Book description
Using a well-conceived incident response plan in the aftermath of an online security breach enables your team to identify attackers and learn how they operate. But only when you approach incident response with a cyber threat intelligence mindset will you truly understand the value of that information. In this updated second edition, you'll learn the fundamentals of intelligence analysis as well as the best ways to incorporate these techniques into your incident response process.
Each method reinforces the other: threat intelligence supports and augments incident response, while incident response generates useful threat intelligence. This practical guide helps incident managers, malware analysts, reverse engineers, digital forensics specialists, and intelligence analysts understand, implement, and benefit from this relationship.
In three parts, this in-depth book includes:
- The fundamentals: Get an introduction to cyberthreat intelligence, the intelligence process, the incident response process, and how they all work together
- Practical application: Walk through the intelligence-driven incident response (IDIR) process using the F3EAD process: Find, Fix, Finish, Exploit, Analyze, and Disseminate
- The way forward: Explore big-picture aspects of IDIR that go beyond individual incident response investigations, including intelligence team building
Publisher resources
Table of contents
- Foreword to the Second Edition
- Foreword to the First Edition
- Preface
- I. The Fundamentals
- 1. Introduction
- 2. Basics of Intelligence
- 3. Basics of Incident Response
- II. Practical Application
- 4. Find
- 5. Fix
- 6. Finish
- 7. Exploit
- 8. Analyze
- 9. Disseminate
- III. The Way Forward
- 10. Strategic Intelligence
- 11. Building an Intelligence Program
- Index
- About the Authors
Product information
- Title: Intelligence-Driven Incident Response, 2nd Edition
- Author(s):
- Release date: June 2023
- Publisher(s): O'Reilly Media, Inc.
- ISBN: 9781098120689
You might also like
book
Intelligence-Driven Incident Response
Using a well-conceived incident response plan in the aftermath of an online security breach enables your …
book
Applied Incident Response
Incident response is critical for the active defense of any network, and incident responders need up-to-date, …
book
Security in Computing, 6th Edition
The New State of the Art in Information Security: From Cloud to Crypto, AI-Driven Security to …
audiobook
(ISC)2 CISSP Certified Information Systems Security Professional Official Study Guide 9th Edition
(ISC)2 Certified Information Systems Security Professional (CISSP) Official Study Guide, 9th Edition has been completely updated …