how to analyze the firewalls, flows, and proxy logs, as well as detect and investigate cyber threats using various security solution alerts, including EDR, IPS, and IDS. You’ll also explore popular threat intelligence platforms such as VirusTotal, AbuseIPDB, and X-Force for investigating cyber threats and successfully build your own sandbox environment for effective malware analysis.
By the end of this book, you’ll have learned how to analyze popular systems and security appliance logs that exist in any environment and explore various attackers' techniques to detect and investigate them with ease.
Maksa helposti kortilla, Klarnalla, Apple Paylla tai Google Paylla. Etkö ole tyytyväinen? Sinulla on aina 14 päivän palautusoikeus. Lue lisää ehdoistamme. Jos sinulla on kysyttävää, lähetä meille sähköpostia osoitteeseen hello@memmo.org.
Memmo tekee opiskelusta helpompaa – missä päin maailmaa ikinä oletkin. Meillä yhdistät kurssikirjat ja fiksut opiskelutyökalut yhteen paikkaan: tiivistelmät, visat, podcastit ja muistikortit. Ja sitten Ted, opiskelukaverisi, joka vastaa kaikkeen, mitä ikinä mietitkin. Yli 50 000 opiskelijaa opiskelee jo täällä – rakennettu auttamaan sinua oppimaan nopeammin ja stressaamaan vähemmän.