Personnaliser

OK

Appareils photo, caméras, drones et bien d'autres ! 30€ et 100€ offerts* dès 299€ et 999€ d'achat sur l'univers Photo et caméras avec les codes : PHOTO30 et PHOTO100

En profiter

Applied Incident Response - Steve Anson

Note : 0

0 avis
  • Soyez le premier à donner un avis

Vous en avez un à vendre ?

Vendez-le-vôtre
Filtrer par :

32,57 €

Occasion · Comme Neuf

  • Ou 8,14 € /mois

  • LIVRAISON RAPIDE

    Ce vendeur propose la livraison entre 3 et 6 jours

    • Livraison GRATUITE
    • Livré entre le 24 et le 27 juillet
    Voir les modes de livraison

    momox

    PRO Vendeur favori

    4,8/5 sur + de 1 000 ventes

    Livré gratuitement chez vous en 2 semaines. Article comme neuf, non utilisé. 2 millions de ventes réalisées en 5 ans, merci de votre confiance ! Découvrez les avis (https://fr.shopping.rakuten.com/feedback/momox) de nos clients.

    Nos autres offres

    • 41,95 €

      Produit Neuf

      Ou 10,49 € /mois

      • Livraison : 3,99 €
      • Livré entre le 27 juillet et le 3 août
      Voir les modes de livraison
      4,8/5 sur + de 1 000 ventes
      Voir le détail de l'annonce 
    • 46,53 €

      Produit Neuf

      Ou 11,63 € /mois

      • Livraison à 0,01 €
      Voir les modes de livraison
      4,7/5 sur + de 1 000 ventes

      Nouvel article expédié dans le 24H à partir des Etats Unis Livraison au bout de 20 à 30 jours ouvrables.

      Voir le détail de l'annonce 
    • 50,53 €

      Produit Neuf

      Ou 12,63 € /mois

      • Livraison à 0,01 €
      Voir les modes de livraison
      4,8/5 sur + de 1 000 ventes

      Expédition rapide et soignée depuis l`Angleterre - Délai de livraison: entre 10 et 20 jours ouvrés.

      Voir le détail de l'annonce 
    • 56,92 €

      Produit Neuf

      Ou 14,23 € /mois

      • Livraison à 0,01 €
      • Livré entre le 28 juillet et le 10 août
      Voir les modes de livraison

      Brand new, In English, Fast shipping from London, UK; Tout neuf, en anglais, expédition rapide depuis Londres, Royaume-Uni;ria9781119560265_dbm

      Voir le détail de l'annonce 
    • 74,49 €

      Produit Neuf

      Ou 18,62 € /mois

      • Livraison : 25,00 €
      • Livré entre le 10 et le 17 août
      Voir les modes de livraison
      4,8/5 sur + de 1 000 ventes

      Apres acceptation de la commande, le delai moyen d'expedition depuis le Japon est de 48 heures. Le delai moyen de livraison est de 3 a 4 semaines. En cas de circonstances exceptionnelles, les delais peuvent s'etendre jusqu'à 2 mois.

      Voir le détail de l'annonce 
    Voir plus d'annonces (5 / 6)
    Publicité
     
    Vous avez choisi le retrait chez le vendeur à
    • Payez directement sur Rakuten (CB, PayPal, 4xCB...)
    • Récupérez le produit directement chez le vendeur
    • Rakuten vous rembourse en cas de problème

    Gratuit et sans engagement

    Félicitations !

    Nous sommes heureux de vous compter parmi nos membres du Club Rakuten !

    En savoir plus

    Retour

    Horaires

        Note :


        Avis sur Applied Incident Response de Steve Anson Format Broché  - Livre

        Note : 0 0 avis sur Applied Incident Response de Steve Anson Format Broché  - Livre

        Les avis publiés font l'objet d'un contrôle automatisé de Rakuten.


        Présentation Applied Incident Response de Steve Anson Format Broché

         - Livre

        Livre - Steve Anson - 01/01/2020 - Broché - Langue : Anglais

        . .

      • Auteur(s) : Steve Anson
      • Editeur : Wiley
      • Langue : Anglais
      • Parution : 01/01/2020
      • Format : Moyen, de 350g à 1kg
      • Nombre de pages : 464
      • Expédition : 765
      • Dimensions : 23.3 x 18.9 x 2.7
      • ISBN : 9781119560265



      • Résumé :

        Part I Prepare 1

        Chapter 1 The Threat Landscape 3

        Attacker Motivations 3

        Intellectual Property Theft 4

        Supply Chain Attack 4

        Financial Fraud 4

        Extortion 5

        Espionage 5

        Power 5

        Hacktivism 6

        Revenge 6

        Attack Methods 6

        DoS and DDoS 7

        Worms 8

        Ransomware 8

        Phishing 9

        Spear Phishing 9

        Watering Hole Attacks 10

        Web Attacks 10

        Wireless Attacks 11

        Sniffing and MitM 11

        Crypto Mining 12

        Password Attacks 12

        Anatomy of an Attack 13

        Reconnaissance 13

        Exploitation 14

        Expansion/Entrenchment 15

        Exfiltration/Damage 16

        Clean Up 16

        The Modern Adversary 16

        Credentials, the Keys to the Kingdom 17

        Conclusion 20

        Chapter 2 Incident Readiness 21

        Preparing Your Process 21

        Preparing Your People 27

        Preparing Your Technology 30

        Ensuring Adequate Visibility 33

        Arming Your Responders 37

        Business Continuity and Disaster Recovery 38

        Deception Techniques 40

        Conclusion 43

        Part II Respond 45

        Chapter 3 Remote Triage 47

        Finding Evil 48

        Rogue Connections 49

        Unusual Processes 52

        Unusual Ports 55

        Unusual Services 56

        Rogue Accounts 56

        Unusual Files 58

        Autostart Locations 59

        Guarding Your Credentials 61

        Understanding Interactive Logons 61

        Incident Handling Precautions 63

        RDP Restricted Admin Mode and Remote Credential Guard 64

        Conclusion 65

        Chapter 4 Remote Triage Tools 67

        Windows Management Instrumentation Command-Line Utility 67

        Understanding WMI and the WMIC Syntax 68

        Forensically Sound Approaches 71

        WMIC and WQL Elements 72

        Example WMIC Commands 79

        PowerShell 84

        Basic PowerShell Cmdlets 87

        PowerShell Remoting 91

        Accessing WMI/MI/CIM with PowerShell 95

        Incident Response Frameworks 98

        Conclusion 100

        Chapter 5 Acquiring Memory 103

        Order of Volatility 103

        Local Memory Collection 105

        Preparing Storage Media 107

        The Collection Process 109

        Remote Memory Collection 117

        WMIC for Remote Collection 119

        PowerShell Remoting for Remote Collection 122

        Agents for Remote Collection 125

        Live Memory Analysis 128

        Local Live Memory Analysis 129

        Remote Live Memory Analysis 129

        Conclusion 131

        Chapter 6 Disk Imaging 133

        Protecting the Integrity of Evidence 133

        Dead-Box Imaging 137

        Using a Hardware Write Blocker 139

        Using a Bootable Linux Distribution 143

        Live Imaging 149

        Live Imaging Locally 149

        Collecting a Live Image Remotely 154

        Imaging Virtual Machines 155

        Conclusion 160

        Chapter 7 Network Security Monitoring 161

        Security Onion 161

        Architecture 162

        Tools 165

        Snort, Sguil, and Squert 166

        Zeek (Formerly Bro) 172

        Elastic Stack 182

        Text-Based Log Analysis 194

        Conclusion 197

        Chapter 8 Event Log Analysis 199

        Understanding Event Logs 199

        Account-Related Events 207

        Object Access 218

        Auditing System Configuration Changes 221

        Process Auditing 224

        Auditing PowerShell Use 229

        Using PowerShell to Query Event Logs 231

        Conclusion 233

        Chapter 9 Memory Analysis 235

        The Importance of Baselines 236

        Sources of Memory Data 242

        Using Volatility and Rekall 244

        Examining Processes 249

        The pslist Plug-in 249

        The pstree Plug-in 252

        ...

        Biographie:

        Steve Anson is a SANS Certified Instructor and co-founder of leading IT security company Forward Defense. He has over 20 years of experience investigating cybercrime and network intrusion incidents. As a former US federal agent, Steve specialized in intrusion investigations for the FBI and DoD. He has taught incident response and digital forensics techniques to thousands of students around the world on behalf of the FBI Academy, US Department of State, and the SANS Institute. He has assisted governments in over 50 countries to improve their strategic and tactical response to computer-facilitated crimes and works with a range of multinational organizations to prevent, detect and respond to network security incidents....

        Sommaire:

        Incident response is critical for the active defense of any network, and incident responders need up-to-date, immediately applicable techniques with which to engage the adversary.??Applied Incident Response?details effective ways to respond to advanced attacks against local and remote network resources,?providing proven response techniques and a framework through which to apply them.? As a starting point for new incident handlers, or as a technical reference for hardened IR veterans, this book details the latest techniques for responding to threats against your network, including:

        • Preparing your environment for effective incident response
        • Leveraging MITRE ATT&CK and threat intelligence for active network defense
        • Local and remote triage of systems using PowerShell, WMIC, and open-source tools
        • Acquiring RAM and disk images locally and remotely
        • Analyzing RAM with Volatility and Rekall
        • Deep-dive forensic analysis of system drives using open-source or commercial tools
        • Leveraging Security Onion and Elastic Stack for network security monitoring
        • Techniques for log analysis and aggregating high-value logs
        • Static and dynamic analysis of malware with YARA rules, FLARE VM, and Cuckoo Sandbox
        • Detecting and responding to lateral movement techniques, including pass-the-hash, pass-the-ticket, Kerberoasting, malicious use of PowerShell, and many more
        • Effective threat hunting techniques
        • Adversary emulation with Atomic Red Team
        • Improving preventive and detective controls
        ...

        Détails de conformité du produit

        Consulter les détails de conformité de ce produit (

        Personne responsable dans l'UE

        )
        Le choixNeuf et occasion
        Minimum5% remboursés
        Le service clientsÀ votre écoute
        LinkedinFacebookTwitterInstagramYoutubePinterestTiktok
        visavisa
        mastercardmastercard
        klarnaklarna
        paypalpaypal
        floafloa
        americanexpressamericanexpress
        Rakuten Logo
        • Rakuten Kobo
        • Rakuten TV
        • Rakuten Viber
        • Rakuten Viki
        • Plus de services
        • À propos de Rakuten
        Rakuten.com