Microsoft Azure Sentinel: Planning and Implementing Microsoft's Cloud-Native Siem Solution
暫譯: Microsoft Azure Sentinel:規劃與實施微軟的雲端原生 SIEM 解決方案
Diogenes, Yuri, Dicola, Nicholas, Turpijn, Tiander
- 出版商: MicroSoft
- 出版日期: 2022-08-29
- 售價: $1,710
- 貴賓價: 9.5 折 $1,625
- 語言: 英文
- 頁數: 240
- 裝訂: Quality Paper - also called trade paper
- ISBN: 0137900937
- ISBN-13: 9780137900930
-
相關分類:
Microsoft Azure
海外代購書籍(需單獨結帳)
商品描述
Microsoft Sentinel is a scalable, cloud-native, security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution that helps to automate threat identification and response―without the complexity and scalability challenges of traditional Security Information and Event Management (SIEM) solutions. Three of Microsoft's leading experts review all it can do, and guide you step by step through planning, deployment, and daily operations. The second edition of this book brings the latest updates in the product and new use case scenarios for investigation, hunting, automation, and orchestration.
- Use Microsoft Sentinel to respond to today's fast-evolving cybersecurity environment, and leverage the benefits of its cloud-native architecture
- Review threat intelligence essentials: attacker motivations, potential targets, and tactics, techniques, and procedures
- Explore Microsoft Sentinel components, architecture, design considerations, and initial configuration
- Ingest alert log data from services and endpoints you need to monitor
- Build and validate rules to analyze ingested data and create cases for investigation
- Prevent alert fatigue by projecting how many incidents each rule will generate
- Help Security Operation Centers (SOCs) seamlessly manage each incident's lifecycle
- Move towards proactive threat hunting: identify sophisticated threat behaviors and disrupt cyber kill chains before you're exploited
- Do more with data: use programmable Jupyter notebooks and their libraries for machine learning, visualization, and data analysis
- Use Playbooks to perform Security Orchestration, Automation and Response (SOAR)
- Save resources by automating responses to low-level events
- Create visualizations to spot trends, identify or clarify relationships, and speed decisions
- Integrate with partners solutions
商品描述(中文翻譯)
Microsoft Sentinel 是一個可擴展的雲原生安全資訊與事件管理 (SIEM) 及安全編排、自動化和響應 (SOAR) 解決方案,幫助自動化威脅識別和響應,無需傳統安全資訊與事件管理 (SIEM) 解決方案的複雜性和擴展性挑戰。三位微軟的頂尖專家將回顧其所有功能,並逐步指導您進行規劃、部署和日常操作。本書的第二版帶來了產品的最新更新以及新的調查、獵捕、自動化和編排的使用案例場景。
- 使用 Microsoft Sentinel 來應對當今快速演變的網路安全環境,並利用其雲原生架構的優勢
- 回顧威脅情報的基本要素:攻擊者的動機、潛在目標,以及戰術、技術和程序
- 探索 Microsoft Sentinel 的組件、架構、設計考量和初始配置
- 從您需要監控的服務和端點中攝取警報日誌數據
- 建立和驗證規則以分析攝取的數據並創建調查案例
- 通過預測每個規則將產生多少事件來防止警報疲勞
- 幫助安全運營中心 (SOCs) 無縫管理每個事件的生命週期
- 向主動威脅獵捕邁進:識別複雜的威脅行為,並在您受到利用之前破壞網路攻擊鏈
- 更有效地使用數據:使用可編程的 Jupyter notebooks 及其庫進行機器學習、可視化和數據分析
- 使用 Playbooks 進行安全編排、自動化和響應 (SOAR)
- 通過自動化對低級事件的響應來節省資源
- 創建可視化以發現趨勢、識別或澄清關係,並加快決策
- 與合作夥伴的解決方案進行整合