So far, this book has focused on the offensive side of cyber security. We have primarily been looking at using Python in the penetration testing domain. In this chapter, we will try to understand how Python can be used on the defensive side of cybersecurity. When we talk of defensive cyber security, what comes to mind is monitoring. Security operations center is a term commonly used for the monitoring team, which is responsible for the continuous monitoring of an organization's security landscape. This team makes use of a tool called Security Information and Event Management (SIEM), which acts as an aggregator to collect logs from various applications and devices that need to be monitored. On top of aggregation, the SIEM has a rule engine in which various rules are configured for anomaly detection. The rules vary from organization to organization...
United States
Great Britain
India
Germany
France
Canada
Russia
Spain
Brazil
Australia
Singapore
Hungary
Ukraine
Luxembourg
Estonia
Lithuania
South Korea
Turkey
Switzerland
Colombia
Taiwan
Chile
Norway
Ecuador
Indonesia
New Zealand
Cyprus
Denmark
Finland
Poland
Malta
Czechia
Austria
Sweden
Italy
Egypt
Belgium
Portugal
Slovenia
Ireland
Romania
Greece
Argentina
Netherlands
Bulgaria
Latvia
South Africa
Malaysia
Japan
Slovakia
Philippines
Mexico
Thailand