Linux System Hardening is a practical guide to securing Linux systems from the kernel to the cloud. It explains how threats work, how to apply effective controls and what you give up along the way. Built for admins, security engineers and DevSecOps teams working with real production systems.
Static code analysis is more than running a linter and fixing warnings. This book shows how to build practical analysis pipelines with Claude Code and deterministic tools, combining AI-driven insights with reliable checks to improve code quality and security across projects of any size.
AI is changing fast, and so are the security risks that come with it. This practical guide shows security and technology leaders how to govern, secure and assure AI systems from design through deployment and beyond. Packed with proven frameworks, controls and real-world guidance, it turns complex AI security requirements into practical action.
Turn complex technology risks into clear, evidence-based executive decisions through visual flows, practical guidance, and a fully fictional enterprise case.
A practical reference for securing real-world OT, ICS and SCADA environments.Roadmap for engineers, CISOs, and consultants to master industrial cybersecurity. Learn to secure ICS, SCADA, and Industry 4.0 environments, apply IEC 62443 & NIS 2, and build robust defense-in-depth architectures—from real-world attack analysis to practical incident response.
Scraping is getting harder to control as bots become more sophisticated. This practical guide shows security engineers, SREs and platform architects how to build anti-scraping defenses that work at scale, from traffic analysis and behavioral detection to rate limiting, challenges, observability and continuous adaptation.
Excerpt 1 — Chapter 1, "Introduction": why cybersecurity management is not about technologyThe simplest way to manage an organization's cybersecurity is to draw up a list of technical measures ("install antivirus software," "enable multi-factor authentication," "encrypt disks") and carry them out one by one. This approach has an obvious advantage — simplicity — but also a systemic flaw: it does not answer the question of which measures this particular organization actually needs, to what extent, and what to do when there are not enough resources for "the whole list." It also creates a false sense of completeness: "we implemented everything on the list — so we are secure," even though the real level of risk depends not on the length of the list but on how well the measures match the specific threats and the value of the organization's assets. Excerpt 2 — Chapter 1: cyber risk within enterprise risk managementIf cybersecurity is about managing risk rather than a checklist of technical measures, the logical continuation of this idea is as follows: cyber risk is not a separate, isolated category discussed only by the IT department in its own language. It is one of the types of risk that any enterprise faces — alongside financial, reputational, operational, and supply chain risk. It should be managed within the same frame of reference as other enterprise risks. Excerpt 3 — Chapter 14, applying the Chapter 10 mapping methodology: where a mapping gap becomes a technical projectThe last row is the central conclusion of this step, and of the whole case study: the mapping table shows honestly that no Annex A control exists for PR.AA-04 that can simply be marked "done" and the gap considered closed. An organization relying only on the SoA, or only on the mapping table, could mistakenly conclude that because A.5.17 partially covers the topic, no further action is needed — which is exactly why the gap analysis, the SoA, and the risk register above all consistently define SSO as a separate, explicit technical project, rather than a derivative action from existing controls. Excerpt 4 — Chapter 14, closing paragraph of the bookThe running case study in this chapter has shown that the fifth step of the Chapter 7 methodology — "the organization can repeat these steps as often as needed" — is not a rhetorical flourish but a real operating cycle: MFA for contractors, backup encryption, and automatic deactivation in the ERP, each opened by a separate cycle in Chapters 6–7 and 13, were already closed and verified by the time this chapter began, and the very fact of their closure — through broadening the profiling scope to identity management across the ERP and CRM together — opened up a new, precisely formulated gap, PR.AA-04, reflected consistently and at once in the updated profile, the action plan, the SoA, the risk register, and the mapping table. It is precisely this consistency among five tools converging on a single decision, not the mere existence of each tool on its own, that is the practical upshot of building an integrated cybersecurity management system.
Build AI systems that do more than demo well. This hands-on guide shows you how to engineer autonomous software on Linux that is secure, observable, reliable and ready for production. From agents and memory to threat modeling, OpenTelemetry and Kubernetes, you’ll build a real system while learning what it takes to run AI you can actually trust.
A practical guide to finding threats that never need to touch disk. Explore Windows internals, memory forensics, EDR telemetry and network detection through safe labs and real investigative methods. Built for defenders who want to understand what happens in memory, spot suspicious behavior and turn evidence into reliable detections.
Move beyond AI demos and build agents that can actually run IT operations. This practical guide takes you from MCP fundamentals to production-ready monitoring, incident response, remediation, Kubernetes operations, security and multi-agent systems, with complete runnable code and a strong focus on safe autonomy.
Cyber threats do not stop at the office network. When industrial systems are targeted, the consequences can reach far beyond lost data. This practical guide shows how to secure OT and critical infrastructure from the ground up, combining proven standards, real-world defenses and hands-on guidance for the systems that keep the world running.
Cybersecurity is no longer just an IT problem. Modern Information Security connects the principles, architecture, operations and strategy behind effective security programs. From identity and cloud security to incident response, governance and emerging threats, it offers practical guidance for building security that works in the real world.
Understand the threats. Learn the defenses. Build a stronger foundation in Network Security.Modern organizations depend on computer networks for communication, business operations, cloud services, applications, and data exchange. With this growing connectivity comes an equally important challenge: protecting networks from unauthorized access, attacks, vulnerabilities, and security incidents.Network Security: A Comprehensive Guide for Beginners and Advanced Learners provides a structured learning journey for students and aspiring security professionals who want to understand how modern networks are protected.The book begins with the fundamentals of networking and network security, covering network topologies, OSI and TCP/IP models, network devices, IP addressing, subnetting, protocols, and ports. It then moves into common cyber threats and vulnerabilities, including malware, phishing, social engineering, DoS and DDoS attacks, Man-in-the-Middle attacks, weak authentication, and software vulnerabilities.Readers will learn important security principles such as the CIA Triad, AAA, Defense-in-Depth, Least Privilege, and Risk Management, followed by an introduction to cryptography, encryption, digital signatures, certificates, TLS, IPsec, and PKI.The book also explores firewalls, IDS, IPS, SIEM, VPNs, wireless security, Network Access Control, web application security, HTTPS, secure development practices, incident response, digital forensics concepts, disaster recovery, and business continuity.The final chapters look toward the future, introducing Zero Trust, Next-Generation Firewalls, AI and Machine Learning in cybersecurity, Cloud Security, and IoT Security.For students, the book provides a strong academic foundation. For aspiring professionals, it introduces important technologies, responsibilities, career paths, and security practices.The goal is not simply to learn how attacks occur, but to understand how responsible security professionals identify risks, protect systems, respond to incidents, and continuously improve security.Learn the fundamentals. Understand the risks. Think like a security professional.
Build web scrapers that survive the real world. This hands-on guide takes you from Scrapy fundamentals to scalable production systems, with practical patterns for asynchronous crawling, clean data pipelines, testing, deployment and resilient architectures. Packed with runnable Python examples, it gives you the skills to scrape smarter, faster and at scale.
The plugin was deleted. The malware came back. This real WordPress investigation shows why. Follow a multi-layer infection across plugins, MU plugins, drop-ins, theme code, database records, memory, recovery archives, administrator access, and browser persistence—and learn how to remove the recovery system instead of deleting one visible symptom.