• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel och pussel

Skapa nya rutiner – hälsoböcker upp till 50% →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Applied Incident Response

    AvSteve Anson

    Häftad, Engelska, 2020

    347 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Fler format och utgåvor

    E-bok

    451 kr

    E-bok

    451 kr

    Häftad

    Kommande

    Beskrivning

    Incident response is critical for the active defense of any network, and incident responders need up-to-date, immediately applicable techniques with which to engage the adversary.  Applied Incident Response details effective ways to respond to advanced attacks against local and remote network resources, providing proven response techniques and a framework through which to apply them.  As a starting point for new incident handlers, or as a technical reference for hardened IR veterans, this book details the latest techniques for responding to threats against your network, including: Preparing your environment for effective incident responseLeveraging MITRE ATT&CK and threat intelligence for active network defenseLocal and remote triage of systems using PowerShell, WMIC, and open-source toolsAcquiring RAM and disk images locally and remotelyAnalyzing RAM with Volatility and RekallDeep-dive forensic analysis of system drives using open-source or commercial toolsLeveraging Security Onion and Elastic Stack for network security monitoringTechniques for log analysis and aggregating high-value logsStatic and dynamic analysis of malware with YARA rules, FLARE VM, and Cuckoo SandboxDetecting and responding to lateral movement techniques, including pass-the-hash, pass-the-ticket, Kerberoasting, malicious use of PowerShell, and many moreEffective threat hunting techniquesAdversary emulation with Atomic Red TeamImproving preventive and detective controls

    Produktinformation

    • Utgivningsdatum:2020-03-09
    • Mått:188 x 231 x 28 mm
    • Vikt:658 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:464
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781119560265

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT

    Mer om författaren

    Steve Anson is a SANS Certified Instructor and co-founder of leading IT security company Forward Defense. He has over 20 years of experience investigating cybercrime and network intrusion incidents. As a former US federal agent, Steve specialized in intrusion investigations for the FBI and DoD. He has taught incident response and digital forensics techniques to thousands of students around the world on behalf of the FBI Academy, US Department of State, and the SANS Institute. He has assisted governments in over 50 countries to improve their strategic and tactical response to computer-facilitated crimes and works with a range of multinational organizations to prevent, detect and respond to network security incidents.

    Innehållsförteckning

    • Part I Prepare 1Chapter 1 The Threat Landscape 3Attacker Motivations 3Intellectual Property Theft 4Supply Chain Attack 4Financial Fraud 4Extortion 5Espionage 5Power 5Hacktivism 6Revenge 6Attack Methods 6DoS and DDoS 7Worms 8Ransomware 8Phishing 9Spear Phishing 9Watering Hole Attacks 10Web Attacks 10Wireless Attacks 11Sniffing and MitM 11Crypto Mining 12Password Attacks 12Anatomy of an Attack 13Reconnaissance 13Exploitation 14Expansion/Entrenchment 15Exfiltration/Damage 16Clean Up 16The Modern Adversary 16Credentials, the Keys to the Kingdom 17Conclusion 20Chapter 2 Incident Readiness 21Preparing Your Process 21Preparing Your People 27Preparing Your Technology 30Ensuring Adequate Visibility 33Arming Your Responders 37Business Continuity and Disaster Recovery 38Deception Techniques 40Conclusion 43Part II Respond 45Chapter 3 Remote Triage 47Finding Evil 48Rogue Connections 49Unusual Processes 52Unusual Ports 55Unusual Services 56Rogue Accounts 56Unusual Files 58Autostart Locations 59Guarding Your Credentials 61Understanding Interactive Logons 61Incident Handling Precautions 63RDP Restricted Admin Mode and Remote Credential Guard 64Conclusion 65Chapter 4 Remote Triage Tools 67Windows Management Instrumentation Command-Line Utility 67Understanding WMI and the WMIC Syntax 68Forensically Sound Approaches 71WMIC and WQL Elements 72Example WMIC Commands 79PowerShell 84Basic PowerShell Cmdlets 87PowerShell Remoting 91Accessing WMI/MI/CIM with PowerShell 95Incident Response Frameworks 98Conclusion 100Chapter 5 Acquiring Memory 103Order of Volatility 103Local Memory Collection 105Preparing Storage Media 107The Collection Process 109Remote Memory Collection 117WMIC for Remote Collection 119PowerShell Remoting for Remote Collection 122Agents for Remote Collection 125Live Memory Analysis 128Local Live Memory Analysis 129Remote Live Memory Analysis 129Conclusion 131Chapter 6 Disk Imaging 133Protecting the Integrity of Evidence 133Dead-Box Imaging 137Using a Hardware Write Blocker 139Using a Bootable Linux Distribution 143Live Imaging 149Live Imaging Locally 149Collecting a Live Image Remotely 154Imaging Virtual Machines 155Conclusion 160Chapter 7 Network Security Monitoring 161Security Onion 161Architecture 162Tools 165Snort, Sguil, and Squert 166Zeek (Formerly Bro) 172Elastic Stack 182Text-Based Log Analysis 194Conclusion 197Chapter 8 Event Log Analysis 199Understanding Event Logs 199Account-Related Events 207Object Access 218Auditing System Configuration Changes 221Process Auditing 224Auditing PowerShell Use 229Using PowerShell to Query Event Logs 231Conclusion 233Chapter 9 Memory Analysis 235The Importance of Baselines 236Sources of Memory Data 242Using Volatility and Rekall 244Examining Processes 249The pslist Plug-in 249The pstree Plug-in 252The dlllist Plug-in 255The psxview Plug-in 256The handles Plug-in 256The malfi nd Plug-in 257Examining Windows Services 259Examining Network Activity 261Detecting Anomalies 264Practice Makes Perfect 273Conclusion 274Chapter 10 Malware Analysis 277Online Analysis Services 277Static Analysis 280Dynamic Analysis 286Manual Dynamic Analysis 287Automated Malware Analysis 299Evading Sandbox Detection 305Reverse Engineering 306Conclusion 309Chapter 11 Disk Forensics 311Forensics Tools 312Time Stamp Analysis 314Link Files and Jump Lists 319Prefetch 321System Resource Usage Monitor 322Registry Analysis 324Browser Activity 333USN Journal 337Volume Shadow Copies 338Automated Triage 340Linux/UNIX System Artifacts 342Conclusion 344Chapter 12 Lateral Movement Analysis 345Server Message Block 345Pass-the-Hash Attacks 351Kerberos Attacks 353Pass-the-Ticket and Overpass-the-Hash Attacks 354Golden and Silver Tickets 361Kerberoasting 363PsExec 365Scheduled Tasks 368Service Controller 369Remote Desktop Protocol 370Windows Management Instrumentation 372Windows Remote Management 373PowerShell Remoting 374SSH Tunnels and Other Pivots 376Conclusion 378Part III Refine 379Chapter 13 Continuous Improvement 381Document, Document, Document 381Validating Mitigation Efforts 383Building On Your Successes, and Learning from Your Mistakes 384Improving Your Defenses 388Privileged Accounts 389Execution Controls 392PowerShell 394Segmentation and Isolation 396Conclusion 397Chapter 14 Proactive Activities 399Threat Hunting 399Adversary Emulation 409Atomic Red Team 410Caldera 415Conclusion 416Index 419
    Hoppa över listan

    Mer från samma författare

    Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson - Mastering Windows Network Forensics and Investigation, Häftad

    Mastering Windows Network Forensics and Investigation

    Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson

    Häftad, 2012

    549 kr

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

    Mastering Windows Network Forensics and Investigation

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

    E-bok
    2012

    564 kr

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

    Mastering Windows Network Forensics and Investigation

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

    E-bok
    2012

    563 kr

    Hoppa över listan

    Du kanske också är intresserad av

    Steve Anson - Applied Incident Response, Häftad

    Applied Incident Response

    Steve Anson

    Häftad, 2027

    548 kr

    Steve Anson - Applied Incident Response, E-bok

    Applied Incident Response

    Steve Anson

    E-bok
    2020

    451 kr

    Steve Anson - Applied Incident Response, E-bok

    Applied Incident Response

    Steve Anson

    E-bok
    2020

    451 kr

    Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson - Mastering Windows Network Forensics and Investigation, Häftad

    Mastering Windows Network Forensics and Investigation

    Steve Anson, Steve Bunting, Ryan Johnson, Scott Pearson

    Häftad, 2012

    549 kr

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

    Mastering Windows Network Forensics and Investigation

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

    E-bok
    2012

    564 kr

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson - Mastering Windows Network Forensics and Investigation, E-bok

    Mastering Windows Network Forensics and Investigation

    Scott Pearson, Ryan Johnson, Steve Bunting, Steve Anson

    E-bok
    2012

    563 kr

    Veronica Henry - Puben vid floden, Pocket
    • -51%

    Puben vid floden

    Veronica Henry

    Pocket, 2023

    4,2 utav 5 stjärnor. Totalt antal röster:(18)

    49 kr99 kr

    Madeline Martin - Den hemliga bibliotekarien i Lissabon, Pocket
    • -51%

    Den hemliga bibliotekarien i Lissabon

    Madeline Martin

    Pocket, 2025

    4,0 utav 5 stjärnor. Totalt antal röster:(6)

    49 kr99 kr

    Frida Gråsjö - Vatten över huvudet, Pocket
    • -45%
    Del 1

    Vatten över huvudet

    Frida Gråsjö

    Pocket, 2024

    3,4 utav 5 stjärnor. Totalt antal röster:(26)

    49 kr89 kr

    Frida Gråsjö - Beska droppar, Pocket
    • -45%
    Del 2

    Beska droppar

    Frida Gråsjö

    Pocket, 2025

    3,9 utav 5 stjärnor. Totalt antal röster:(7)

    49 kr89 kr