Microsoft Sentinel in Action - Second Edition: Architect, design, implement, and operate Microsoft Sentinel as the core of your security solutions
暫譯: 《Microsoft Sentinel 實戰 - 第二版:架構、設計、實作及運營 Microsoft Sentinel 作為您安全解決方案的核心》
Diver, Richard, Bushey, Gary, Perkins, John
- 出版商: Packt Publishing
- 出版日期: 2022-01-27
- 售價: $2,000
- 貴賓價: 9.5 折 $1,900
- 語言: 英文
- 頁數: 478
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1801815534
- ISBN-13: 9781801815536
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Learn how to set up, configure, and use Microsoft Sentinel to provide security incident and event management services for your multi-cloud environment
Key Features:
- Collect, normalize, and analyze security information from multiple data sources
- Integrate AI, machine learning, built-in and custom threat analyses, and automation to build optimal security solutions
- Detect and investigate possible security breaches to tackle complex and advanced cyber threats
Book Description:
Microsoft Sentinel is a security information and event management (SIEM) tool developed by Microsoft that helps you to integrate cloud security and artificial intelligence (AI). This book will enable you to implement Microsoft Sentinel and understand how it can help detect security incidents in your environment with integrated AI, threat analysis, and built-in and community-driven logic.
The book begins by introducing you to Microsoft Sentinel and Log Analytics. You'll then get to grips with data collection and management, before learning how to create effective Microsoft Sentinel queries to detect anomalous behaviors and activity patterns. Moving ahead, you'll learn about useful features such as entity behavior analytics and Microsoft Sentinel playbooks along with exploring the new bi-directional connector for ServiceNow. As you progress, you'll find out how to develop solutions that automate responses needed to handle security incidents. Finally, you'll grasp the latest developments in security, discover techniques to enhance your cloud security architecture, and explore how you can contribute to the security community.
By the end of this Microsoft Sentinel book, you'll have learned how to implement Microsoft Sentinel to fit your needs and be able to protect your environment from cyber threats and other security issues.
What You Will Learn:
- Implement Log Analytics and enable Microsoft Sentinel and data ingestion from multiple sources
- Get to grips with coding using the Kusto Query Language (KQL)
- Discover how to carry out threat hunting activities in Microsoft Sentinel
- Connect Microsoft Sentinel to ServiceNow for automated ticketing
- Find out how to detect threats and create automated responses for immediate resolution
- Use triggers and actions with Microsoft Sentinel playbooks to perform automations
Who this book is for:
If you are an IT professional with prior experience in other Microsoft security products and Azure and are now looking to expand your knowledge to incorporate Microsoft Sentinel, then this book is for you. Security experts using an alternative SIEM tool who want to adopt Microsoft Sentinel as an additional service or as a replacement will also find this book useful.
商品描述(中文翻譯)
學習如何設置、配置和使用 Microsoft Sentinel 以提供多雲環境中的安全事件和事件管理服務
主要特點:
- 從多個數據來源收集、標準化和分析安全信息
- 整合人工智慧(AI)、機器學習、內建和自訂的威脅分析及自動化,構建最佳的安全解決方案
- 偵測和調查可能的安全漏洞,以應對複雜和先進的網路威脅
書籍描述:
Microsoft Sentinel 是由微軟開發的安全信息和事件管理(SIEM)工具,幫助您整合雲安全和人工智慧(AI)。本書將使您能夠實施 Microsoft Sentinel,並了解它如何利用整合的 AI、威脅分析以及內建和社群驅動的邏輯來偵測您環境中的安全事件。
本書首先介紹 Microsoft Sentinel 和 Log Analytics。接著,您將掌握數據收集和管理,然後學習如何創建有效的 Microsoft Sentinel 查詢,以偵測異常行為和活動模式。隨著進展,您將了解有用的功能,例如實體行為分析和 Microsoft Sentinel 操作手冊,並探索新的雙向連接器以連接 ServiceNow。隨著學習的深入,您將發現如何開發自動化響應的解決方案,以處理安全事件。最後,您將掌握安全領域的最新發展,發現增強雲安全架構的技術,並探索如何為安全社群做出貢獻。
在本書結束時,您將學會如何實施 Microsoft Sentinel 以符合您的需求,並能夠保護您的環境免受網路威脅和其他安全問題的影響。
您將學到的內容:
- 實施 Log Analytics,啟用 Microsoft Sentinel 並從多個來源進行數據攝取
- 掌握使用 Kusto 查詢語言(KQL)進行編碼
- 發現如何在 Microsoft Sentinel 中進行威脅獵捕活動
- 將 Microsoft Sentinel 連接到 ServiceNow 以實現自動化工單處理
- 瞭解如何偵測威脅並創建自動化響應以便立即解決
- 使用觸發器和動作與 Microsoft Sentinel 操作手冊執行自動化
本書適合對象:
如果您是具有其他微軟安全產品和 Azure 先前經驗的 IT 專業人員,並希望擴展知識以納入 Microsoft Sentinel,那麼本書適合您。使用其他 SIEM 工具的安全專家,想要將 Microsoft Sentinel 作為附加服務或替代品的人,也會發現本書有用。