Leanpub Header

Skip to main content

Filters

Category: "Computer Security"

Computer Security

  1. CSIRT Operations
    CSIRT Operations
    SouthStone Publications

    Running incidents is a technical problem under time pressure. Running the team that handles them is an organizational design problem, and most CSIRTs fail at exactly that gap. This handbook gives security leaders the charters, catalogs, playbooks, RACIs, and war room templates to build a CSIRT that survives its first real crisis, and the next one.

  2. The Prompt Injection Bible
    The Prompt Injection Bible
    Attacks, Defenses, and the Architecture of Trust in LLM Systems
    Ismail Tasdelen

    Prompt injection is the SQL injection of the AI era — and most LLM apps are wide open. This hands-on field manual shows application security engineers how to attack and defend LLM systems: direct, indirect, multimodal, and agentic injection, with working code, labs, and ASR benchmarks you can run in CI. Break it, then build the defense-in-depth that holds in production.

  3. SOC Operations
    SOC Operations
    SouthStone Publications

    A practitioner's guide to running a modern SOC, from alert triage and detection engineering to SOAR automation and metrics that actually mean something. Includes real Sigma and KQL rules, a triage checklist, an escalation matrix, and a full worked phishing case from alert to closure.

  4. Cyber Threat Intelligence: From Foundational Principles to Advanced Operational Practice
    Cyber Threat Intelligence: From Foundational Principles to Advanced Operational Practice
    A Comprehensive Guide to the Intelligence Lifecycle, Adversary Analysis, and Proactive Defense
    Steve Publications

    Cyber threats evolve constantly, and effective defense starts with actionable intelligence. This book guides you from the fundamentals of cyber threat intelligence to advanced operational practices, providing practical frameworks, real-world examples, and proven techniques to help you turn threat data into stronger security decisions.

  5. Honeypots: The Art and Science of Cyber Deception
    Honeypots: The Art and Science of Cyber Deception
    A Comprehensive Guide to Designing, Deploying, and Operating Security Honeypots
    Steve Publications

    Cyber deception gives defenders a powerful way to detect threats and gather valuable intelligence. Honeypots: The Art and Science of Cyber Deception is a practical guide to designing, deploying, and operating security honeypots, covering everything from core concepts to modern frameworks and real-world operations.

  6. Windows Internals: Architecture of Modern Microsoft Operating Systems
    Windows Internals: Architecture of Modern Microsoft Operating Systems
    From Boot to Shutdown — Kernel Design, Security, Virtualization, and Debugging in Windows 10, 11, and Server
    Steve Publications

    Discover how Windows really works beneath the desktop. From boot to shutdown, this book provides a practical, in-depth exploration of the Windows NT kernel, covering architecture, memory management, security, virtualization, debugging, and more for developers, security professionals, and advanced students.

  7. Practical Binary Analysis with Capstone & Keystone
    Practical Binary Analysis with Capstone & Keystone
    The Complete Guide to Binary Analysis, Disassembly, and Assembly
    Steve Publications

    Master the art of binary analysis with Practical Binary Analysis with Capstone & Keystone. Learn how to disassemble, assemble, analyze, and rewrite machine code while building real-world tools for reverse engineering, security research, and automation.

  8. Black Hat C
    Black Hat C
    Low-Level Exploitation and Malware Engineering
    Steve Publications

    Real attacks don't live in slide decks. They live in the stack, the heap, the kernel. This code-first guide takes practitioners who already know C straight into how modern exploits and malware actually work, pairing every offensive technique with the defense built to stop it. Rigorous, hands-on, and strictly for isolated, legal, ethical lab use.

  9. 관리자는 절대 ��먼저 DM하지 않습니다
    관리자는 절대 먼저 DM하지 않습니다
    오픈 커뮤니티를 지배하는 스캠 경제의 해부
    Bruno Galvao (브루노 갈방)

    모든 크립토 채널에는 같은 다급한 경고가 고정되어 있습니다. "운영진은 절대 먼저 DM을 보내지 않습니다." 이 책은 그 한 줄 뒤에 숨은 스캠 경제의 필드 가이드입니다. 사칭 관리자, 딥페이크로 만들어진 창업자, 피그 부처링, 통째로 합성된 커뮤니티까지 — 스팸에서 크립토, 그리고 AI로 이어지는 세 시대를 가로질러 추적하고, 이 모든 것을 끝낼 단 하나의 질문에 도달합니다. 지금 이 방에 누가 있는가?

  10. AIエージェントセキュリティ・フィールドマニュアル
    AIエージェントセキュリティ・フィールドマニュアル
    自律システムの脅威・コントロール・検証可能な保証
    Shugo Nozaki

    脅威 → コントロール → 要件 → 検証。AIエージェントを出荷する前に読むフィールドマニュアル。

  11. The Anatomy of Modern Endpoint Detection and Response
    The Anatomy of Modern Endpoint Detection and Response
    From Kernel Hooks to Zero Trust — A Security Professional's Guide
    Steve Publications

    Endpoint Detection and Response is at the core of modern cybersecurity. This book explores the technologies behind EDR, from kernel-level telemetry to threat hunting and zero-trust architectures, providing practical guidance for deploying and operating EDR at scale.

  12. Trust Graph Intelligence: Securing Machine Identities at Scale

    Machine identities outnumber humans 82:1 in modern cloud environments. Every IAM role, every OIDC federation from your CI/CD pipeline, every service account — they accumulate silently. No one monitors them. No one audits them. Each one is a potential entry point for attackers. This book shows you how to build the platform that makes them visible.

  13. AI Agent Security: A Field Manual

    Threat → Control → Requirement → Verification. The field manual to read before you ship an autonomous agent.

  14. CCSP - Certified Cloud Security Professional: The Complete Study Guide
    CCSP - Certified Cloud Security Professional: The Complete Study Guide
    Mastering Cloud Security Across All Six Domains
    Steve Publications

    Master cloud security with confidence using this comprehensive CCSP study guide. Covering all six CCSP domains, it combines clear explanations, real-world examples, and exam-focused practice to help you succeed on the certification exam while building practical cloud security skills for your career.

  15. CIS Controls v8.1: The Definitive Guide to Cybersecurity's Most Actionable Framework
    CIS Controls v8.1: The Definitive Guide to Cybersecurity's Most Actionable Framework
    A Complete Walkthrough of the 18 Controls, 153 Safeguards, and Implementation Groups for Modern Organizations
    Steve Publications

    The CIS Controls are one of the most trusted cybersecurity frameworks, but turning them into a real security program isn't always straightforward. This book walks through all 18 controls and 153 safeguards with clear explanations, practical guidance, and real-world context to help you implement the framework with confidence, whether you're starting from scratch or improving an existing program.