1 option
Advanced Cyber Threat Intelligence and Hunting.
- Format:
- Book
- Author/Creator:
- Tiepolo, Gianluca
- Language:
- English
- Subjects (All):
- Artificial intelligence--Industrial applications.
- Artificial intelligence.
- Computer security.
- Physical Description:
- 1 online resource (658 p.)
- Place of Publication:
- Birmingham, England Packt Publishing 2026
- Summary:
- Develop actionable strategies to proactively hunt advanced persistent threats and detect zero-days using CTI and behavior-based detection techniques Key Features Intelligence-led threat hunting framework for detecting APTs and zero-day attacks at scale Hands-on detection of stealthy adversaries using behavioral analytics and machine learning...
- Contents:
- Intro
- Advanced Cyber Threat Intelligence and Hunting
- Detect APTs and zero-day attacks using CTI, behavioral analytics, and AI techniques
- Contributors
- About the authors
- About the reviewers
- Table of Contents
- Preface
- Who this book is for
- What this book covers
- To get the most out of this book
- Download the example code files
- Download the color images
- Conventions used
- Free benefits with your book
- How to Unlock
- Get in touch
- Share your thoughts
- Part 1
- Foundations of Cyber Threat Intelligence
- 1
- Revisiting CTI for Advanced Threat Hunting
- Defining CTI
- Strategic, operational, and tactical CTI
- The Pyramid of Pain
- Low pain indicators
- Medium pain indicators
- High pain indicators
- IOCs vs. TTPs
- Defining cyber threats
- Known threats
- Unknown threats
- The pitfalls of overfocusing on known threats
- The intelligence cycle
- The proactive workflow
- Introducing threat hunting
- Key frameworks for intrusion analysis
- Practical exercise
- mapping CTI to MITRE ATT&CK for hypothesis generation
- Scenario
- Sample report
- Tasks
- Summary
- Get this book's PDF copy, code bundle, and more
- 2
- Understanding APTs
- Actors, Motivations, and TTPs
- Introducing threat actors
- Defining actor types
- Understanding advanced persistent threats
- A history of APTs
- The case of Moonlight Maze (1996-1998)
- Stuxnet (2010)
- The APT1 report (2013)
- The modern APT
- Understanding APT intent, capabilities, and common modus operandi
- Intent and motivations
- Capabilities and modus operandi
- Offensive development and capabilities
- Infrastructure and logistics
- Lateral movement and persistence
- Data exfiltration
- Evasion and anti-forensics
- Cloud, Edge devices and IoT exploitation
- Artificial intelligence and automation
- Using the Kill Chain for intrusion analysis
- Dissecting the Cyber Kill Chain
- Reconnaissance
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and Control (C2)
- Actions on Objectives
- Practical use case: Analyzing an APT28 intrusion
- Campaign summary
- Campaign analysis
- Summary
- Further reading
- Get this book's PDF copy, code bundle, and more
- 3
- Deep Dive
- CTI Collection and Enrichment for APTs
- CTI collection in the security operations workflow
- Traditional data collection
- Open-source intelligence (OSINT)
- Commercial and vendor intelligence feeds
- Internal sources
- Threat intelligence platforms
- The evolution beyond basic threat feeds
- Enrichment: The alchemy of CTI
- Enrichment tools
- Automation workflow
- Analysis and analytic pivoting
- Introducing the Diamond Model
- Mapping the attack lifecycle with MITRE ATT&CK
- Adversary hunting
- Tracking threat actor infrastructure over time
- Infrastructure overlap
- Passive DNS
- WHOIS analysis
- ISBN:
- 9781806380398
- OCLC:
- 1581573951
- Publisher Number:
- CIPO000357211
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.