A vendor-neutral, hands-on guide to proactive threat hunting: the assume-breach mindset, MITRE ATT&CK, core telemetry, and techniques like baselining, beaconing, and LOLBin detection, all backed by Sigma-rule pseudocode and four full scenario hunts from phishing to command-and-control exfiltration.
A practical guide to cyber threat intelligence, from raw indicators to strategic decisions. Learn the intelligence lifecycle, MITRE ATT&CK, STIX/TAXII/MISP, and intelligence-driven threat hunting, all traced through one real phishing campaign from first alert to CISO briefing.
Tens of thousands of vulnerabilities. A handful that actually matter. This book shows you how to build a risk-based vulnerability management program, from asset discovery and scanning to CVSS/EPSS/KEV prioritization, remediation workflows, cloud and container security, and zero-day response, complete with SLA matrices, scoring formulas, and a full Log4Shell case study.
A practical, hands on guide that walks SOC analysts, incident responders, and aspiring reverse engineers from a suspicious file to a defensible detection, covering static, dynamic, code, and memory analysis, unpacking, YARA, and real world reporting.
Running incidents is a technical problem under time pressure. Running the team that handles them is an organizational design problem, and most CSIRTs fail at exactly that gap. This handbook gives security leaders the charters, catalogs, playbooks, RACIs, and war room templates to build a CSIRT that survives its first real crisis, and the next one.
A practitioner's guide to running a modern SOC, from alert triage and detection engineering to SOAR automation and metrics that actually mean something. Includes real Sigma and KQL rules, a triage checklist, an escalation matrix, and a full worked phishing case from alert to closure.
Cyber threats evolve constantly, and effective defense starts with actionable intelligence. This book guides you from the fundamentals of cyber threat intelligence to advanced operational practices, providing practical frameworks, real-world examples, and proven techniques to help you turn threat data into stronger security decisions.
Cyber deception gives defenders a powerful way to detect threats and gather valuable intelligence. Honeypots: The Art and Science of Cyber Deception is a practical guide to designing, deploying, and operating security honeypots, covering everything from core concepts to modern frameworks and real-world operations.
Master the art of binary analysis with Practical Binary Analysis with Capstone & Keystone. Learn how to disassemble, assemble, analyze, and rewrite machine code while building real-world tools for reverse engineering, security research, and automation.
Real attacks don't live in slide decks. They live in the stack, the heap, the kernel. This code-first guide takes practitioners who already know C straight into how modern exploits and malware actually work, pairing every offensive technique with the defense built to stop it. Rigorous, hands-on, and strictly for isolated, legal, ethical lab use.
Endpoint Detection and Response is at the core of modern cybersecurity. This book explores the technologies behind EDR, from kernel-level telemetry to threat hunting and zero-trust architectures, providing practical guidance for deploying and operating EDR at scale.
Master cloud security with confidence using this comprehensive CCSP study guide. Covering all six CCSP domains, it combines clear explanations, real-world examples, and exam-focused practice to help you succeed on the certification exam while building practical cloud security skills for your career.
The CIS Controls are one of the most trusted cybersecurity frameworks, but turning them into a real security program isn't always straightforward. This book walks through all 18 controls and 153 safeguards with clear explanations, practical guidance, and real-world context to help you implement the framework with confidence, whether you're starting from scratch or improving an existing program.
Application sandboxing is the foundation of secure modern computing. This book explores the principles, architectures, and technologies behind containers, virtual machines, browser sandboxes, WebAssembly, and more, explaining how they isolate untrusted code, where their security boundaries break down, and how to choose the right approach for real-world systems.
Discover how Windows software really works with a practical guide to modern x64 assembly. From core concepts to advanced optimization, reverse engineering, and low-level systems programming, this book equips you with the knowledge to write fast, secure, and efficient code.