My Account Log in

1 option

Advanced Cyber Threat Intelligence and Hunting.

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Tiepolo, Gianluca
Contributor:
Sorensen, Dan
Language:
English
Subjects (All):
Artificial intelligence--Industrial applications.
Artificial intelligence.
Computer security.
Physical Description:
1 online resource (658 p.)
Place of Publication:
Birmingham, England Packt Publishing 2026
Summary:
Develop actionable strategies to proactively hunt advanced persistent threats and detect zero-days using CTI and behavior-based detection techniques Key Features Intelligence-led threat hunting framework for detecting APTs and zero-day attacks at scale Hands-on detection of stealthy adversaries using behavioral analytics and machine learning...
Contents:
Intro
Advanced Cyber Threat Intelligence and Hunting
Detect APTs and zero-day attacks using CTI, behavioral analytics, and AI techniques
Contributors
About the authors
About the reviewers
Table of Contents
Preface
Who this book is for
What this book covers
To get the most out of this book
Download the example code files
Download the color images
Conventions used
Free benefits with your book
How to Unlock
Get in touch
Share your thoughts
Part 1
Foundations of Cyber Threat Intelligence
1
Revisiting CTI for Advanced Threat Hunting
Defining CTI
Strategic, operational, and tactical CTI
The Pyramid of Pain
Low pain indicators
Medium pain indicators
High pain indicators
IOCs vs. TTPs
Defining cyber threats
Known threats
Unknown threats
The pitfalls of overfocusing on known threats
The intelligence cycle
The proactive workflow
Introducing threat hunting
Key frameworks for intrusion analysis
Practical exercise
mapping CTI to MITRE ATT&CK for hypothesis generation
Scenario
Sample report
Tasks
Summary
Get this book's PDF copy, code bundle, and more
2
Understanding APTs
Actors, Motivations, and TTPs
Introducing threat actors
Defining actor types
Understanding advanced persistent threats
A history of APTs
The case of Moonlight Maze (1996-1998)
Stuxnet (2010)
The APT1 report (2013)
The modern APT
Understanding APT intent, capabilities, and common modus operandi
Intent and motivations
Capabilities and modus operandi
Offensive development and capabilities
Infrastructure and logistics
Lateral movement and persistence
Data exfiltration
Evasion and anti-forensics
Cloud, Edge devices and IoT exploitation
Artificial intelligence and automation
Using the Kill Chain for intrusion analysis
Dissecting the Cyber Kill Chain
Reconnaissance
Weaponization
Delivery
Exploitation
Installation
Command and Control (C2)
Actions on Objectives
Practical use case: Analyzing an APT28 intrusion
Campaign summary
Campaign analysis
Summary
Further reading
Get this book's PDF copy, code bundle, and more
3
Deep Dive
CTI Collection and Enrichment for APTs
CTI collection in the security operations workflow
Traditional data collection
Open-source intelligence (OSINT)
Commercial and vendor intelligence feeds
Internal sources
Threat intelligence platforms
The evolution beyond basic threat feeds
Enrichment: The alchemy of CTI
Enrichment tools
Automation workflow
Analysis and analytic pivoting
Introducing the Diamond Model
Mapping the attack lifecycle with MITRE ATT&CK
Adversary hunting
Tracking threat actor infrastructure over time
Infrastructure overlap
Passive DNS
WHOIS analysis
ISBN:
9781806380398
OCLC:
1581573951
Publisher Number:
CIPO000357211

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account