Sinopsis
This is the volume for three o'clock in the morning.
Twenty chapters on how organisations actually monitor, detect, hunt, investigate, contain and recover — and how they prove afterwards that they did the right thing.
It covers building and running a security operations centre, logging and telemetry engineering, SIEM architecture and cost control, SOAR and automation, endpoint and network detection, and SOC metrics that mean something. Then detection engineering and detection-as-code, behavioural analytics and insider risk, threat intelligence, ATT&CK coverage mapping and threat hunting. Then exposure: vulnerability and attack-surface management, penetration testing, red and purple teaming. And finally the full arc of response — readiness, triage, containment, digital forensics, ransomware and extortion, and crisis communication.
Every chapter is built on a real incident
How the SolarWinds campaign was actually discovered — an anomalous second device registration, noticed by an analyst. A shipping giant's ten-day global rebuild, saved by one domain controller in Ghana that happened to be offline. A casino group's hundred-million-dollar disclosure. A bank's clearing operation halted. A national library rebuilding from nothing, and publishing its own lessons. A file-transfer flaw that reached thousands of organisations through one supplier. A manufacturer that answered a ransomware attack with daily press briefings — and rebuilt its reputation while rebuilding its network.
Every chapter gives you something to use
- A control room or bridge call under pressure, then the engineering behind it
- A controls-and-evidence table naming the auditable artefact for each control
- The board translation — what leadership must decide, and when
- A practitioner checklist and review questions whose answers teach
Plus reference apparatus you will actually reopen
Nine original framework diagrams. A field toolkit of working templates. Worked technical examples — a full detection rule specification with its false-positive profile, correlation logic for ransomware precursors, one alert triaged from raw telemetry to verdict, five incidents severity-classified, a forensic timeline with confidence ratings. A glossary of over 125 terms. A page-accurate index.
Written for SOC analysts at every tier, detection engineers, threat hunters, incident responders, forensic practitioners, and the managers accountable for response.
Assume the breach. Prove the control. Command the response.
"Sinopsis" puede pertenecer a otra edición de este libro.