Threat Hunting with Elastic Stack: Solve complex security challenges with integrated prevention, detection, and response
暫譯: 使用 Elastic Stack 進行威脅獵捕:解決複雜的安全挑戰,實現整合的預防、檢測與回應

Pease, Andrew

  • 出版商: Packt Publishing
  • 出版日期: 2021-07-23
  • 售價: $1,980
  • 貴賓價: 9.5$1,881
  • 語言: 英文
  • 頁數: 392
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1801073783
  • ISBN-13: 9781801073783
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

買這商品的人也買了...

相關主題

商品描述

Get hands-on with advanced threat analysis techniques by implementing Elastic Stack security features with the help of practical examples


Key Features:

  • Get started with Elastic Security configuration and features
  • Understand how to use Elastic Stack features to provide optimal protection against threats
  • Discover tips, tricks, and best practices to enhance the security of your environment


Book Description:

Elastic Security is an open solution that equips professionals with the tools to prevent, detect, and respond to threats. Threat Hunting with Elastic Stack will show you how to make the best use of Elastic Security to provide optimal protection against cyber threats. With this book, security practitioners working with Kibana will be able to put their knowledge to work and detect malicious adversary activity within their contested network.


You'll take a hands-on approach to learning the implementation and methodologies that will have you up and running in no time. Starting with the foundational parts of the Elastic Stack, you'll explore analytical models and how they support security response and finally leverage Elastic technology to perform defensive cyber operations. You'll then cover threat intelligence analytical models, threat hunting concepts and methodologies, and how to leverage them in cyber operations. Further, you'll apply the knowledge you've gained to build and configure your own Elastic Stack, upload data, and explore that data directly as well as by using the built-in tools in the Kibana app to hunt for nefarious activities.


By the end of this book, you'll be able to build an Elastic Stack for self-training or to monitor your own network and/or assets and use Kibana to monitor and hunt for adversaries within your network.


What You Will Learn:

  • Explore cyber threat intelligence analytical models and hunting methodologies
  • Build and configure Elastic Stack for cyber threat hunting
  • Leverage the Elastic endpoint and Beats for data collection
  • Perform security data analysis using the Kibana Discover, Visualize, and Dashboard apps
  • Execute hunting and response operations using the Kibana Security app
  • Use Elastic Common Schema to ensure data uniformity across organizations


Who this book is for:

Security analysts, cybersecurity enthusiasts, information systems security staff, or anyone who works with the Elastic Stack for security monitoring, incident response, intelligence analysis, or threat hunting will find this book useful. Basic working knowledge of IT security operations and network and endpoint systems is necessary to get started.

商品描述(中文翻譯)

透過實作 Elastic Stack 安全功能,掌握進階威脅分析技術,並輔以實務範例

主要特色:


  • 開始使用 Elastic Security 的配置和功能

  • 了解如何使用 Elastic Stack 功能來提供最佳的威脅防護

  • 發現增強環境安全的技巧、竅門和最佳實踐

書籍描述:
Elastic Security 是一個開放解決方案,為專業人士提供預防、檢測和應對威脅的工具。《使用 Elastic Stack 進行威脅獵捕》將向您展示如何充分利用 Elastic Security 來提供對網路威脅的最佳防護。透過本書,與 Kibana 一同工作的安全從業人員將能夠將他們的知識付諸實踐,並在其受爭議的網路中檢測到惡意對手的活動。

您將採取實作的方式學習實施和方法論,讓您迅速上手。從 Elastic Stack 的基礎部分開始,您將探索分析模型及其如何支持安全響應,並最終利用 Elastic 技術執行防禦性網路作業。接著,您將涵蓋威脅情報分析模型、威脅獵捕概念和方法論,以及如何在網路作業中利用它們。此外,您將應用所學知識來建立和配置自己的 Elastic Stack,上傳數據,並直接探索這些數據,以及使用 Kibana 應用中的內建工具來獵捕不法活動。

在本書結束時,您將能夠建立一個 Elastic Stack 進行自我訓練或監控自己的網路和/或資產,並使用 Kibana 監控和獵捕網路中的對手。

您將學到的內容:


  • 探索網路威脅情報分析模型和獵捕方法論

  • 為網路威脅獵捕建立和配置 Elastic Stack

  • 利用 Elastic endpoint 和 Beats 進行數據收集

  • 使用 Kibana Discover、Visualize 和 Dashboard 應用進行安全數據分析

  • 使用 Kibana Security 應用執行獵捕和響應作業

  • 使用 Elastic Common Schema 確保組織間數據的一致性

本書適合誰:
安全分析師、網路安全愛好者、資訊系統安全人員,或任何使用 Elastic Stack 進行安全監控、事件響應、情報分析或威脅獵捕的人士都會發現本書有用。開始之前需要具備 IT 安全作業及網路和端點系統的基本工作知識。