Automating Security Detection Engineering: A hands-on guide to implementing Detection as Code
Author: Dennis Chow (Author)
Publisher finelybook 出版社: Packt Publishing
Edition 版本: 1st edition
Publication Date 出版日期: 2024-06-28
Language 语言: English
Print Length 页数: 252 pages
ISBN-10: 1837636419
ISBN-13: 9781837636419
Book Description
Book Description
Review
“Dennis’s insights will illuminate your path, equipping you with the knowledge needed to confront the speed and consistency required to detect an adversary. As technology continues to shape the way we live, work, and communicate, the importance of cybersecurity cannot be overstated. With Dennis as our guide, we gain not only a mentor but a friend who is dedicated to providing the mindset and techniques to defend our daily lives.”
David Bruskin
SVP, Head of Cyber Operations, Synchrony Financial
“[…] For incident response professionals, Automating Security Detection Engineering is more than just a technical manual; it’s a strategic blueprint for building resilient, scalable, and effective detection systems. Chow’s clear writing style, combined with his deep expertise and practical approach, makes this book an invaluable resource for anyone looking to advance their skills in detection engineering and incident response.
Highly recommended for detection engineers, SOC engineers, and technical program managers seeking to enhance their understanding and implementation of Detection as Code.”
Simon Lang, Global Head of Digital Forensics and Incident Response (DFIR)/(CERT) and eDiscovery at CyberClan
“Automating Security Detection Engineering delves into the world of Detection as Code (DaC), offering a practical guide to implementing this approach in various environments. As someone who has long advocated for the integration of automation in security, D&R and detection engineering specifically, I was excited to see this book. […]Chow doesn’t just talk about the theory of DaC; he provides detailed instructions and code examples for automating various aspects of the detection engineering process. Another notable aspect of the book is its focus on threat-informed defense which emphasizes the importance of using threat intelligence to prioritize and scope detection efforts. He also provides guidance on how to automate the ingestion and analysis of threat intelligence data, a significant time-saver for security teams.
It is a valuable resource for security professionals of all levels. I highly recommend this book to anyone looking to improve the efficiency and effectiveness of their security operations.”
Anton Chuvakin, Security Advisor at Office of the CISO, Google Cloud
About the Author
Dennis Chow is an experienced security engineer and manager who has led global security teams in Fortune 500 industries with over 14 years of experience. Dennis started from an IT and security analyst background, working upwards to engineering, architecture, and consultancy in blue- and red-team-focused roles. In 2015, the US Department of Health and Human Services awarded Dennis a grant to standardize cyber threat intelligence sharing for the entire US healthcare vertical. In that time, Dennis achieved over 30 certifications and became GIAC Security Expert #288. During his time at Amazon Web Services (AWS), Dennis worked as a professional services consultant, focusing on security transformation for detection-focused automation.
相关文件下载地址
相关推荐
- Microsoft 365 Copilot At Work: Using AI to Get the Most from Your Business Data and Favorite Apps
- Real-World Edge Computing: Scale, secure, and succeed in the realm of edge computing with Open Horizon
- Salesforce DevOps for Architects: Discover tools and techniques to optimize the delivery of your Salesforce projects
- Segment Routing in MPLS Networks: Transition from traditional MPLS to SR-MPLS with TI-LFA FRR
- Unveiling NIST Cybersecurity Framework 2.0: Secure your organization with the practical applications of CSF
- Mastering DevOps on Microsoft Power Platform: Build, deploy, and secure low-code solutions on Power Platform using Azure DevOps and GitHub
无链接
已更新