So far, this book has focused on the offensive side of cyber security. We have primarily been looking at using Python in the penetration testing domain. In this chapter, we will try to understand how Python can be used on the defensive side of cybersecurity. When we talk of defensive cyber security, what comes to mind is monitoring. Security operations center is a term commonly used for the monitoring team, which is responsible for the continuous monitoring of an organization's security landscape. This team makes use of a tool called Security Information and Event Management (SIEM), which acts as an aggregator to collect logs from various applications and devices that need to be monitored. On top of aggregation, the SIEM has a rule engine in which various rules are configured for anomaly detection. The rules vary from organization to organization...
United States
United Kingdom
India
Germany
France
Canada
Russia
Spain
Brazil
Australia
Argentina
Austria
Belgium
Bulgaria
Chile
Colombia
Cyprus
Czechia
Denmark
Ecuador
Egypt
Estonia
Finland
Greece
Hungary
Indonesia
Ireland
Italy
Japan
Latvia
Lithuania
Luxembourg
Malaysia
Malta
Mexico
Netherlands
New Zealand
Norway
Philippines
Poland
Portugal
Romania
Singapore
Slovakia
Slovenia
South Africa
South Korea
Sweden
Switzerland
Taiwan
Thailand
Turkey
Ukraine