

Buy Practical Threat Detection Engineering: A hands-on guide to planning, developing, and validating detection capabilities by Megan Roddie, Jason Deyalsingh, Gary J. Katz (ISBN: 9781801076715) from desertcart's Book Store. Everyday low prices and free delivery on eligible orders. Review: This is my best IT Security book this year. Purchasing the Kindle version today, I was immediately captivated. This book, astoundingly well-crafted for all skill levels, is a treasure trove of valuable insights. I started from the back and then went to the beginning. I am almost done with phase One ( Requirements Discovery) and I really love how the SOC team and Detection Engineers can collaborate to improve threat intelligence requirements by leveraging the observability of the SOC team in a feedback loop. It's not merely for the defense (blue team) or adversarial simulation (red team) squads or any specific IT security subdivision. It's a universal resource for protecting and detecting threats, resolving vulnerabilities across on-premises or cloud architectures. I strongly recommend every IT manager to read this and distribute copies among their team members, except want to keep the good stuff only to yourself, lol. If you're skeptical of my praise, simply preview the sample on Kindle for a taste of its quality." Review: This book shows that threat detection is not just about creating and implementing rules in a detection tool like a SIEM. It is also about understanding the initial requirements of these rules, the data sources that support them, continuous testing and validation, ensuring that they have the right coverage, and measuring their performance. The title is spot on because I was able to use the information right away to improve our SIEM rule management and learn how to come up with new detections using public information such as repos from other vendors, the Sigma project, or blog posts.
| Best Sellers Rank | 655,624 in Books ( See Top 100 in Books ) 3,131 in Web Administration 7,993 in Computer Science (Books) |
| Customer reviews | 4.6 4.6 out of 5 stars (36) |
| Dimensions | 19.05 x 1.88 x 23.5 cm |
| ISBN-10 | 1801076715 |
| ISBN-13 | 978-1801076715 |
| Item weight | 210 g |
| Language | English |
| Print length | 328 pages |
| Publication date | 21 July 2023 |
| Publisher | Packt Publishing |
A**D
O**E
This is my best IT Security book this year. Purchasing the Kindle version today, I was immediately captivated. This book, astoundingly well-crafted for all skill levels, is a treasure trove of valuable insights. I started from the back and then went to the beginning. I am almost done with phase One ( Requirements Discovery) and I really love how the SOC team and Detection Engineers can collaborate to improve threat intelligence requirements by leveraging the observability of the SOC team in a feedback loop. It's not merely for the defense (blue team) or adversarial simulation (red team) squads or any specific IT security subdivision. It's a universal resource for protecting and detecting threats, resolving vulnerabilities across on-premises or cloud architectures. I strongly recommend every IT manager to read this and distribute copies among their team members, except want to keep the good stuff only to yourself, lol. If you're skeptical of my praise, simply preview the sample on Kindle for a taste of its quality."
A**R
This book shows that threat detection is not just about creating and implementing rules in a detection tool like a SIEM. It is also about understanding the initial requirements of these rules, the data sources that support them, continuous testing and validation, ensuring that they have the right coverage, and measuring their performance. The title is spot on because I was able to use the information right away to improve our SIEM rule management and learn how to come up with new detections using public information such as repos from other vendors, the Sigma project, or blog posts.
L**N
It's a good book! Definitely more practical than those exam books which are full of theories and It actually inspired me to start a little project.
C**T
Since becoming a detection engineer, many people have approached me asking for advice on how to develop their DE skills. There are some good sources of information out there for the conceptual piece, and some options for self-directed hands-on work that are suitable for those with experience but overwhelming for those just beginning to learn about DE. I struggled to find resources that had a good balance between teaching theory and guiding newer learners through more practical scenarios. This book bridges the gap. It’s approachable for someone who has some general infosec knowledge and experience while still offering valuable considerations and additional references for those already working in a DE capacity. It’s well-structured, easy to read, and does a nice job of explaining both conceptual and practical points. I have already recommended this book to others and am happy to have a resource to recommend in the future.
Trustpilot
1 week ago
2 months ago