The Practice of Network Security Monitoring
by Richard Bejtlich · Richard Bejtlich
Bejtlich walks through deploying network security monitoring with open-source tools like Security Onion, Argus and Bro. Readers finish able to collect session, full-packet and alert data, then work real intrusions through detection and response.
This link may earn us a small commission at no extra cost to you. Affiliate disclosure
More resources on Incident Response
r/incidentresponse
A subreddit where security practitioners discuss live incident handling: triage decisions, forensic tooling, containment tradeoffs, career paths, and postmortems. Useful for seeing how working responders reason about real cases rather than how textbooks describe the process.
FOR508: Advanced Incident Response
Master advanced incident response and threat hunting techniques with expert SANS instructors in FOR508. Elevate your skills today!
SANS Reading Room - DFIR Papers
SANS's archive of student-written whitepapers on forensics, incident handling, and security operations, plus its reference posters. Browsing it gives free practitioner-level writeups of tools and techniques, though quality varies since papers are certification coursework.
MITRE ATT&CK
MITRE's public knowledge base of adversary tactics, techniques and procedures drawn from real-world intrusions, organised into enterprise, mobile and ICS matrices with linked threat groups, software, mitigations and detections. Defenders use it to describe attacker behaviour consistently and map detection coverage and gaps.
Incident Response Path
Learn incident response from the TryHackMe Team! This course guides you through identifying, analyzing, and containing security incidents.
Defensive Security Podcast
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.