|
|
Books > Computing & IT > Social & legal aspects of computing > Privacy & data protection
Secure your Amazon Web Services (AWS) infrastructure with
permission policies, key management, and network security, along
with following cloud security best practices Key Features Explore
useful recipes for implementing robust cloud security solutions on
AWS Monitor your AWS infrastructure and workloads using CloudWatch,
CloudTrail, config, GuardDuty, and Macie Prepare for the AWS
Certified Security-Specialty exam by exploring various security
models and compliance offerings Book DescriptionAs a security
consultant, securing your infrastructure by implementing policies
and following best practices is critical. This cookbook discusses
practical solutions to the most common problems related to
safeguarding infrastructure, covering services and features within
AWS that can help you implement security models such as the CIA
triad (confidentiality, integrity, and availability), and the AAA
triad (authentication, authorization, and availability), along with
non-repudiation. The book begins with IAM and S3 policies and later
gets you up to speed with data security, application security,
monitoring, and compliance. This includes everything from using
firewalls and load balancers to secure endpoints, to leveraging
Cognito for managing users and authentication. Over the course of
this book, you'll learn to use AWS security services such as Config
for monitoring, as well as maintain compliance with GuardDuty,
Macie, and Inspector. Finally, the book covers cloud security best
practices and demonstrates how you can integrate additional
security services such as Glacier Vault Lock and Security Hub to
further strengthen your infrastructure. By the end of this book,
you'll be well versed in the techniques required for securing AWS
deployments, along with having the knowledge to prepare for the AWS
Certified Security - Specialty certification. What you will learn
Create and manage users, groups, roles, and policies across
accounts Use AWS Managed Services for logging, monitoring, and
auditing Check compliance with AWS Managed Services that use
machine learning Provide security and availability for EC2
instances and applications Secure data using symmetric and
asymmetric encryption Manage user pools and identity pools with
federated login Who this book is forIf you are an IT security
professional, cloud security architect, or a cloud application
developer working on security-related roles and are interested in
using AWS infrastructure for secure application deployments, then
this Amazon Web Services book is for you. You will also find this
book useful if you're looking to achieve AWS certification. Prior
knowledge of AWS and cloud computing is required to get the most
out of this book.
Build your organization's cyber defense system by effectively
implementing digital forensics and incident management techniques
Key Features Create a solid incident response framework and manage
cyber incidents effectively Perform malware analysis for effective
incident response Explore real-life scenarios that effectively use
threat intelligence and modeling techniques Book DescriptionAn
understanding of how digital forensics integrates with the overall
response to cybersecurity incidents is key to securing your
organization's infrastructure from attacks. This updated second
edition will help you perform cutting-edge digital forensic
activities and incident response. After focusing on the
fundamentals of incident response that are critical to any
information security team, you'll move on to exploring the incident
response framework. From understanding its importance to creating a
swift and effective response to security incidents, the book will
guide you with the help of useful examples. You'll later get up to
speed with digital forensic techniques, from acquiring evidence and
examining volatile memory through to hard drive examination and
network-based evidence. As you progress, you'll discover the role
that threat intelligence plays in the incident response process.
You'll also learn how to prepare an incident response report that
documents the findings of your analysis. Finally, in addition to
various incident response activities, the book will address malware
analysis, and demonstrate how you can proactively use your digital
forensic skills in threat hunting. By the end of this book, you'll
have learned how to efficiently investigate and report unwanted
security breaches and incidents in your organization. What you will
learn Create and deploy an incident response capability within your
own organization Perform proper evidence acquisition and handling
Analyze the evidence collected and determine the root cause of a
security incident Become well-versed with memory and log analysis
Integrate digital forensic techniques and procedures into the
overall incident response process Understand the different
techniques for threat hunting Write effective incident reports that
document the key findings of your analysis Who this book is forThis
book is for cybersecurity and information security professionals
who want to implement digital forensics and incident response in
their organization. You will also find the book helpful if you are
new to the concept of digital forensics and are looking to get
started with the fundamentals. A basic understanding of operating
systems and some knowledge of networking fundamentals are required
to get started with this book.
Evade antiviruses and bypass firewalls with the most widely used
penetration testing frameworks Key Features Gain insights into the
latest antivirus evasion techniques Set up a complete pentesting
environment using Metasploit and virtual machines Discover a
variety of tools and techniques that can be used with Kali Linux
Book DescriptionPenetration testing or ethical hacking is a legal
and foolproof way to identify vulnerabilities in your system. With
thorough penetration testing, you can secure your system against
the majority of threats. This Learning Path starts with an in-depth
explanation of what hacking and penetration testing is. You'll gain
a deep understanding of classical SQL and command injection flaws,
and discover ways to exploit these flaws to secure your system.
You'll also learn how to create and customize payloads to evade
antivirus software and bypass an organization's defenses. Whether
it's exploiting server vulnerabilities and attacking client
systems, or compromising mobile phones and installing backdoors,
this Learning Path will guide you through all this and more to
improve your defense against online attacks. By the end of this
Learning Path, you'll have the knowledge and skills you need to
invade a system and identify all its vulnerabilities. This Learning
Path includes content from the following Packt products: Web
Penetration Testing with Kali Linux - Third Edition by Juned Ahmed
Ansari and Gilberto Najera-Gutierrez Metasploit Penetration Testing
Cookbook - Third Edition by Abhinav Singh , Monika Agarwal, et al
What you will learn Build and analyze Metasploit modules in Ruby
Integrate Metasploit with other penetration testing tools Use
server-side attacks to detect vulnerabilities in web servers and
their applications Explore automated attacks such as fuzzing web
applications Identify the difference between hacking a web
application and network hacking Deploy Metasploit with the
Penetration Testing Execution Standard (PTES) Use MSFvenom to
generate payloads and backdoor files, and create shellcode Who this
book is forThis Learning Path is designed for security
professionals, web programmers, and pentesters who want to learn
vulnerability exploitation and make the most of the Metasploit
framework. Some understanding of penetration testing and Metasploit
is required, but basic system administration skills and the ability
to read code are a must.
|
|