Section 4: Improving Threat Detection in Incident Response
Incident response is a demanding and changing practice. When there is a security breach, seconds count, and you must make quick decisions. At this point, the knowledge, experience, and skills of the incident response professional are critical. In this last part, you will learn the concepts of developing detection engineering and threat hunting to quickly identify any compromise or malicious behavior in order to contain the attack.
This section comprises the following chapters:
- Chapter 12, Working with Analytics and Detection Engineering in Incident Response
- Chapter 13, Creating and Deploying Detection Rules
- Chapter 14, Hunting and Investigating Security Incidents