Wazuh SIEM & XDR Mastery: Build a Real-World SOC Lab for Threat Hunting, Security Monitoring, Incident Response, Linux Defense, and Cloud Security
暫譯: Wazuh SIEM 與 XDR 精通:建立實際的 SOC 實驗室以進行威脅獵捕、安全監控、事件響應、Linux 防禦及雲端安全

Vertex, Zane

  • 出版商: Independently Published
  • 出版日期: 2026-05-21
  • 售價: $1,140
  • 貴賓價: 9.5$1,083
  • 語言: 英文
  • 頁數: 210
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798198027954
  • ISBN-13: 9798198027954
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

商品描述

Master the Future of Cybersecurity with Wazuh SIEM and XDR

Modern cyber threats demand far more than traditional antivirus software and firewalls. Today's organizations rely on Security Operations Centers (SOCs), SIEM platforms, and XDR technologies to detect, investigate, and respond to attacks across Linux systems, cloud environments, endpoints, containers, and enterprise networks.

Wazuh SIEM and XDR Mastery is a practical, hands-on guide designed to help you build real-world cybersecurity skills using one of the most powerful open-source security monitoring platforms available today.

Whether you are an aspiring SOC analyst, blue team engineer, cybersecurity student, Linux administrator, or IT professional transitioning into security operations, this book provides the technical knowledge and operational mindset needed to monitor, detect, investigate, and respond to modern cyber threats effectively.

Inside this book, you will learn how to:

  • Build and configure a complete Wazuh SIEM and XDR environment
  • Monitor Linux systems, logs, processes, and network activity
  • Detect brute-force attacks, malware behavior, persistence mechanisms, and suspicious activity
  • Configure Wazuh agents, dashboards, and custom detection rules
  • Perform real-world log analysis and security event correlation
  • Build effective incident response workflows
  • Reduce false positives and improve alert accuracy
  • Integrate Suricata and Zeek for advanced threat detection
  • Monitor AWS, Azure, Docker, Kubernetes, and hybrid environments
  • Perform vulnerability detection and compliance monitoring
  • Build a practical home SOC lab for hands-on learning
  • Develop threat hunting and blue team investigation skills

Unlike theory-heavy cybersecurity books, this guide focuses on real SOC workflows, practical monitoring strategies, detection engineering, and enterprise-grade defensive operations used in modern environments.

By the end of this book, you will understand how defenders think, how attackers behave, and how to use Wazuh to build powerful security monitoring and threat detection capabilities from the ground up.

If you want to master SIEM, XDR, Linux security monitoring, threat hunting, and real-world SOC operations, this book provides the practical roadmap to help you build professional cybersecurity skills and advance your cybersecurity career.

商品描述(中文翻譯)

掌握未來的網路安全:Wazuh SIEM 和 XDR

現代的網路威脅要求的不僅僅是傳統的防毒軟體和防火牆。當今的組織依賴於 安全運營中心 (SOCs)、SIEM 平台和 XDR 技術 來檢測、調查和應對在 Linux 系統、雲端環境、端點、容器和企業網路中的攻擊。

Wazuh SIEM 和 XDR 精通 是一本實用的、動手操作的指南,旨在幫助您使用當今最強大的開源安全監控平台之一來建立現實世界的網路安全技能。

無論您是有志成為 SOC 分析師、藍隊工程師、網路安全學生、Linux 管理員或轉型為安全運營的 IT 專業人員,本書提供了監控、檢測、調查和有效應對現代網路威脅所需的技術知識和操作思維。

在本書中,您將學習如何:


  • 建立和配置完整的 Wazuh SIEM 和 XDR 環境

  • 監控 Linux 系統、日誌、進程和網路活動

  • 檢測暴力破解攻擊、惡意軟體行為、持久性機制和可疑活動

  • 配置 Wazuh 代理、儀表板和自定義檢測規則

  • 執行現實世界的日誌分析和安全事件關聯

  • 建立有效的事件響應工作流程

  • 減少誤報並提高警報準確性

  • 整合 Suricata 和 Zeek 以進行高級威脅檢測

  • 監控 AWS、Azure、Docker、Kubernetes 和混合環境

  • 執行漏洞檢測和合規性監控

  • 建立實用的家庭 SOC 實驗室以進行動手學習

  • 發展威脅獵捕和藍隊調查技能

與理論重的網路安全書籍不同,本指南專注於 現實的 SOC 工作流程、實用的監控策略、檢測工程和企業級防禦操作,這些都是在現代環境中使用的。

在本書結束時,您將了解防禦者的思維方式、攻擊者的行為,以及如何使用 Wazuh 從零開始建立強大的安全監控和威脅檢測能力。

如果您想掌握 SIEM、XDR、Linux 安全監控、威脅獵捕和現實世界的 SOC 操作,本書提供了實用的路線圖,幫助您建立專業的網路安全技能並推進您的網路安全職業生涯。