Applied Incident Response is a comprehensive guide to incident response, providing effective techniques for responding to advanced attacks against local and remote network resources. The book covers preparing the environment for incident response, leveraging MITRE ATT&CK and threat intelligence, triage of systems, acquiring and analyzing RAM and disk images, log analysis, malware analysis, detecting lateral movement techniques, threat hunting, and adversary emulation. The book is a valuable resource for incident responders, providing a framework for applying incident response techniques and staying ahead of adversaries. Topics covered include: * Preparing the environment for incident response * Leveraging MITRE ATT&CK and threat intelligence * Local and remote triage of systems * Acquiring and analyzing RAM and disk images * Log analysis and aggregating high-value logs * Malware analysis * Detecting and responding to lateral movement techniques * Threat hunting and adversary emulation
FEATURES
ALTERNATIVES
A newsletter providing summarized cyber defense technical content for blue and purple teams to stay informed and protect their estates.
A series of vulnerable virtual machine images with documentation to teach Linux, Apache, PHP, MySQL security.
A comprehensive guide to developing an incident response capability through intelligence-based threat hunting, covering theoretical concepts and real-life scenarios.
Comprehensive tutorial series on ARM Assembly covering various topics.
A repository aiming to archive all Android security presentations and whitepapers from conferences.
IT certification training for CompTIA exams with free resources.
Learn how hackers find security vulnerabilities, exploit web applications, and how to defend against these attacks.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
RoboShadow
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.