Zum Hauptinhalt springen Zur Suche springen Zur Hauptnavigation springen
Beschreibung

A strong cybersecurity program needs to stay informed. With this all-in-one guide, master cyber threat intelligence (CTI) techniques and understand its practical applications. Walk through the intelligence lifecycle, and then get up to speed on the latest tools and technologies for intelligence gathering, adversary profiling, network and host-based forensics, threat hunting, and more. Follow practical examples that showcase key CTI strategies in modern security operations.

Highlights include:

1)Cyber intelligence lifecycle

2)Open-source intelligence (OSINT)

3)Human intelligence (HUMINT)

4)Signals intelligence (SIGINT)

5)Intelligence gathering

6)Adversary profiling

7)Threat intelligence feed integrity

8)Network forensics

9)Host-based forensics

10)Incident response

11)Threat hunting

12)Automation

A strong cybersecurity program needs to stay informed. With this all-in-one guide, master cyber threat intelligence (CTI) techniques and understand its practical applications. Walk through the intelligence lifecycle, and then get up to speed on the latest tools and technologies for intelligence gathering, adversary profiling, network and host-based forensics, threat hunting, and more. Follow practical examples that showcase key CTI strategies in modern security operations.

Highlights include:

1)Cyber intelligence lifecycle

2)Open-source intelligence (OSINT)

3)Human intelligence (HUMINT)

4)Signals intelligence (SIGINT)

5)Intelligence gathering

6)Adversary profiling

7)Threat intelligence feed integrity

8)Network forensics

9)Host-based forensics

10)Incident response

11)Threat hunting

12)Automation

Über den Autor
Haydar Yener Arc is a senior systems and cybersecurity specialist with more than 23 years of experience in IT infrastructure, system administration, digital forensics, and open-source intelligence (OSINT). Throughout his career, he has conducted extensive work in critical areas such as the design, operation, and security of enterprise IT infrastructures; digital evidence analysis; and the establishment and development of corporate cybersecurity processes.Haydar holds one bachelor's degree and three master's degrees, combining his academic background with extensive field experience to develop projects at both technical and strategic levels. He is the author of six books published in Turkey covering Windows Server administration, enterprise IT security, and digital evidence management. These works serve as important reference resources for system administrators, cybersecurity professionals, and digital forensics specialists, and are widely used within the [...] many years, Haydar served as a Microsoft Certified Trainer (MCT), during which he delivered advanced training to numerous IT professionals in system administration, infrastructure security, and enterprise security [...] has also collaborated with universities and academic institutions, providing training, consultancy, and academic contributions in areas such as forensic readiness, cybersecurity policy development, and enterprise system hardening.Haydar continues his work by combining technical expertise with academic knowledge and field experience, focusing on enterprise security architectures, digital forensics, and advanced system security.
Inhaltsverzeichnis

... Preface ... 15

... Who This Book Is For ... 15

... How This Book Is Organized ... 16

... Acknowledgments ... 18

... Conclusion ... 19

1 ... Foundations of Cyber Threat Intelligence ... 21

1.1 ... What Is Cyber Threat Intelligence? ... 22

1.2 ... The Strategic Context and Importance of CTI ... 26

1.3 ... The Evolution of Threat Intelligence ... 34

1.4 ... Types of Intelligence in Cybersecurity ... 39

1.5 ... Core Concepts and Conceptual Models ... 41

1.6 ... Summary ... 50

2 ... Intelligence Lifecycle in Practice ... 53

2.1 ... Planning and Direction Phase ... 54

2.2 ... Collection: Active and Passive Techniques ... 73

2.3 ... Processing and Initial Analysis ... 79

2.4 ... Interpretation and Dissemination ... 85

2.5 ... Feedback and the Sustainability of the Lifecycle ... 93

2.6 ... Summary ... 97

3 ... Intelligence Sources ... 99

3.1 ... Understanding Intelligence Source Classifications ... 100

3.2 ... Open-Source Intelligence ... 105

3.3 ... Human Intelligence ... 124

3.4 ... Signals Intelligence ... 139

3.5 ... Integrating and Correlating Multisource Intelligence ... 155

3.6 ... Summary ... 164

4 ... Applied OSINT: Tools, Methodologies, and Operational Discipline ... 167

4.1 ... Principles of Effective OSINT Collection ... 168

4.2 ... Passive OSINT Collection Strategies ... 185

4.3 ... Active OSINT Techniques ... 225

4.4 ... OSINT Data Structuring and Storage ... 245

4.5 ... Summary ... 259

5 ... Advanced Intelligence Collection from the Deep and Dark Web ... 261

5.1 ... The Invisible Architecture of the Dark Ecosystem ... 262

5.2 ... Accessing Hidden Services and Managing Anonymity ... 276

5.3 ... Summary ... 284

6 ... Threat Actor Profiling and Behavioral Mapping ... 287

6.1 ... Introduction to Threat Actor Profiling ... 288

6.2 ... Tactics, Techniques, and Procedures ... 291

6.3 ... Applying the MITRE ATT&CK Framework ... 298

6.4 ... Using the Diamond Model in Threat Profiling ... 304

6.5 ... Behavioral Indicators and Fingerprints ... 309

6.6 ... Summary ... 316

7 ... Integrity, Poisoning, and Enrichment in Threat Intelligence Feeds ... 317

7.1 ... The Anatomy of a Threat Intelligence Feed ... 318

7.2 ... Feed Poisoning and Manipulation Techniques ... 334

7.3 ... Detecting Low-Quality or Malicious Threat Intelligence Feeds ... 350

7.4 ... Data Enrichment Techniques ... 366

7.5 ... Summary ... 382

8 ... Network-Centric Forensic Intelligence ... 385

8.1 ... Introduction to Network-Centric Digital Forensics ... 386

8.2 ... Traffic Capture and Protocol Analysis ... 392

8.3 ... Flow-Level Analysis ... 416

8.4 ... Correlation of Logs and Network Metadata ... 433

8.5 ... Monitoring Attacker Infrastructure and Lateral Movement ... 443

8.6 ... Summary ... 453

9 ... Host-Based Forensic Analysis and Windows Telemetry ... 455

9.1 ... Role of Host-Based Forensics in CTI ... 456

9.2 ... Advanced Configuration of Event Logs and Audit Policy ... 464

9.3 ... Windows Registry Forensic Analysis ... 487

9.4 ... Memory Acquisition and Memory-Based Forensic Analysis ... 510

9.5 ... Summary ... 537

10 ... Integrating CTI into Incident Response ... 539

10.1 ... The Role of CTI in Incident Response ... 540

10.2 ... Detection and Validation with IOCs and IOAs ... 559

10.3 ... Contextualization of Threats and Impact Analysis ... 589

10.4 ... Summary ... 619

11 ... Intelligence-Driven Proactive Threat Hunting ... 621

11.1 ... What Is Threat Hunting? ... 622

11.2 ... Intelligence-Driven Hunting Methodologies ... 657

11.3 ... Summary ... 692

12 ... Automation and Threat Intelligence Platforms ... 695

12.1 ... Introduction to CTI Automation ... 696

12.2 ... Overview of Threat Intelligence Platforms ... 703

12.3 ... Using MISP for Community-Based Threat Sharing ... 711

12.4 ... Summary ... 734

A ... Bibliography ... 735

B ... The Author ... 739

... Index ... 741

Details
Erscheinungsjahr: 2026
Fachbereich: Datenkommunikation, Netze & Mailboxen
Genre: Importe, Informatik
Rubrik: Naturwissenschaften & Technik
Medium: Taschenbuch
Inhalt: 755 S.
ISBN-13: 9781493228133
ISBN-10: 1493228137
Sprache: Englisch
Einband: Kartoniert / Broschiert
Autor: Arici, Haydar Yener
Hersteller: Rheinwerk Verlag GmbH
Rheinwerk Publishing Inc.
Verantwortliche Person für die EU: Rheinwerk Verlag GmbH, Rheinwerkallee 4, D-53227 Bonn, service@rheinwerk-verlag.de
Von/Mit: Haydar Yener Arici
Erscheinungsdatum: 07.09.2026
Artikel-ID: 135998961