

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Iceland.
Incident response is critical for the active defense of any network, and incident responders need up-to-date, immediately applicable techniques with which to engage the adversary. Applied Incident Response details effective ways to respond to advanced attacks against local and remote network resources, providing proven response techniques and a framework through which to apply them. As a starting point for new incident handlers, or as a technical reference for hardened IR veterans, this book details the latest techniques for responding to threats against your network, including: Preparing your environment for effective incident response Leveraging MITRE ATT&CK and threat intelligence for active network defense Local and remote triage of systems using PowerShell, WMIC, and open-source tools Acquiring RAM and disk images locally and remotely Analyzing RAM with Volatility and Rekall Deep-dive forensic analysis of system drives using open-source or commercial tools Leveraging Security Onion and Elastic Stack for network security monitoring Techniques for log analysis and aggregating high-value logs Static and dynamic analysis of malware with YARA rules, FLARE VM, and Cuckoo Sandbox Detecting and responding to lateral movement techniques, including pass-the-hash, pass-the-ticket, Kerberoasting, malicious use of PowerShell, and many more Effective threat hunting techniques Adversary emulation with Atomic Red Team Improving preventive and detective controls Review: Fantastic DFIR Resource! - This book is a bit of an anomaly. Ever since I purchased "Mastering Windows Network Forensics and Investigation" (1st and 2nd editions) years ago, I've been curious as to why the author hadn't published anything further. I was excited to see this book announced and even more so, after having read it, to learn that my anticipation was not in vain. This book is the most valuable book on DFIR that I've ever found. The coverage is comprehensive, thorough, and covers many of the latest "cutting edge" DFIR techniques. With that said, this book is an anomaly in that it is so very valuable but seems to be, as of yet, still widely unknown to the cybersecurity community. I would encourage anyone in (or even interested in) the cybersecurity field to purchase this book and study it thoroughly. Personally, this book is easily near the top of my list of favorites and I will be amazed if it doesn't hold it's title as the most valuable cybersecurity book that I've read this year. Review: Great Read for Incident Response - I’m currently enrolled in SANS504 and was looking for some material to supplement my course. I was a little hesitant to purchase this book with it being recently published and not having a ton of reviews. I’m so glad I decided to purchase it! This book is very thorough and you will be a better security professional after reading this. The content of this book is outstanding and complements that SANS material quite nicely. Highly recommended!
| Best Sellers Rank | #307,297 in Books ( See Top 100 in Books ) #68 in Computer Networking (Books) #202 in Computer Network Security |
| Customer Reviews | 4.7 out of 5 stars 223 Reviews |
A**R
Fantastic DFIR Resource!
This book is a bit of an anomaly. Ever since I purchased "Mastering Windows Network Forensics and Investigation" (1st and 2nd editions) years ago, I've been curious as to why the author hadn't published anything further. I was excited to see this book announced and even more so, after having read it, to learn that my anticipation was not in vain. This book is the most valuable book on DFIR that I've ever found. The coverage is comprehensive, thorough, and covers many of the latest "cutting edge" DFIR techniques. With that said, this book is an anomaly in that it is so very valuable but seems to be, as of yet, still widely unknown to the cybersecurity community. I would encourage anyone in (or even interested in) the cybersecurity field to purchase this book and study it thoroughly. Personally, this book is easily near the top of my list of favorites and I will be amazed if it doesn't hold it's title as the most valuable cybersecurity book that I've read this year.
S**H
Great Read for Incident Response
I’m currently enrolled in SANS504 and was looking for some material to supplement my course. I was a little hesitant to purchase this book with it being recently published and not having a ton of reviews. I’m so glad I decided to purchase it! This book is very thorough and you will be a better security professional after reading this. The content of this book is outstanding and complements that SANS material quite nicely. Highly recommended!
P**Y
My go to refferance guide for the IHT.
A must have, time tested and useful in difficult situations. Of course, if you get where I’m going with that comment. Simplified, even the Exec’s understand it and that’s a huge win when budget season comes.
A**R
Bit damaged upon arrival
So I haven't had the chance to read it yet (heard really good things about this book!) but the book came somewhat damaged on the front cover. there are some scratches around the cover of the book and appears a bit bent between a bit the "E" in Incident and "N" in response. Still OK that it came in one piece haha.
J**E
Can't say enough good things about this book.
I have being performing assessments at a Federal Agency for about 4 years, time for a change. So I order Applied Incident Response and have read about 5 chapters and have been very happy with the book The author is clearly knowledgeable, an "expert" in the subject matter, but many expert write poorly. Steve Anson writes with great clarity which makes reading/learning a pleasure. Additionally, the book is filled with detailed links to tools, articles, books ... to supplement the book. The examples of tools, e.g., Security Onion, the corresponding screenshots and text are perfectly in sync and easy to follow. Great technical content and the book is a pleasure to read.
K**G
Comprehensive, Updated Book on DFIR
Overall excellent content on DFIR. A great updated supplement to the Incident Response & Computer Forensics series. I particularly enjoyed the Lateral Movement section as it really solidified my understanding in how to monitor, hunt and investigate common techniques of pivoting within a network.
M**S
Lots of technical details
This book has a lots of technical details - someone might like it, some not.
A**R
Bought Paperback New...yet came with binding damages.
The inside of the book is brand new but I'm not exactly happy with the quality of the cover. I purchased a book brand new and with Amazon's new packaging, I don't think shipping books out in this helps to my review. I'm disappointed that I paid for a new book yet it came with binding damages...
A**R
Terrible print quality
Haven’t read as the print quality is terrible. Pages are stuck together and it’s impossible to read it without destroying the book.
V**I
Good material
This book covers a lot of topics and touches the most important parts. The topics are presented clearly and in a concise manner and it's a great addition to people studying forensics / incident response.
Trustpilot
1 month ago
2 days ago