Adversary Emulation with Mitre Att&ck: Bridging the Gap Between the Red and Blue Teams
暫譯: 利用 Mitre Att&ck 進行對手模擬:縮短紅隊與藍隊之間的差距
Selmanaj, Drinor
- 出版商: O'Reilly
- 出版日期: 2025-06-03
- 售價: $2,310
- 貴賓價: 9.5 折 $2,195
- 語言: 英文
- 頁數: 399
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1098143760
- ISBN-13: 9781098143763
尚未上市,無法訂購
相關主題
商品描述
By incorporating cyber threat intelligence, adversary emulation provides a form of cybersecurity assessment that mimics advanced persistent threat (APT) tactics, techniques, and procedures (TTPs). This comprehensive guide introduces an empirical approach with strategies and processes collected over a decade of experience in the cybersecurity field. You'll learn to assess resilience against coordinated and stealthy threat actors capable of harming an organization.
Author Drinor Selmanaj demonstrates adversary emulation for offensive operators and defenders using practical examples and exercises that actively model adversary behavior. Each emulation plan includes different hands-on scenarios, such as smash-and-grab or slow-and-deliberate. This book uses the MITRE ATT&CK knowledge base as a foundation to describe and categorize TTPs based on real-world observations and provides a common language that's standardized and accessible to everyone.
You'll learn how to:
- Map cyber threat intelligence to ATT&CK
- Define adversary emulation goals and objectives
- Research adversary emulation TTPs using ATT&CK knowledge base
- Plan adversary emulation activity
- Implement adversary tradecraft
- Conduct adversary emulation
- Communicate adversary emulation findings
- Automate adversary emulation to support repeatable testing
- Execute FIN6, APT3, and APT29 emulation plans
商品描述(中文翻譯)
透過整合網路威脅情報,對手模擬提供了一種模仿進階持續威脅(APT)戰術、技術和程序(TTPs)的網路安全評估形式。本綜合指南介紹了一種經驗性的方法,包含在網路安全領域十多年累積的策略和流程。您將學會評估對抗能夠對組織造成傷害的協調性和隱蔽性威脅行為者的韌性。
作者 Drinor Selmanaj 透過實際範例和練習,展示了對手模擬如何為攻擊者和防禦者提供支持,這些範例和練習積極模擬對手行為。每個模擬計畫包括不同的實作情境,例如快速搶奪或緩慢而深思熟慮的行動。本書以 MITRE ATT&CK 知識庫為基礎,描述和分類基於現實觀察的 TTPs,並提供一種標準化且易於理解的共同語言。
您將學會如何:
- 將網路威脅情報映射到 ATT&CK
- 定義對手模擬的目標和目的
- 使用 ATT&CK 知識庫研究對手模擬的 TTPs
- 計畫對手模擬活動
- 實施對手的技術
- 進行對手模擬
- 溝通對手模擬的發現
- 自動化對手模擬以支持可重複測試
- 執行 FIN6、APT3 和 APT29 模擬計畫