Windows Ransomware Detection and Protection: Securing Windows endpoints, the cloud, and infrastructure using Microsoft Intune, Sentinel, and Defender
暫譯: Windows 勒索病毒檢測與防護:使用 Microsoft Intune、Sentinel 和 Defender 保護 Windows 端點、雲端及基礎設施
Sandbu, Marius
- 出版商: Packt Publishing
- 出版日期: 2023-03-17
- 售價: $1,710
- 貴賓價: 9.5 折 $1,625
- 語言: 英文
- 頁數: 290
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1803246340
- ISBN-13: 9781803246345
海外代購書籍(需單獨結帳)
商品描述
Protect your end users and IT infrastructure against common ransomware attack vectors and efficiently monitor future threats
Purchase of the print or Kindle book includes a free PDF eBook
Key Features
• Learn to build security monitoring solutions based on Microsoft 365 and Sentinel
• Understand how Zero-Trust access and SASE services can help in mitigating risks
• Build a secure foundation for Windows endpoints, email, infrastructure, and cloud services
Book Description
If you're looking for an effective way to secure your environment against ransomware attacks, this is the book for you. From teaching you how to monitor security threats to establishing countermeasures to protect against ransomware attacks, Windows Ransomware Detection and Protection has it all covered.
The book begins by helping you understand how ransomware attacks work, identifying different attack vectors, and showing you how to build a secure network foundation and Windows environment. You'll then explore ransomware countermeasures in different segments, such as Identity and Access Management, networking, Endpoint Manager, cloud, and infrastructure, and learn how to protect against attacks. As you move forward, you'll get to grips with the forensics involved in making important considerations when your system is attacked or compromised with ransomware, the steps you should follow, and how you can monitor the threat landscape for future threats by exploring different online data sources and building processes.
By the end of this ransomware book, you'll have learned how configuration settings and scripts can be used to protect Windows from ransomware attacks with 50 tips on security settings to secure your Windows workload.
What you will learn
• Understand how ransomware has evolved into a larger threat
• Secure identity-based access using services like multifactor authentication
• Enrich data with threat intelligence and other external data sources
• Protect devices with Microsoft Defender and Network Protection
• Find out how to secure users in Active Directory and Azure Active Directory
• Secure your Windows endpoints using Endpoint Manager
• Design network architecture in Azure to reduce the risk of lateral movement
Who this book is for
This book is for Windows administrators, cloud administrators, CISOs, and blue team members looking to understand the ransomware problem, how attackers execute intrusions, and how you can use the techniques to counteract attacks. Security administrators who want more insights into how they can secure their environment will also find this book useful. Basic Windows and cloud experience is needed to understand the concepts in this book.
商品描述(中文翻譯)
保護您的最終用戶和 IT 基礎設施免受常見的勒索病毒攻擊向量,並有效監控未來的威脅
購買印刷版或 Kindle 版書籍包括免費的 PDF 電子書
主要特點
• 學習如何基於 Microsoft 365 和 Sentinel 建立安全監控解決方案
• 了解零信任訪問和 SASE 服務如何幫助減輕風險
• 為 Windows 端點、電子郵件、基礎設施和雲服務建立安全基礎
書籍描述
如果您正在尋找有效的方法來保護您的環境免受勒索病毒攻擊,那麼這本書就是為您而寫的。從教您如何監控安全威脅到建立對抗勒索病毒攻擊的對策,《Windows 勒索病毒檢測與保護》涵蓋了所有內容。
本書首先幫助您了解勒索病毒攻擊的運作方式,識別不同的攻擊向量,並展示如何建立安全的網絡基礎和 Windows 環境。接著,您將探索在不同領域中的勒索病毒對策,例如身份和訪問管理、網絡、端點管理、雲和基礎設施,並學習如何保護自己免受攻擊。隨著進展,您將掌握在系統受到勒索病毒攻擊或被入侵時所需考慮的重要取證步驟,以及如何通過探索不同的在線數據來源和建立流程來監控未來的威脅。
在這本勒索病毒書籍的結尾,您將學會如何使用配置設置和腳本來保護 Windows 免受勒索病毒攻擊,並獲得 50 條安全設置的提示,以保護您的 Windows 工作負載。
您將學到的內容
• 了解勒索病毒如何演變成更大的威脅
• 使用多因素身份驗證等服務來保護基於身份的訪問
• 使用威脅情報和其他外部數據來源來豐富數據
• 使用 Microsoft Defender 和網絡保護來保護設備
• 瞭解如何在 Active Directory 和 Azure Active Directory 中保護用戶
• 使用端點管理器保護您的 Windows 端點
• 在 Azure 中設計網絡架構以減少橫向移動的風險
本書適合誰
本書適合 Windows 管理員、雲管理員、CISO 和藍隊成員,旨在了解勒索病毒問題、攻擊者如何執行入侵以及如何使用這些技術來對抗攻擊。希望獲得更多有關如何保護其環境的見解的安全管理員也會發現本書有用。需要具備基本的 Windows 和雲經驗以理解本書中的概念。
目錄大綱
1. Ransomware Attack Vectors and the Threat Landscape
2. Building a Secure Foundation
3. Security Monitoring using Microsoft Sentinel and Defender
4. Ransomware Countermeasures - Windows Endpoints, Identity, and SaaS
5. Ransomware Countermeasures – Microsoft Azure Workloads
6. Ransomware Countermeasures - Networking and Zero-Trust Access
7. Protecting Information Using Azure Information Protection and Data Protection
8. Ransomware Forensics
9. Monitoring the Threat Landscape
10. Best Practices for Protecting Windows from Ransomware Attacks
目錄大綱(中文翻譯)
1. Ransomware Attack Vectors and the Threat Landscape
2. Building a Secure Foundation
3. Security Monitoring using Microsoft Sentinel and Defender
4. Ransomware Countermeasures - Windows Endpoints, Identity, and SaaS
5. Ransomware Countermeasures – Microsoft Azure Workloads
6. Ransomware Countermeasures - Networking and Zero-Trust Access
7. Protecting Information Using Azure Information Protection and Data Protection
8. Ransomware Forensics
9. Monitoring the Threat Landscape
10. Best Practices for Protecting Windows from Ransomware Attacks