MTU Library Catalogue

Syndetics cover image
Image from Syndetics

Blue team handbook : incident response edition: a condensed field guide for the cyber security incident responder / Don Murdoch.

By: Murdoch, Don [author].
Material type: materialTypeLabelBookPublisher: Charleston, SC : CreateSpace Independent Publishing Platform, 2015Edition: Second edition.Description: iv, 146 pages ; 23 cm.Content type: text Media type: unmediated Carrier type: volumeISBN: 9781500734756; 1500734756.Subject(s): Information technology -- Security measures | Computer security -- Management | Cyberspace -- Security measures | Data protection | Computer networks -- Security measuresDDC classification: 658.478
Contents:
Blue team handbook - introduction -- Some lessons from the US military -- Six steps of incident response -- Assessing impact of cyber attacks -- Essential IR business process and paperwork -- Chain of custody and evidence topics (V2) -- Six step incident response template -- Commercial incident response template -- Incident response and forensics are partners -- The attack process, tools, and IR points -- Secure communications -- Netcat and Cryptcat for the blue team -- Nmap and Masscan network assessment -- Windows counter loops -- Simple windows password guessing -- Automated collection (Windows) -- Malware standard response pattern -- Windows volatile data investigation -- Other windows artifact investigation -- Linux volatile data system investigation -- Linux artifact investigation -- SIFT based timeline construction (Windows) -- Linux Iptables essentials: An example -- Firewall Assurance/Testing with HPing -- Network device collection and analysis process -- Website investigation techniques -- Network traffic analysis techniques -- Common malware campaign pattern -- Suspicious traffic patterns -- Packet data carving notes -- RDBMS incident response (V2) -- Wireless specific topics -- Using the snort IDS (Blacktrack, Kali) -- Notes: Bootable Linux distributions -- Vulnerability testing (OpenVAS) -- Wireshark usage notes -- Password assessment -- Common TCP and UDP ports -- ICMP table -- Web site references -- ICMP header -- IPVA header -- UDP header -- TCP header -- IPv6 header -- Acronyms used in this manual.
Summary: The Blue Team Handbook is a zero fluff reference guide for cyber security incident responders and InfoSec pros alike. The BTHb includes essential information in a condensed handbook format about the incident response process, how attackers work, common tools, a methodology for network analysis developed over 12 years, Windows and Linux analysis processes, tcpdump usage examples, Snort IDS usage, and numerous other topics. The book is peppered with practical real life techniques from the authors extensive career working in academia and a corporate setting. Whether you are writing up your cases notes, analyzing potentially suspicious traffic, or called in to look over a misbehaving server this book should help you handle the case and teach you some new techniques along the way.
Holdings
Item type Current library Call number Copy number Status Barcode
General lending MTU Bishopstown Library Lending 658.478 (Browse shelf(Opens below)) 1 Available 00163747
Total holds: 0

Enhanced descriptions from Syndetics:

BTHb:INRE - Version 2.2 now available. Voted #3 of the 100 Best Cyber Security Books of All Time by Vinod Khosla, Tim O'Reilly andMarcus Spoons Stevens on BookAuthority.com as of 06/09/2018!The Blue Team Handbook is a "zero fluff" reference guide for cyber security incident responders, security engineers, and InfoSec pros alike. The BTHb includes essential information in a condensed handbook format. Main topics include the incident response process, how attackers work, common tools for incident response, a methodology for network analysis, common indicators of compromise, Windows and Linux analysis processes, tcpdump usage examples, Snort IDS usage, packet headers, and numerous other quick reference topics. The book is designed specifically to share "real life experience", so it is peppered with practical techniques from the authors' extensive career in handling incidents. Whether you are writing up your cases notes, analyzing potentially suspicious traffic, or called in to look over a misbehaving server - this book should help you handle the case and teach you some new techniques along the way.


Version 2.2 updates:
- *** A new chapter on Indicators of Compromise added.
- Table format slightly revised throughout book to improve readability.
- Dozens of paragraphs updated and expanded for readability and completeness.
- 15 pages of new content since version 2.0.

Includes bibliographical references (page 138) and index.

Blue team handbook - introduction -- Some lessons from the US military -- Six steps of incident response -- Assessing impact of cyber attacks -- Essential IR business process and paperwork -- Chain of custody and evidence topics (V2) -- Six step incident response template -- Commercial incident response template -- Incident response and forensics are partners -- The attack process, tools, and IR points -- Secure communications -- Netcat and Cryptcat for the blue team -- Nmap and Masscan network assessment -- Windows counter loops -- Simple windows password guessing -- Automated collection (Windows) -- Malware standard response pattern -- Windows volatile data investigation -- Other windows artifact investigation -- Linux volatile data system investigation -- Linux artifact investigation -- SIFT based timeline construction (Windows) -- Linux Iptables essentials: An example -- Firewall Assurance/Testing with HPing -- Network device collection and analysis process -- Website investigation techniques -- Network traffic analysis techniques -- Common malware campaign pattern -- Suspicious traffic patterns -- Packet data carving notes -- RDBMS incident response (V2) -- Wireless specific topics -- Using the snort IDS (Blacktrack, Kali) -- Notes: Bootable Linux distributions -- Vulnerability testing (OpenVAS) -- Wireshark usage notes -- Password assessment -- Common TCP and UDP ports -- ICMP table -- Web site references -- ICMP header -- IPVA header -- UDP header -- TCP header -- IPv6 header -- Acronyms used in this manual.

The Blue Team Handbook is a zero fluff reference guide for cyber security incident responders and InfoSec pros alike. The BTHb includes essential information in a condensed handbook format about the incident response process, how attackers work, common tools, a methodology for network analysis developed over 12 years, Windows and Linux analysis processes, tcpdump usage examples, Snort IDS usage, and numerous other topics. The book is peppered with practical real life techniques from the authors extensive career working in academia and a corporate setting. Whether you are writing up your cases notes, analyzing potentially suspicious traffic, or called in to look over a misbehaving server this book should help you handle the case and teach you some new techniques along the way.