Automating Security Detection Engineering: A hands-on guide to implementing Detection as Code Automating Security Detection Engineering: A hands-on guide to implementing Detection as Code Paperback Kindle
Best Sellers Rank: #968,630 in Books (See Top 100 in Books) #175 in Computer Viruses #605 in Computer Network Security #1,323 in Internet & Telecommunications
Customer Reviews: 4.2 out of 5 stars 17Reviews
Product Information
From the Publisher
From the Preface:
Detection engineering as a practice intersects the best of security operational analytics, engineering, and research. What's often left out is the automation life cycle of how the practice works with a globally distributed team at scale. There are many times when engineers who perform manual tasks, or administrative-burdensome items, can be greatly expedited by automation using DevSecOps principles. Automation is paramount to scaling the team and letting engineers focus on what they do best. The most effective automation comes in the form of a Detection-as-Code (DAC) program that incorporates three key principles:
Research and engineering expertise
Technology stacks that support integrations
A "shift-left" mindset for work streams
This book aims to extend the core skill and focus from only creating use cases to mastering the life cycle of the use cases through automation. This book will cover the best practices and advance your skills to implement an effective DAC program.
I'll guide you through strategic planning, hands-on technical build-outs, and optimizations with AI augmentation, and monitoring the program, drawing upon my direct experience as a detection engineer contributor and a director-level leader of people for multiple Fortune 500 enterprises. I also sought the input of respected industry leaders on their thoughts on an effective DAC program.
An industry-wide survey by the SANS Institute in November 2023 suggested the best practices of a detection engineering team, which include automating development, deployment, and testing use cases. All these best practices lead back and align to a well-implemented DAC program. As an industry trend, we can expect the demands of security programs to increase and, by extension, our efficiency in detection engineering. Enterprises that carve resources for a detection engineering team will need to deploy DAC as part of their program strategy to keep the team efficient and effective.
Who this book is for:
Detection engineers, SOC engineers, or any cybersecurity professional who wants to gain practical skills and best practices to automate any part of the use case detection life cycle from the various labs and concepts in this book.
The three main personas who are the target audience of this content are as follows:
Detection engineers: Technical SMEs that want to expedite their use case life cycle through automation while creating more consistency at scale, using a wide range of technologies and code development.
SOC engineers: Technical SMEs who want to gain a better understanding of detection engineering needs and workflows. This book informs these individuals what infrastructure and patterns to use and how to support the detection engineering team with appropriate tooling by maturity.
Technical program managers: Leaders who want to gain a better understanding of how to optimize detection engineering strategically and how to measure program success.