Op werkdagen voor 23:00 besteld, morgen in huis Gratis verzending vanaf €20

Cloud Defense Strategies with Azure Sentinel

Hands-on Threat Hunting in Cloud Logs and Services

Paperback Engels 2021 1e druk 9781484271315
Verwachte levertijd ongeveer 9 werkdagen

Samenvatting

Use various defense strategies with Azure Sentinel to enhance your cloud security. This book will help you get hands-on experience, including threat hunting inside Azure cloud logs and metrics from services such as Azure Platform, Azure Active Directory, Azure Monitor, Azure Security Center, and others such as Azure Defender's many security layers. This book is divided into three parts.

Part I helps you gain a clear understanding of Azure Sentinel and its features along with Azure Security Services, including Azure Monitor, Azure Security Center, and Azure Defender. Part II covers integration with third-party security appliances and you learn configuration support, including AWS. You will go through multi-Azure Tenant deployment best practices and its challenges.

In Part III you learn how to improve cyber security threat hunting skills while increasing your ability to defend against attacks, stop data loss, prevent business disruption, and expose hidden malware. You will get an overview of the MITRE Attack Matrix and its usage, followed by Azure Sentinel operations and how to continue Azure Sentinel skill improvement. After reading this book, you will be able to protect Azure resources from cyberattacks and support XDR (Extend, Detect, Respond), an industry threat strategy through Azure Sentinel.

What You Will LearnUnderstand Azure Sentinel technical benefits and functionalityConfigure to support incident responseIntegrate with Azure Security standardsBe aware of challenges and costs for the Azure log analytics workspaceWho This Book Is ForSecurity consultants, solution architects, cloud security architects, and IT security engineers

Specificaties

ISBN13:9781484271315
Taal:Engels
Bindwijze:paperback
Aantal pagina's:285
Uitgever:Apress
Druk:1
Verschijningsdatum:2-10-2021
Hoofdrubriek:IT-management / ICT

Lezersrecensies

Wees de eerste die een lezersrecensie schrijft!

Inhoudsopgave

Part I (page count 100) Goals: Introduction to Azure Sentinel es with technical featurthat benefit the business. Initial configuration using Azure subscription data connectors, discuss 3rd party integration and alignment with other Azure Security Services. XDR introduction, why it is an industry standard and how to use it in Sentinel.

Sub-Topics
1. Overview of Technical Features
2. Benefit and cost support for the business, initial configuration
3. Azure Defender support into Azure Sentinel
4. Azure Security Center support into Azure Sentinel

Chapter 1 Azure Sentinel Overview
Platform benefits, SOC security reference, alignment to Cyber framework, Log Analytics planning, cost structure

Chapter 2 Other Azure Security Services Azure Monitor, Azure Security Center, Azure Defender, working together to support Azure Sentinel

Chapter 3 Azure Sentinel XDR Capabilities Integration with Azure Security standards, protection for additional Azure workloads, guidance for XDR and how it should be used to modernize security operations.

Part II (page count 100) Goals: Deployment best practices, platform integration and support for AWS

Sub - Topics
1. Enable integration with 3rd party security appliances
2. Configure support for AWS
3. Multi-Azure Tenant deployment best practices

Chapter 4 Data Connection
Single Tenant: Data connectors native, Log Analytics storage options, 3rd party data, KQL validation processes, AWS connection, Service NOW integration

Chapter 5 Threat Intelligence (TI)
TI connectors and feeds, Sentinel Workbooks introduction, Sentinel Notebook usage, Python integration

Chapter 6 Multi-Tenant Architecture
Challenges and cost of Azure log analytics workspace, KQL modification requirements, SOC alignment needed

Part III (page count 100) Goals: Improve Cyber Security Threat Hunting Techniques

Sub - Topics:
1. Threat Hunting with KQL Language deep dive with examples
2. Integration with MITRE attack Matrix and support for TAXII
3. Data flow examples: User logon, track and validate. Stop network connection to China, etc.
4. Configuration changes needed for multiple Sentinel deployments

Chapter 7 Threat Hunting with Azure Sentinel
KQL Hunting introduction, custom queries, Sentinel bookmarks, Sentinel notebooks

Chapter 8 Introduction to MITRE Matrix
MITRE Attack Matrix overview and usage, STIX defined, TAXII defined, free TI -vs- service SLA

Chapter 9 Azure Sentinel Operations
Daily, Weekly, Monthly tasks, SOC engineer alignment, Continued SOC operations support from official Microsoft supported forum

Chapter Appendix: Chapter Goal: Where to gain additional knowledge for Azure Sentinel

No of pages: 20

Sub - Topics:
1. Guidance to continue Azure Sentinel skill improvement
2. Relating information to Cyber Security standards

Managementboek Top 100

Rubrieken

Populaire producten

    Personen

      Trefwoorden

        Cloud Defense Strategies with Azure Sentinel