Master AWS incident response from CloudTrail to courtroom-ready evidence. Learn to acquire EC2 and container evidence, trace identity-based attacks, investigate S3 exfiltration, and build forensic readiness, all through three real-world incidents walked end to end.
Azure investigations don't start with a disk image, they start with the control plane. This field guide walks incident responders through Azure's logging architecture, identity attack chains, VM and container forensics, and evidence acquisition at cloud scale, with three full attack scenarios worked end to end.
Cloud security is built, not bought. This practical guide goes beyond checklists and compliance to teach the engineering principles behind secure cloud environments. Learn how to design resilient identity systems, protect workloads, secure data, detect threats, and respond to incidents across AWS, Microsoft Azure, and Google Cloud using production-tested techniques and real-world architectures.
Master the complete lifecycle of authorized adversary emulation, from threat modeling and initial access through objective completion. Every offensive technique paired with detection and remediation, complete with ready-to-use templates for rules of engagement, ATT&CK mapping, and findings reports.
A practical, multi-cloud guide to securing AWS, Azure, and GCP workloads. Twelve chapters cover IAM hardening, CSPM/CWPP, IaC scanning, Kubernetes defense, and cloud incident response, each paired with runnable policies, scan configs, and detection rules you can put to work immediately.
A field-tested, platform-agnostic methodology for proactive threat hunting, from hypothesis formation and data foundations to a full scenario library organized by MITRE ATT&CK tactic. Every technique ships as portable Sigma YAML or pseudocode, built to outlast whichever SIEM or EDR you run today.
Learn to investigate Windows, Linux, macOS, memory, network, and cloud evidence with the rigor courts and regulators expect. Packed with runnable tool examples (Volatility 3, Plaso, KAPE, The Sleuth Kit) and a full worked case study, this book turns forensic theory into repeatable, defensible practice.
A vendor-neutral, hands-on guide to proactive threat hunting: the assume-breach mindset, MITRE ATT&CK, core telemetry, and techniques like baselining, beaconing, and LOLBin detection, all backed by Sigma-rule pseudocode and four full scenario hunts from phishing to command-and-control exfiltration.
A practical guide to cyber threat intelligence, from raw indicators to strategic decisions. Learn the intelligence lifecycle, MITRE ATT&CK, STIX/TAXII/MISP, and intelligence-driven threat hunting, all traced through one real phishing campaign from first alert to CISO briefing.
Tens of thousands of vulnerabilities. A handful that actually matter. This book shows you how to build a risk-based vulnerability management program, from asset discovery and scanning to CVSS/EPSS/KEV prioritization, remediation workflows, cloud and container security, and zero-day response, complete with SLA matrices, scoring formulas, and a full Log4Shell case study.
A practical, hands on guide that walks SOC analysts, incident responders, and aspiring reverse engineers from a suspicious file to a defensible detection, covering static, dynamic, code, and memory analysis, unpacking, YARA, and real world reporting.
Running incidents is a technical problem under time pressure. Running the team that handles them is an organizational design problem, and most CSIRTs fail at exactly that gap. This handbook gives security leaders the charters, catalogs, playbooks, RACIs, and war room templates to build a CSIRT that survives its first real crisis, and the next one.
Prompt injection is the SQL injection of the AI era — and most LLM apps are wide open. This hands-on field manual shows application security engineers how to attack and defend LLM systems: direct, indirect, multimodal, and agentic injection, with working code, labs, and ASR benchmarks you can run in CI. Break it, then build the defense-in-depth that holds in production.
A practitioner's guide to running a modern SOC, from alert triage and detection engineering to SOAR automation and metrics that actually mean something. Includes real Sigma and KQL rules, a triage checklist, an escalation matrix, and a full worked phishing case from alert to closure.
Cyber threats evolve constantly, and effective defense starts with actionable intelligence. This book guides you from the fundamentals of cyber threat intelligence to advanced operational practices, providing practical frameworks, real-world examples, and proven techniques to help you turn threat data into stronger security decisions.