So far, this book has focused on the offensive side of cyber security. We have primarily been looking at using Python in the penetration testing domain. In this chapter, we will try to understand how Python can be used on the defensive side of cybersecurity. When we talk of defensive cyber security, what comes to mind is monitoring. Security operations center is a term commonly used for the monitoring team, which is responsible for the continuous monitoring of an organization's security landscape. This team makes use of a tool called Security Information and Event Management (SIEM), which acts as an aggregator to collect logs from various applications and devices that need to be monitored. On top of aggregation, the SIEM has a rule engine in which various rules are configured for anomaly detection. The rules vary from organization to organization...
Germany
Slovakia
Canada
Brazil
Singapore
Hungary
Philippines
Mexico
Thailand
Ukraine
Luxembourg
Estonia
Lithuania
Norway
Chile
United States
Great Britain
India
Spain
South Korea
Ecuador
Colombia
Taiwan
Switzerland
Indonesia
Cyprus
Denmark
Finland
Poland
Malta
Czechia
New Zealand
Austria
Turkey
France
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Malaysia
South Africa
Netherlands
Bulgaria
Latvia
Australia
Japan
Russia