Security Orchestration, Automation, and Response for Security Analysts: Learn the secrets of SOAR to improve MTTA and MTTR and strengthen your organiz
Kovacevic, Benjamin
- 出版商: Packt Publishing
- 出版日期: 2023-07-21
- 售價: $2,150
- 貴賓價: 9.5 折 $2,043
- 語言: 英文
- 頁數: 338
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1803242914
- ISBN-13: 9781803242910
-
相關分類:
GAN 生成對抗網絡、SOA、資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Become a security automation expert and build solutions that save time while making your organization more secure
Key Features:
What's inside
- An exploration of the SOAR platform's full features to streamline your security operations
- Lots of automation techniques to improve your investigative ability
- Actionable advice on how to leverage the capabilities of SOAR technologies such as incident management and automation to improve security posture
Book Description:
What your journey will look like
With the help of this expert-led book, you'll become well versed with SOAR, acquire new skills, and make your organization's security posture more robust.
You'll start with a refresher on the importance of understanding cyber security, diving into why traditional tools are no longer helpful and how SOAR can help.
Next, you'll learn how SOAR works and what its benefits are, including optimized threat intelligence, incident response, and utilizing threat hunting in investigations.
You'll also get to grips with advanced automated scenarios and explore useful tools such as Microsoft Sentinel, Splunk SOAR, and Google Chronicle SOAR.
The final portion of this book will guide you through best practices and case studies that you can implement in real-world scenarios.
By the end of this book, you will be able to successfully automate security tasks, overcome challenges, and stay ahead of threats.
What You Will Learn:
Some of the things you'll learn in this book
- How to reap the general benefits of using the SOAR platform
- Transforming manual investigations into automated scenarios
- How to manage known false positives and low-severity incidents for faster resolution
- Tips and tricks for using various Microsoft Sentinel playbook actions
- All you need to know about tools such as Google Chronicle SOAR, Microsoft Sentinel, and Splunk SOAR
Who this book is for:
You'll get the most out of this book if
You're a junior SOC engineer, junior SOC analyst, a DevSecOps professional, or anyone working in the security ecosystem who wants to upskill toward automating security tasks
You often feel overwhelmed with security events and incidents
You have general knowledge of SIEM and SOAR, which is a prerequisite
You're a beginner, in which case this book will give you a head start
You've been working in the field for a while, in which case you'll add new tools to your arsenal
商品描述(中文翻譯)
成為一位安全自動化專家,建立能夠節省時間並使組織更安全的解決方案
主要特點:
- 探索SOAR平台的完整功能,以簡化安全操作
- 大量的自動化技術,提升調查能力
- 實用的建議,如何利用SOAR技術(如事件管理和自動化)提升安全姿態
書籍描述:
通過這本由專家帶領的書籍,您將熟悉SOAR,獲得新技能,並使組織的安全姿態更加堅固。
您將首先複習了解網絡安全的重要性,深入研究為何傳統工具已不再有用,以及SOAR如何幫助。
接下來,您將學習SOAR的工作原理及其好處,包括優化威脅情報、事件響應以及在調查中利用威脅狩獵。
您還將熟悉高級自動化場景,並探索有用的工具,如Microsoft Sentinel、Splunk SOAR和Google Chronicle SOAR。
本書的最後部分將指導您實施實際場景中的最佳實踐和案例研究。
通過閱讀本書,您將能夠成功自動化安全任務,克服挑戰,並保持領先威脅。
您將學到的內容:
- 如何獲得使用SOAR平台的一般好處
- 將手動調查轉化為自動化場景
- 如何管理已知的誤報和低嚴重性事件,以加快解決速度
- 使用各種Microsoft Sentinel playbook操作的技巧和訣竅
- 關於Google Chronicle SOAR、Microsoft Sentinel和Splunk SOAR等工具的所有必要知識
本書適合對象:
- 初級SOC工程師、初級SOC分析師、DevSecOps專業人員或任何在安全生態系統中工作並希望提升自動化安全任務能力的人士
- 經常感到被安全事件和事故壓倒
- 具備SIEM和SOAR的基礎知識
- 初學者,本書將幫助您快速入門
- 在該領域工作一段時間的人,本書將為您增加新的工具