Blue Team Handbook: Soc, Siem, and Threat Hunting: Practical Techniques for Security Operations and Threat Hunting Teams
暫譯: 藍隊手冊:SOC、SIEM 與威脅獵捕——安全營運與威脅獵捕團隊的實務技術

Murdoch, Don

  • 出版商: O'Reilly
  • 出版日期: 2026-10-13
  • 售價: $2,710
  • 貴賓價: 9.5$2,574
  • 語言: 英文
  • 頁數: 488
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798341662292
  • ISBN-13: 9798341662292
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

As cyberthreats become more sophisticated and alert volumes rise, security teams need more than just tools--they need strategy, structure, and field-tested guidance. Following the success of the original print edition, this updated edition of Blue Team Handbook: SOC, SIEM, and Threat Hunting is still the essential resource for building, optimizing, and managing modern detection engineering practices and security operations centers.

This practical guide distills over 20 years of frontline cybersecurity experience into an actionable playbook for analysts, SOC managers, architects, detection engineers, and threat hunters. Author Don Murdoch delivers expert insights designed to help teams improve quickly. Whether you're refining your current operations or launching a SOC from scratch, this book empowers you with proven, real-world techniques to defend against today's most persistent threats.

  • Build and organize SOC teams for maximum operational impact
  • Understand how to launch and execute a comprehensive telemetry, audit data, and SIEM deployment strategy
  • Create effective SOC use cases, including risk-based alerting
  • Develop and apply meaningful metrics to evaluate SOC effectiveness, analyst performance, and SIEM utility
  • Identify advanced threats using real-world threat hunting techniques

商品描述(中文翻譯)

隨著網路威脅日益複雜、警示數量持續增加,資安團隊需要的不只是工具,更需要策略、架構與經過實務驗證的指引。在初版紙本書廣受好評之後,這本更新版的《Blue Team Handbook: SOC, SIEM, and Threat Hunting》依然是建立、最佳化及管理現代化偵測工程實務與安全性作業中心(SOC)的必備資源。

本實用指南將作者超過 20 年的第一線網路安全經驗,濃縮成一套可實際執行的作戰手冊,適用於分析師、SOC 管理者、架構師、偵測工程師與威脅獵捕人員。作者 Don Murdoch 提供專業洞見,協助團隊迅速提升能力。無論您是要改善現有的作業流程,或是從零開始建立 SOC,本書都能提供經過驗證的實務技術,協助您防禦當今最難以根除的威脅。

• 建立並組織 SOC 團隊,以發揮最大的作業效益
• 了解如何啟動並執行完整的遙測資料、稽核資料與 SIEM 部署策略
• 建立有效的 SOC 使用案例,包括風險導向的警示(risk-based alerting)
• 開發並套用具意義的衡量指標,以評估 SOC 的效能、分析師的表現及 SIEM 的實用性
• 運用真實世界的威脅獵捕技術,識別進階威脅