Aufgrund einer technischen Störung sind wir derzeit telefonisch nicht erreichbar. Wir arbeiten bereits an der Behebung. Vielen Dank für Ihr Verständnis.
Buch, Englisch
Buch, Englisch
ISBN: 978-1-394-38176-0
Verlag: Wiley
Incident response across Windows, Linux, cloud, and containers using open-source tools
Now in its Second Edition, Applied Incident Response explains how to prepare for and handle the most common and damaging cybersecurity threats facing organizations today. It covers the most effective tools, techniques, and strategies available to contemporary cybersecurity practitioners, adding new chapters on Linux incident response techniques, cloud forensics across AWS, Azure, and Google Cloud, and container compromise detection and response. Every existing chapter has been updated for Windows 11 and Windows Server 2025, addressing changes to triage workflows.
The book centers on free and open-source tools throughout, including Velociraptor, Kansa, KAPE, Sysinternals tools, and the Eric Zimmerman tool set, so techniques work regardless of budget. Coverage spans the threat landscape and attacker motivations, remote triage, memory and disk image acquisition, event log analysis, and detecting lateral movement across Windows, Linux, cloud, and container environments.
Readers will also find:
- Guidance on preparing your people, process, and technology for effective incident response before an attack occurs
- Detailed step-by-step procedures for remote system triage and for acquiring memory and disk images for forensic analysis
- Event log analysis techniques fully updated for Windows 11 artifacts and current real-world attacker tradecraft
- Cloud incident investigation workflows that cover response procedures across AWS, Azure, and Google Cloud platforms and services
- Container security coverage from fundamentals through detecting active compromise with eBPF-based runtime tools including Falco
Applied Incident Response serves information security professionals working in or entering the incident response discipline, as well as IT professionals seeking to understand their role during security incidents. The book also provides relevant background for practitioners pursuing IT certifications or preparing for government and military cybersecurity training requirements.
Fachgebiete
Weitere Infos & Material
Part I: Prepare
Part II: Respond
Part III: Refine
Index




