Windows Security Monitoring: Scenarios and Patterns

Andrei Miroshnikov

  • 出版商: Wiley
  • 出版日期: 2018-04-17
  • 定價: $1,690
  • 售價: 9.5$1,606
  • 語言: 英文
  • 頁數: 648
  • 裝訂: Paperback
  • ISBN: 1119390648
  • ISBN-13: 9781119390640
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Go deep into Windows security tools to implement more robust protocols and processes

Windows Security Monitoring goes beyond Windows admin and security certification guides to provide in-depth information for security professionals. Written by a Microsoft security program manager, DEFCON organizer and CISSP, this book digs deep into the underused tools that help you keep Windows systems secure. Expert guidance brings you up to speed on Windows auditing, logging, and event systems to help you exploit the full capabilities of these powerful native tools, while scenario-based instruction provides clear illustration of how these events unfold in the real world. From security monitoring and event detection to incident response procedures and best practices, this book provides detailed information on all of the security tools your Windows system has to offer.

Windows includes many native tools that can help IT professionals and security experts spot and remedy suspicious activities on servers, networks, and end-user computers. If you're like many Windows pros, you're probably not taking full advantage of these features. This book takes you deep into Windows' underutilized built-in security tools to help you beef up your monitoring, detection, and response processes.

  • Detect anomalous events and implement centralized alerting infrastructure
  • Dig into the native Windows tools that enable robust security measures
  • Understand the details of Powershell, Applocker, LogParser, and other tools
  • Adopt effective incident response processes for various common scenarios

Fully applicable to a range of Windows versions—back to Windows Vista and Windows Server 2008—this book is designed for real-world implementation. As the threats to your data grow more numerous by the day, it becomes ever more critical to use every security tool at your disposal. Windows Security Monitoring offers complete, expert guidance toward robust security with specialist-level use of powerful Windows tools.

商品描述(中文翻譯)

深入瞭解Windows安全工具,實施更強大的協議和流程

《Windows安全監控》超越了Windows管理和安全認證指南,為安全專業人員提供深入的信息。這本書由一位微軟安全計劃經理、DEFCON組織者和CISSP撰寫,深入探討了幫助您保持Windows系統安全的未被充分利用的工具。專家指導使您能夠熟悉Windows審計、日誌和事件系統,以幫助您充分利用這些強大的本地工具的功能,而基於情景的指導則清晰地說明了這些事件在現實世界中如何發展。從安全監控和事件檢測到事件響應程序和最佳實踐,本書提供了有關Windows系統提供的所有安全工具的詳細信息。

Windows包含許多本地工具,可以幫助IT專業人員和安全專家發現並解決伺服器、網絡和最終用戶電腦上的可疑活動。如果您和許多Windows專業人員一樣,可能沒有充分利用這些功能。本書將深入介紹Windows中未充分利用的內建安全工具,以幫助您加強監控、檢測和響應流程。

- 檢測異常事件並實施集中警報基礎設施
- 深入瞭解啟用強大安全措施的本地Windows工具
- 瞭解Powershell、Applocker、LogParser和其他工具的細節
- 適應各種常見情景的有效事件響應流程

本書完全適用於各種Windows版本,包括Windows Vista和Windows Server 2008,並且設計用於實際實施。隨著對您的數據的威脅日益增多,使用您可以使用的每個安全工具變得更加重要。《Windows安全監控》提供了專家級指導,以運用強大的Windows工具實現強大的安全性。