• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

Upp till 20% på populära nyheter →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare

    Mina sidor

      Hjälp

      • Kundservice
      • Vanliga frågor och svar
      • Frakt och leverans
      • Retur vid ångerrätt
      • Reklamera vara
      • Betalning
      • Köpvillkor
      • Allmänna villkor
      • Information om webbplatsens tillgänglighet

      Om Bokus

      • Om oss
      • Pressrum
      • För studenter
      • För företag
      • För bibliotek och offentlig verksamhet
      • För leverantörer
      • Hållbarhet

      Populärt

      • Aktuella erbjudanden
      • Presentkort
      • Studentlitteratur
      • Nya böcker
      • Topplistor
      • Signerade böcker
      • Engelska böcker

      Inspiration

      • Boktips
      • BookTok
      • Populära bokserier
      • Barnbokskaraktärer
      • Populära författare
      Logotyp för Bokus
      Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
      bokus @ CookiesIntegritetspolicyKöpvillkor
      Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
      1. Data och IT
      2. Nätverk och kommunikation

      Applied Incident Response

      AvSteve Anson

      Häftad, Engelska, 2020

      350 kr

      Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

      Fler format och utgåvor

      E-bok

      451 kr

      E-bok

      451 kr

      Beskrivning

      Incident response is critical for the active defense of any network, and incident responders need up-to-date, immediately applicable techniques with which to engage the adversary.  Applied Incident Response details effective ways to respond to advanced attacks against local and remote network resources, providing proven response techniques and a framework through which to apply them.  As a starting point for new incident handlers, or as a technical reference for hardened IR veterans, this book details the latest techniques for responding to threats against your network, including: Preparing your environment for effective incident responseLeveraging MITRE ATT&CK and threat intelligence for active network defenseLocal and remote triage of systems using PowerShell, WMIC, and open-source toolsAcquiring RAM and disk images locally and remotelyAnalyzing RAM with Volatility and RekallDeep-dive forensic analysis of system drives using open-source or commercial toolsLeveraging Security Onion and Elastic Stack for network security monitoringTechniques for log analysis and aggregating high-value logsStatic and dynamic analysis of malware with YARA rules, FLARE VM, and Cuckoo SandboxDetecting and responding to lateral movement techniques, including pass-the-hash, pass-the-ticket, Kerberoasting, malicious use of PowerShell, and many moreEffective threat hunting techniquesAdversary emulation with Atomic Red TeamImproving preventive and detective controls

      Produktinformation

      • Utgivningsdatum:2020-03-09
      • Mått:188 x 231 x 28 mm
      • Vikt:658 g
      • Format:Häftad
      • Språk:Engelska
      • Antal sidor:464
      • Förlag:John Wiley & Sons Inc
      • ISBN:9781119560265

      Utforska kategorier

      • Nätverk och kommunikation inom Data och IT

      Mer om författaren

      Steve Anson is a SANS Certified Instructor and co-founder of leading IT security company Forward Defense. He has over 20 years of experience investigating cybercrime and network intrusion incidents. As a former US federal agent, Steve specialized in intrusion investigations for the FBI and DoD. He has taught incident response and digital forensics techniques to thousands of students around the world on behalf of the FBI Academy, US Department of State, and the SANS Institute. He has assisted governments in over 50 countries to improve their strategic and tactical response to computer-facilitated crimes and works with a range of multinational organizations to prevent, detect and respond to network security incidents.

      Innehållsförteckning

      • Part I Prepare 1Chapter 1 The Threat Landscape 3Attacker Motivations 3Intellectual Property Theft 4Supply Chain Attack 4Financial Fraud 4Extortion 5Espionage 5Power 5Hacktivism 6Revenge 6Attack Methods 6DoS and DDoS 7Worms 8Ransomware 8Phishing 9Spear Phishing 9Watering Hole Attacks 10Web Attacks 10Wireless Attacks 11Sniffing and MitM 11Crypto Mining 12Password Attacks 12Anatomy of an Attack 13Reconnaissance 13Exploitation 14Expansion/Entrenchment 15Exfiltration/Damage 16Clean Up 16The Modern Adversary 16Credentials, the Keys to the Kingdom 17Conclusion 20Chapter 2 Incident Readiness 21Preparing Your Process 21Preparing Your People 27Preparing Your Technology 30Ensuring Adequate Visibility 33Arming Your Responders 37Business Continuity and Disaster Recovery 38Deception Techniques 40Conclusion 43Part II Respond 45Chapter 3 Remote Triage 47Finding Evil 48Rogue Connections 49Unusual Processes 52Unusual Ports 55Unusual Services 56Rogue Accounts 56Unusual Files 58Autostart Locations 59Guarding Your Credentials 61Understanding Interactive Logons 61Incident Handling Precautions 63RDP Restricted Admin Mode and Remote Credential Guard 64Conclusion 65Chapter 4 Remote Triage Tools 67Windows Management Instrumentation Command-Line Utility 67Understanding WMI and the WMIC Syntax 68Forensically Sound Approaches 71WMIC and WQL Elements 72Example WMIC Commands 79PowerShell 84Basic PowerShell Cmdlets 87PowerShell Remoting 91Accessing WMI/MI/CIM with PowerShell 95Incident Response Frameworks 98Conclusion 100Chapter 5 Acquiring Memory 103Order of Volatility 103Local Memory Collection 105Preparing Storage Media 107The Collection Process 109Remote Memory Collection 117WMIC for Remote Collection 119PowerShell Remoting for Remote Collection 122Agents for Remote Collection 125Live Memory Analysis 128Local Live Memory Analysis 129Remote Live Memory Analysis 129Conclusion 131Chapter 6 Disk Imaging 133Protecting the Integrity of Evidence 133Dead-Box Imaging 137Using a Hardware Write Blocker 139Using a Bootable Linux Distribution 143Live Imaging 149Live Imaging Locally 149Collecting a Live Image Remotely 154Imaging Virtual Machines 155Conclusion 160Chapter 7 Network Security Monitoring 161Security Onion 161Architecture 162Tools 165Snort, Sguil, and Squert 166Zeek (Formerly Bro) 172Elastic Stack 182Text-Based Log Analysis 194Conclusion 197Chapter 8 Event Log Analysis 199Understanding Event Logs 199Account-Related Events 207Object Access 218Auditing System Configuration Changes 221Process Auditing 224Auditing PowerShell Use 229Using PowerShell to Query Event Logs 231Conclusion 233Chapter 9 Memory Analysis 235The Importance of Baselines 236Sources of Memory Data 242Using Volatility and Rekall 244Examining Processes 249The pslist Plug-in 249The pstree Plug-in 252The dlllist Plug-in 255The psxview Plug-in 256The handles Plug-in 256The malfi nd Plug-in 257Examining Windows Services 259Examining Network Activity 261Detecting Anomalies 264Practice Makes Perfect 273Conclusion 274Chapter 10 Malware Analysis 277Online Analysis Services 277Static Analysis 280Dynamic Analysis 286Manual Dynamic Analysis 287Automated Malware Analysis 299Evading Sandbox Detection 305Reverse Engineering 306Conclusion 309Chapter 11 Disk Forensics 311Forensics Tools 312Time Stamp Analysis 314Link Files and Jump Lists 319Prefetch 321System Resource Usage Monitor 322Registry Analysis 324Browser Activity 333USN Journal 337Volume Shadow Copies 338Automated Triage 340Linux/UNIX System Artifacts 342Conclusion 344Chapter 12 Lateral Movement Analysis 345Server Message Block 345Pass-the-Hash Attacks 351Kerberos Attacks 353Pass-the-Ticket and Overpass-the-Hash Attacks 354Golden and Silver Tickets 361Kerberoasting 363PsExec 365Scheduled Tasks 368Service Controller 369Remote Desktop Protocol 370Windows Management Instrumentation 372Windows Remote Management 373PowerShell Remoting 374SSH Tunnels and Other Pivots 376Conclusion 378Part III Refine 379Chapter 13 Continuous Improvement 381Document, Document, Document 381Validating Mitigation Efforts 383Building On Your Successes, and Learning from Your Mistakes 384Improving Your Defenses 388Privileged Accounts 389Execution Controls 392PowerShell 394Segmentation and Isolation 396Conclusion 397Chapter 14 Proactive Activities 399Threat Hunting 399Adversary Emulation 409Atomic Red Team 410Caldera 415Conclusion 416Index 419
      Hoppa över listan

      Mer från samma författare

      Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson - Mastering Windows Network Forensics and Investigation, Häftad

      Mastering Windows Network Forensics and Investigation

      Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson

      Häftad, 2012

      549 kr

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

      Mastering Windows Network Forensics and Investigation

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

      E-bok
      2012

      564 kr

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

      Mastering Windows Network Forensics and Investigation

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

      E-bok
      2012

      563 kr

      Hoppa över listan

      Du kanske också är intresserad av

      Steve Anson - Applied Incident Response, E-bok

      Applied Incident Response

      Steve Anson

      E-bok
      2020

      451 kr

      Steve Anson - Applied Incident Response, E-bok

      Applied Incident Response

      Steve Anson

      E-bok
      2020

      451 kr

      Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson - Mastering Windows Network Forensics and Investigation, Häftad

      Mastering Windows Network Forensics and Investigation

      Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson

      Häftad, 2012

      549 kr

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

      Mastering Windows Network Forensics and Investigation

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

      E-bok
      2012

      564 kr

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

      Mastering Windows Network Forensics and Investigation

      Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

      E-bok
      2012

      563 kr

      Måns Petter Zelmerlöw - När allt faller, Inbunden
      • -12%

      När allt faller

      Måns Petter Zelmerlöw

      Inbunden, 2026

      229 kr259 kr

      Peter Englund - Om att misslyckas, Inbunden
      • -17%

      Om att misslyckas

      Peter Englund

      Inbunden, 2026

      4,0 utav 5 stjärnor. Totalt antal röster:(9)

      199 kr239 kr

      Roland Paulsen - Avbegåvad : en essäberättelse om arv och miljö, Inbunden
      • -15%

      Avbegåvad : en essäberättelse om arv och miljö

      Roland Paulsen

      Inbunden, 2026

      225 kr265 kr

      Klara Peters Bastin - SIGNERAD - Om julens wälgång, Inbunden
      • Signerad!

      SIGNERAD - Om julens wälgång

      Klara Peters Bastin

      Inbunden, 2026

      249 kr

      Vendela Blomström, Jeanna Wennerberg - Akademiskt läsande och skrivande, Häftad

      Akademiskt läsande och skrivande

      Vendela Blomström, Jeanna Wennerberg

      Häftad, 2026

      421 kr