learn siem xdr and threat hunting hands on with open source tools
Many learners struggle to translate theory into practical detection and response skills because enterprise tooling and realistic environments are hard to access. This book shows you how to build a repeatable home SOC lab that mirrors real operations so you can practice the skills employers seek.
Follow clear, task oriented labs that walk you from hardware and network design to deployed monitoring, detection engineering and incident response using open source software.
plan and build a hypervisor based lab with segmented networks and isolationdeploy and configure wazuh as your siem xdr style platform and enroll windows and linux agentsadd network visibility with suricata and zeek and integrate alerts into your analyticsimplement endpoint visibility using sysmon and auditd and tune file integrity monitoringwrite and test detection rules with yara and sigma and validate with atomic red teampractice threat hunting techniques and simulate real attacks with kali and offensive toolingbuild incident response workflows using thehive and automate playbooks with shufflemonitor cloud and container workloads and create dashboards and queries for operational usedocument and package lab projects into a portfolio to demonstrate job ready skillsthe manuscript includes step by step lab exercises configuration snippets dashboard templates sample rules and playbooks so you can reproduce each setup in your own environment
working code and configuration examples are included so you can run the same commands and templates used in the labs
grab your copy today