Running incidents is a technical problem under time pressure. Running the team that handles them is an organizational design problem, and most CSIRTs fail at exactly that gap. This handbook gives security leaders the charters, catalogs, playbooks, RACIs, and war room templates to build a CSIRT that survives its first real crisis, and the next one.
A practitioner's guide to running a modern SOC, from alert triage and detection engineering to SOAR automation and metrics that actually mean something. Includes real Sigma and KQL rules, a triage checklist, an escalation matrix, and a full worked phishing case from alert to closure.
Cyber threats evolve constantly, and effective defense starts with actionable intelligence. This book guides you from the fundamentals of cyber threat intelligence to advanced operational practices, providing practical frameworks, real-world examples, and proven techniques to help you turn threat data into stronger security decisions.
Cyber deception gives defenders a powerful way to detect threats and gather valuable intelligence. Honeypots: The Art and Science of Cyber Deception is a practical guide to designing, deploying, and operating security honeypots, covering everything from core concepts to modern frameworks and real-world operations.
Master the art of binary analysis with Practical Binary Analysis with Capstone & Keystone. Learn how to disassemble, assemble, analyze, and rewrite machine code while building real-world tools for reverse engineering, security research, and automation.
Endpoint Detection and Response is at the core of modern cybersecurity. This book explores the technologies behind EDR, from kernel-level telemetry to threat hunting and zero-trust architectures, providing practical guidance for deploying and operating EDR at scale.
Master cloud security with confidence using this comprehensive CCSP study guide. Covering all six CCSP domains, it combines clear explanations, real-world examples, and exam-focused practice to help you succeed on the certification exam while building practical cloud security skills for your career.
The CIS Controls are one of the most trusted cybersecurity frameworks, but turning them into a real security program isn't always straightforward. This book walks through all 18 controls and 153 safeguards with clear explanations, practical guidance, and real-world context to help you implement the framework with confidence, whether you're starting from scratch or improving an existing program.
Application sandboxing is the foundation of secure modern computing. This book explores the principles, architectures, and technologies behind containers, virtual machines, browser sandboxes, WebAssembly, and more, explaining how they isolate untrusted code, where their security boundaries break down, and how to choose the right approach for real-world systems.
Master IDA Pro 9.x with a practical, comprehensive guide to modern reverse engineering. From disassembly and decompilation to debugging, IDAPython, automation, malware analysis, and binary patching, this book equips you with the skills and workflows needed to analyze real-world binaries with confidence.
Master advanced web application security testing with Advanced Web Application Penetration Testing Strategies with Burp Suite. Learn practical techniques to find complex vulnerabilities, improve your workflow and deliver more effective security assessments.
Secrets are one of the most overlooked risks in modern infrastructure. Secrets at Scale is a practical guide to managing credentials, API keys, certificates and other sensitive data across modern software environments. It gives engineers, DevOps teams, platform teams and security professionals the tools to build secure, scalable secrets management.
Mobile apps handle some of our most sensitive data, making security essential. Mobile Application Security explores how Android, iOS and cross-platform apps are attacked and secured. Covering secure coding, cryptography, reverse engineering and penetration testing, it gives developers, security professionals and students the practical skills to build and assess secure mobile applications.
Security engineering is about building systems that stay secure when things go wrong. This book covers the fundamentals of secure applications, infrastructure and operations through practical examples, real breaches and proven security practices.
AI is changing exploit development. Learn how to use large language models with tools like IDA Pro, Ghidra and Binary Ninja to speed up vulnerability research, reverse engineering and proof-of-concept exploit development while understanding where human expertise still matters.