Hands-on Threat Hunting in Cloud Logs and Services
Buch, Englisch, 285 Seiten, Format (B × H): 178 mm x 254 mm, Gewicht: 576 g
ISBN: 978-1-4842-7131-5
Verlag: Apress
This book is divided into three parts. Part I helps you gain a clear understanding of Azure Sentinel and its features along with Azure Security Services, including Azure Monitor, Azure Security Center, and Azure Defender. Part II covers integration with third-party security appliances and you learn configuration support, including AWS. You will go through multi-Azure Tenant deployment best practices and its challenges. In Part III you learn how to improve cyber security threat hunting skills while increasing your ability to defend against attacks, stop data loss, prevent business disruption, and expose hidden malware. You will get an overview of the MITRE Attack Matrix and its usage, followed by Azure Sentinel operations and how to continue Azure Sentinel skill improvement.
After reading this book, you will be able to protect Azure resources from cyberattacks and support XDR (Extend, Detect, Respond), an industry threat strategy through Azure Sentinel.
What You Will Learn
- Understand AzureSentinel technical benefits and functionality
- Configure to support incident response
- Integrate with Azure Security standards
- Be aware of challenges and costs for the Azure log analytics workspace
Security consultants, solution architects, cloud security architects, and IT security engineers
Zielgruppe
Professional/practitioner
Autoren/Hrsg.
Fachgebiete
Weitere Infos & Material
Part I.- Chapter 1: Azure Sentinel Overview.- Chapter 2: Other Azure Security Services.- Chapter 3: Getting Started with Azure Sentinel and XDR Capabilities.- Part II.- Chapter 4: Sentinel Data Connection.- Chapter 5: Threat Intelligence.- Chapter 6: Multi-Tenant Architecture.- Part III.- Chapter 7: Kusto Query Language and Threat Hunting.- Chapter 8: Introduction to MITRE Matrix.- Chapter 9:Azure Sentinel Operations.