Practical Detection Engineering with Sigma: Implement Cross-Platform Threat Detections and SIEM Integration for Modern Security Operations (English Edition)

Prijzen vanaf
21,24

Uitgelicht

VERGELIJK ALLE AANBIEDERS (3)

Beschrijving

Bol Practical Detection Engineering with Sigma is a hands-on guide to building, testing, and operationalizing modern detections in real SOC environments. The book walks you step by step through the full detection engineering lifecycle—from understanding Sigma fundamentals to writing structured rules and deploying them across SIEM and XDR platforms. You will learn how to translate adversary behavior into behavior-based detections, aligned with MITRE ATT&CK, create rules for Windows, Linux, and network telemetry, and convert them into backend-specific queries for platforms such as Elastic, Splunk, Microsoft Sentinel, and Wazuh. Practical examples demonstrate how to validate detections using real and simulated attack data, reduce false positives, and design alerts that analysts can confidently triage. From rule creation to CI/CD automation, version control, and large-scale rule management, this book equips you to build scalable, maintainable, and production-ready detection programs aligned with modern security operations.

Vergelijk aanbieders (3)

Shop
Prijs
Verzendkosten
Totale prijs
38,66
21,24
Gratis
21,24
Naar shop
Gratis Shipping Costs
41,33
Gratis
41,33
Naar shop
Gratis Shipping Costs
41,33
Gratis
41,33
Naar shop
Gratis Shipping Costs
Beschrijving (2)
Bol

Practical Detection Engineering with Sigma is a hands-on guide to building, testing, and operationalizing modern detections in real SOC environments. The book walks you step by step through the full detection engineering lifecycle—from understanding Sigma fundamentals to writing structured rules and deploying them across SIEM and XDR platforms. You will learn how to translate adversary behavior into behavior-based detections, aligned with MITRE ATT&CK, create rules for Windows, Linux, and network telemetry, and convert them into backend-specific queries for platforms such as Elastic, Splunk, Microsoft Sentinel, and Wazuh. Practical examples demonstrate how to validate detections using real and simulated attack data, reduce false positives, and design alerts that analysts can confidently triage. From rule creation to CI/CD automation, version control, and large-scale rule management, this book equips you to build scalable, maintainable, and production-ready detection programs aligned with modern security operations.

Amazon

Pagina's: 448, Paperback, Orange Education Pvt Ltd


Productspecificaties

Merk Ava
EAN
  • 9789349887978
Maat


Prijshistorie

* Prijshistorie bevat geen data van Amazon, Amazon Marketplace.

Prijzen voor het laatst bijgewerkt op:

Uitgelichte Keuze
21,24
Naar shop