Introduction to Kali Purple: Harness the synergy of offensive and defensive cybersecurity strategies of Kali Linux

Оглавление⌄
Preface xiiiPart 1: Introduction, History, and Installation1An Introduction to Cybersecurity....3How we got here....4Stuxnet....6The Target cyberattack of 2013....8Offensive security....11Nmap....12Metasploit Framework....13Burp Suite....14Wireshark....17Aircrack -ng....18John the Ripper....20Hydra....21SQLmap....22Maltego....23Social Engineering Toolkit (SET)....25Defensive security....27Confidentiality....28Integrity....28Availability....28Summary....37Questions....38Further reading....402Kali Linux and the ELK Stack....41The evolution of Kali Linux....42Elasticsearch, Logstash, andKibana (ELK stack)....43Elasticsearch....43Logstash....46Kibana....49Agents and monitoring....51Beats....51X-Pack....55Summary....56Questions....56Further reading....573Installing the Kali Purple Linux Environment....59Technical requirements....60Acquiring the KaliPurple distribution....60Linux backup....61Windows backup....61macOS backup....61Linux....65Mac....65Windows....66The installation of a VM....67Windows users....71macOS users....72Linux users....72Linux VirtualBox installation....73macOS VirtualBox installation....74Windows VirtualBox installation....74Setting the environment PATH variable inWindows....79Setting the environment PATH variable inmacOS or Linux....79The installation of Kali Purple....83The installation of the Java SDK....96Summary....98Questions....98Further reading....1004Configuring the ELK Stack....101Technical requirements....102Elasticsearch....102Kibana....107Logstash....112Summary....117Questions....118Further reading....1195Sending Data to the ELK Stack....121Technical requirements....122Understanding the data flow....122Filebeat....130Linux and macOS download and installation....133Types of Beats....143Elastic Agent....143Logstash and filters....148Summary....151Questions....151Further reading....152Part 2: Data Analysis, Triage, andIncident Response6Traffic and Log Analysis....157Technical requirements....158Understanding packets....158Malcolm....159Arkime....167CyberChef and obfuscation....176Summary....181Questions....182Further reading....1837Intrusion Detection and Prevention Systems....185Technical requirements....186IDS....186Traffic monitoring....187Anomaly detection....187Signature-based detection....188Real-time alerts....189Log and event analysis....190Network and host-based detection....190Response and mitigation....190Regulatory compliance....191Integration with security infrastructure....191IPS....191Real-time threat prevention....192Automated response....193Policy enforcement....193Inline protection....193Application layer protection....193Performance optimization....194Suricata....194Zeek....200Summary....206Questions....206Further reading....2078Security Incident and Response....209Technical requirements....210Incident response....210Docker....212Cortex....216TheHive....224Challenge!....234Summary....235Questions....236Further reading....237Part 3: Digital Forensics, Offensive Security,and NIST CSF9Digital Forensics....241Technical requirements....242Digital forensics andmalware analysis....242Portable Executable Identifier (PEiD)....243PEScan....244IDA Pro....245Volatility3....248ApateDNS....251SET....255BeEF....258Maltego....262Summary....266Further reading....26710Integrating the Red Team and External Tools....269Technical requirements....270OWASP ZAP....270Mozilla Firefox....274Google Chrome....276Wireshark....280Metasploit....283Scanners....285Nmap....285SQLmap....287Nikto....288Nessus....289Greenbone Vulnerability Management andOpenVAS....290Password cracking....291Hydra....292Medusa....294John the Ripper....295Burp Suite integration....296Summary....298Questions....299Further reading....30011Autopilot, Python, and NIST Control....301Technical requirements....302Autopilot....302Python....314NIST Control....319Identify....321Protect....321Detect....322Respond....322Recover....323Govern....324Summary....324Questions....325Further reading....326Appendix: Answer Key....327Index....343Other Books You May Enjoy....354
Описание
Коротко и по делу о том, что важно знать про tools.
Defensive Security with Kali Purple combines red team tools from the Kali Linux OS and blue team tools commonly found within a security operations center (SOC) for an all-in-one approach to cybersecurity. This book takes you from an overview of today's cybersecurity services and their evolution to building a solid understanding of how Kali Purple can enhance training and support proof-of-concept scenarios for your technicians and analysts.
This is demonstrated through the installation and configuration of supporting tools such as virtual machines, the Java SDK, Elastic, and related software. After getting to grips with the basics, you’ll learn how to develop a cyber defense system for Small Office Home Office (SOHO ) services. You’ll then explore Kali Purple’s compatibility with the Malcolm suite of tools, including Arkime, CyberChef, Suricata, and Zeek. Finally, you’ll delve into digital forensics and explore tools for social engineering and exploit development. As you progress, the book introduces advanced features, such as security incident response with StrangeBee’s Cortex and TheHive and threat and intelligence feeds.
By the end of this book, you’ll have a clear and practical understanding of how this powerful suite of tools can be implemented in real-world scenarios.
What you will learnSet up and configure a fully functional miniature security operations center
Explore and implement the government-created Malcolm suite of tools
Understand traffic and log analysis using Arkime and CyberChef
Compare and contrast intrusion detection and prevention systems
Explore incident response methods through Cortex, TheHive, and threat intelligence feed integration
Leverage purple team techniques for social engineering and exploit development
Cybersecurity analysts, SOC analysts, and junior penetration testers seeking to better understand their targets will find this content particularly useful. Who this book is forThis book is for entry-level cybersecurity professionals eager to explore a functional defensive environment. If you’re looking for a proper training mechanism for proof-of-concept scenarios, this book has you covered. While not a prerequisite, a solid foundation of offensive and defensive cybersecurity terms, along with basic experience using any Linux operating system, will make following along easier.
Файл доступен для загрузки ниже.
Поделиться
Частые вопросы
Можно ли скачать «Introduction to Kali Purple: Harness the synergy of offensive and defensive cybersecurity strategies of Kali Linux» бесплатно?
Да, «Introduction to Kali Purple: Harness the synergy of offensive and defensive cybersecurity strategies of Kali Linux» доступна для бесплатного скачивания на нашем сайте в формате PDF. Ссылка на файл находится на этой странице.
В каком формате и какого размера файл?
Книга предоставляется в формате PDF, размер файла 7,1 МБ.
Кто автор и когда вышла книга?
автор — Lane Karl, издательство Packt Publishing Limited, год выпуска 2024, 377 страниц.
О чём книга «Introduction to Kali Purple: Harness the synergy of offensive and defensive cybersecurity strategies of Kali Linux»?
Defensive Security with Kali Purple combines red team tools from the Kali Linux OS and blue team tools commonly found within a security operations center (SOC) for an all-in-one approach to cybersecurity.