Leanpub Header

Skip to main content

Filters

Category: "Cyber Security"

Books

  1. The IDA Pro Handbook
    Disassembly, Decompilation, Debugging, and Reverse Engineering at Scale with IDA 9.0+
    Steve Publications

    Master IDA Pro 9.x with a practical, comprehensive guide to modern reverse engineering. From disassembly and decompilation to debugging, IDAPython, automation, malware analysis, and binary patching, this book equips you with the skills and workflows needed to analyze real-world binaries with confidence.

  2. BlackHat Zig
    Offensive Security, Exploit Development, and Tooling with the Zig Programming Language
    Steve Publications

    Modern cybersecurity needs tools that are fast, reliable and close to the hardware. BlackHat Zig shows how Zig's performance, memory control and compile-time features make it a powerful language for building security tools. Through practical examples, you'll learn Zig while exploring reverse engineering, exploit development, malware analysis, network security and defensive engineering.

  3. Static Analysis for AI-Generated Code
    Building Production Analyzers to Detect, Diagnose, and Defend Against AI Code Quality Failures
    Steve Publications

    AI-generated code can look flawless while hiding invented APIs, security gaps and subtle logic errors. This practical guide shows you how to build production-ready analyzers that catch what tests miss, from taint tracking and symbolic execution to custom rules for CI/CD and IDEs.

  4. Malware Analysis
    SouthStone Publications

    A practical, hands on guide that walks SOC analysts, incident responders, and aspiring reverse engineers from a suspicious file to a defensible detection, covering static, dynamic, code, and memory analysis, unpacking, YARA, and real world reporting.

  5. Security engineering is about building systems that stay secure when things go wrong. This book covers the fundamentals of secure applications, infrastructure and operations through practical examples, real breaches and proven security practices.

  6. Implementing ISO/IEC 27001:2022
    A Practical Implementation Manual for Information Security Management Systems
    Steve Publications

    Implementing ISO/IEC 27001:2022 is easier with the right guide. Packed with practical steps, ready-to-use templates and real-world examples, this book helps you build, manage and certify an effective Information Security Management System with confidence.

  7. Smart Card Application Development
    Building Secure Applications for ISO/IEC 7816 and ISO/IEC 14443 Systems
    Steve Publications

    Smart cards power secure payments, digital identity and trusted authentication around the world. This book is a practical guide to building secure applications for ISO/IEC 7816 and ISO/IEC 14443 systems with real code, hands-on examples and proven development practices.

  8. The self-contained hardening guide for Maester — real Risk/Command/Verdict for every one of the 407 Microsoft 365 & Entra ID security tests, no Microsoft Learn required.

  9. The firewall attackers actually bypass is human. This practical guide reveals the psychology, tactics, and real-world cases behind phishing, vishing, BEC, and deepfake social engineering, then hands you the frameworks, red team methods, and incident response playbooks to build a genuine human firewall.

  10. Evasion Engineering
    A Comprehensive Technical Reference: From Foundational Concepts to Advanced Implementation
    Steve Publications

    Detection keeps getting smarter. So do the systems built to avoid it. Evasion Engineering explores the techniques, architectures and design principles behind stealth in modern computing, from operating systems and networks to cloud environments and machine learning. A practical deep dive for security professionals who want to understand how advanced evasion really works.

  11. Practical AI Security Engineering
    Building and Operating Secure AI Systems in Production
    Steve Publications

    AI changes the security game. New attack paths demand new ways of thinking. This practical guide shows you how to build, deploy and defend AI systems with confidence using proven patterns, real code and production-tested techniques. Built for engineers who need security that works in the real world.

  12. Secure Software Supply Chains
    End-to-End Security for Modern Software Delivery
    Steve Publications

    Your software is only as secure as the path it takes to production. This book walks you through protecting every stage of the software supply chain, from dependencies and builds to deployment and runtime. Learn practical techniques, proven tools and the mindset needed to stop modern supply chain attacks before they spread.

  13. Hardening MCP Servers
    Hands-on recipes to secure MCP Servers from code injection, rug pulls, OAuth flaws, and prompt attacks
    GitforGits | Asian Publishing House

    This book is a workshop where things go wrong on the page, in front of you, and then get fixed in code, with the output that proves the fix worked. There's no need to be a security expert to follow along. We'll be moving from the interpreter to the supply chain, from the token to the human clicking Allow, and from a single tool to a whole host of untrusting servers.

  14. BlackHat Ruby
    Building Offensive Security Tools, Exploit Frameworks, and Vulnerability Research Instrumentation
    Steve Publications

    Build offensive security tools that go beyond simple scripts. BlackHat Ruby shows how to create scanners, fuzzers, protocol analyzers and exploit frameworks with clean, practical Ruby code. Along the way you'll see how these techniques work, where the legal boundaries are and how defenders spot and stop them.

  15. The Effective Bug Bounty Playbook
    A Systematic Approach to Finding High-Impact Vulnerabilities
    Steve Publications

    The Effective Bug Bounty Playbook teaches a systematic approach to finding high-impact vulnerabilities. Through real-world case studies and proven methodologies, you'll learn how to think like an experienced bug bounty hunter and uncover impactful security flaws more consistently.