Part I. Understanding Adversary Emulation
If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.
Sun Tzu, The Art of War
Part I equips you with a strong foundation for adversary emulation (AE) and helps you start a journey of cognition on adversarial tradecraft through contemplation and experience. You will have the chance to explore some of the processes used by cybersecurity professionals to protect critical segments of an organization. You will read stories of the dark side of the internet, where cyber adversaries try to circumvent these defenses. In addition, you will learn how to use visualization to show defensive coverage, red/blue team planning, the frequency of detected techniques, or other daily tasks, helping you present your findings better.
Later chapters dive deep into cyber intelligence reports of some of the leading cybersecurity organizations and explain how the MITRE ATT&CK framework can help you effectively communicate actionable threat intelligence to build more realistic emulation plans. Finally, you will understand the goals and objectives these threats have and how you can use their behavior to assess your organization’s security.
You will be able to provide a holistic view of security by assessing people and training them to become better defenders, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access