• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Redefining Hacking

    A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in an AI-driven World

    AvOmar Santos,Savannah Lazzara

    Häftad, Engelska, 2025

    Del i serien Addison Wesley

    373 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in an AI-Driven World equips cybersecurity professionals, students, and tech enthusiasts with modern hacking methodologies and the tools to combat evolving threats. Written by industry experts Omar Santos, Savannah Lazzara, and Wesley Thurner, this book blends real-world insights with forward-looking perspectives on AI, automation, and quantum computing. Packed with hands-on exercises, actionable strategies, and case studies, it empowers readers to think like attackers while proactively strengthening their defenses. Gain practical knowledge to master red teaming, bug bounty hunting, and prepare for an AI-influenced cybersecurity landscape.

    This practical forward-thinking book provides: 

    • Holistic Coverage: Comprehensive insights into red teaming and bug bounty hunting
    • Future Trends: Explore AI, automation, and quantum computing’s impact on security
    • Hands-On Learning: Includes exercises, review questions, and GitHub resources
    • Expert Guidance: Authored by seasoned cybersecurity professionals with diverse expertise

    Produktinformation

    • Utgivningsdatum:2025-04-16
    • Mått:188 x 231 x 36 mm
    • Vikt:940 g
    • Format:Häftad
    • Språk:Engelska
    • Serie:Addison Wesley
    • Antal sidor:608
    • Upplaga:1
    • Förlag:Pearson Education
    • ISBN:9780138363611

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    Omar Santos is a Distinguished Engineer at Cisco who pioneers advancements in artificial intelligence security, cybersecurity research, ethical hacking, incident response, and vulnerability disclosure. As co-chair of the Coalition for Secure AI (CoSAI) and board member of the OASIS Open standards organization, he shapes the future of secure technology adoption across industries.Omar drives innovation through multiple leadership roles, including as founder of OpenEoX and co-chair of the Forum of Incident Response and Security Teams (FIRST) PSIRT Special Interest Group. His commitment to cybersecurity education and community building is evident in his role as the co-founder and one of the leaders of the DEF CON Red Team Village and the chair of the Common Security Advisory Framework (CSAF) technical committee.Omar has published over 20 books, created over 20 video courses, and contributed more than 40 academic research papers to the field. Omar's work in cybersecurity is also recognized through multiple granted patents. You can follow Omar in X at https://x.com/santosomar and LinkedIn at https://www.linkedin.com/in/santosomar.Savannah Lazzara is a Security Engineer specializing in red teaming at a tech company. Savannah has multiple years of experience in security consulting working with many Fortune 500 corporations and      has experience in carrying out security assessments, which include network assessments, social engineering exercises, physical facility penetration tests, and wireless assessments. Savannah also has experience in performing adversary simulation assessments, which include remote red team simulations, insider threat assessments, and onsite red team assessments. Savannah’s area of expertise is focused on social engineering and physical security.Savannah is the co-lead of Red Team Village. Additionally, Savannah has spoken at various cybersecurity conferences, including Source Zero Con, BSides, and others. Savannah has also spoken on multiple podcast shows including The Hacker Factor and Hackerz and Haecksen.Wesley Thurner is a Principal Security Engineer on the Intuit Red Team, designing and leading transformative security initiatives across the organization. He accomplishes this through multiple internal roles. Wesley leaders the internal Purple Team, is an Ambassador for cybersecurity education throughout the workforce and leads working groups to define security policies.Prior to Intuit, Wesley served as an exploitation operator in the U.S. Department of Defense's most elite computer network exploitation (CNE) unit. There he led and developed multiple teams across a variety of roles in the U.S. Air Force's premier selectively manned cyberattack squadron. Wesley is also a co-lead for the Red Team Village, a community-driven village bridging the gap between penetration testers and offensive operations. He has spoken at various cybersecurity conferences and authored numerous training courses as well as white papers.

    Innehållsförteckning

    • Chapter 1:The Evolution of Penetration Testing, Red Teaming, and Bug Bounties.. . . . . . . 1Into the Abyss.. . . . . . . 1Industry Overview. . . . . . . 5The Early Days and Evolution of Penetration Testing.. . . 7The Rise of Red Teaming. . . . . . 9The Emergence of Bug Bounty Programs.. . . . 10The Convergence of Penetration Testing, Red Teaming, and Bug Bounties.. 11The Future of Penetration Testing, Red Teaming, and Bug Bounties. . 12The Increasing Use of AI and ML in Penetration Testing,Red Teaming, and Bug Bounties.. . . . . 13Test Your Skills. . . . . . . 15Chapter 2 Introduction to Red Teaming.. . . . . 17What Is Red Teaming?. . . . . . 17The Importance of Red Teaming. . . . . 18Red Team Frameworks and Methodologies.. . . . 20Red Team Engagements.. . . . . . 22Red Team Challenges.. . . . . . 26References. . . . . . . 28Test Your Skills. . . . . . . 30Chapter 3 Red Team Infrastructure.. . . . . . 33An Overview of Red Team Infrastructure.. . . . 34Command and Control.. . . . . . 34Test Your Skills. . . . . . . 60Chapter 4 Modern Red Team Methodology and Tools.. . . . 63Planning.. . . . . . . 64Reconnaissance. . . . . . . 65Initial Access.. . . . . . . 81Persistence.. . . . . . . 96Lateral Movement. . . . . . . 97Post-Exploitation. . . . . . . 105Reporting.. . . . . . . 105Test Your Skills. . . . . . . 107Chapter 5 Social Engineering and Physical Assessments. . . 109Phone Pretexting: Let’s Dial into Your Target. . . . 110Spear Phishing: Time to Reel In Your Target.. . . . 115Infrastructure.. . . . . . . 116Formulating Your Email or Instant Message. . . . 128Execution.. . . . . . . 130Can You Hear Us from the Inside?. . . . . 131Test Your Skills. . . . . . . 144Chapter 6 Advanced Post-Exploitation Techniques.. . . . 147An Overview of Post-Exploitation. . . . . 148How to Maintain Access, Use Persistence Mechanisms, andCreate Backdoors.. . . . . . 152Command and Control (C2) and Covert Channels.. . . 180How to Perform Lateral Movement. . . . . 186Legitimate Utilities and Living Off the Land.. . . . 189Post-Exploitation Privilege Escalation. . . . . 197Test Your Skills. . . . . . . 202Chapter 7 Active Directory and Linux Environments.. . . . 207Active Directory Fundamentals. . . . . 208Microsoft Entra ID and Azure.. . . . . 223Active Directory Attack Techniques. . . . . 229Advanced Linux Environment Attack Techniques. . . 267Test Your Skills. . . . . . . 277Chapter 8 The Future of Red Teaming Beyond the AI Revolution.. . 281Understanding the Current State of AI in Red Teaming.. . . 282Creating AI-Powered Offensive Security Tools.. . . . 283Examining Fine-Tuned Uncensored AI Models.. . . . 297Understanding Retrieval-Augmented Generation (RAG) for Red Teaming.. 299Red Teaming AI and Autonomous Systems. . . . 313Keeping Pace with Rapidly Evolving Technologies. . . 322Test Your Skills. . . . . . . 324Chapter 9 Introduction to Bug Bounty and Effective Reconnaissance. . 327Understanding Bug Bounty Programs.. . . . 328Exploring Effective Reconnaisance.. . . . . 336Performing Active Reconnaissance. . . . . 377Understanding the Art of Performing Vulnerability Scans.. . . 396Performing Web Application and API Recon. . . . 401Communicating Your Findings and Creating EffectiveBug Bounty Reports.. . . . . . 407Test Your Skills. . . . . . . 410Exercises.. . . . . . . 412Chapter 10 Hacking Modern Web Applications and APIs. . . . 415Overview of Web Application-Based Attacks, the OWASPTop 10 for Web Applications, and OWASP Top 10 for LLM Applications. 416Building Your Own Web Application Lab.. . . . 429Understanding Business Logic Flaws.. . . . . 430Understanding Injection-Based Vulnerabilities. . . . 432Exploiting Authentication-Based Vulnerabilities. . . . 451Exploiting Authorization-Based Vulnerabilities. . . . 461Understanding Cross-Site Scripting (XSS) Vulnerabilities.. . . 463Understanding Cross-Site Request Forgery and Server-SideRequest Forgery Attacks.. . . . . . 472Understanding Clickjacking.. . . . . 480Exploiting Security Misconfigurations. . . . . 480Exploiting File Inclusion Vulnerabilities. . . . 482Exploiting Insecure Code Practices. . . . . 484Using Additional Web Application Hacking Tools. . . 488Test Your Skills. . . . . . . 493Chapter 11 Automating a Bug Hunt and Leveraging the Power of AI.. . 497Traditional Bug Hunting Methods. . . . . 498AI-Powered Automation in Bug Hunting.. . . . 500AI Model Training, Fine-Tuning, and RAG for Bug Bounties. . . 516Challenges of Using AI for Bug Bounty Hunting. . . . 521Test Your Skills. . . . . . . 523Appendix Answers to Multiple-Choice Questions.. . . . . 527  9780138363611, TOC, 2/18/2025