18 520 633 książek w 175 językach
Jednak się nie przyda? Nic nie szkodzi! Możesz zwrócić produkty nawet do 30 dni
Bon prezentowy to zawsze dobry pomysł. Obdarowany może za bon prezentowy wybrać cokolwiek z naszej oferty.
Nawet do 30 dni na zwrot
Every red team engagement produces a compromise. Almost none of them produce a program. Red Teaming in Practice is the book for the security leader and practitioner who need both: a rigorous, technically accurate walkthrough of how attack paths actually get mapped, emulated, and validated against the real MITRE ATT&CK framework, and the discipline to turn that work into evidence a board, a regulator, and a budget conversation will actually accept.
Grounded in a full fictional engagement, Meridian Trust Bank's "Operation Fenwick", and more than twenty real, publicly documented incidents, including Capital One, Microsoft's Storm-0558, Target, Equifax, SolarWinds, Colonial Pipeline, and others, this book covers the entire lifecycle: threat intelligence and adversary profiling, scoping and rules of engagement, attack-path mapping, adversary emulation against real ATT&CK tactics and techniques, purple teaming, detection engineering, and the reporting, metrics, and board-briefing discipline that keeps a program funded. Two full chapters are devoted to what most red-teaming books skip entirely: building the business case for security validation, and navigating the regulatory drivers, DORA, TIBER-EU, CBEST, now making this testing mandatory across financial services. No exploit code, no lab-only theater: real frameworks, real incidents, real structure.
The full red team engagement backbone: scoping and ROE, threat intelligence, emulation, purple team review, reporting, and remediation
A rigorous, accurate walkthrough of MITRE ATT&CK as a mapping language, real tactics and technique IDs, not fabricated ones
Identity and privilege attack-path patterns, grounded in real breach case studies
A full chapter on purple teaming and detection engineering, including how to validate that a fix actually works
A dedicated business-case chapter: budget justification, ROI framing, and a full worked board-briefing script
A dedicated regulatory chapter on DORA, TIBER-EU, and CBEST threat-led penetration testing requirements
Reusable templates and checklists, ROE, purple-team agenda, closure-report outline, board briefing, maturity self-assessment
Written at leadership-and-practitioner depth, process, governance, and communication, not another exploit-tooling tutorial
Every framework reference, ATT&CK, PTES, DORA, TIBER-EU, CBEST, NIST SP 800-115, is accurate and current, cross-checked against the real published sources
More than twenty real, well-documented incidents used as grounding evidence alongside a full fictional case study
The only book in the category built around the business case and regulatory mandate for security validation, not just the technique
Includes a full appendix of reusable templates and a framework/regulatory quick-reference
Written by a practitioner-author fluent in both the technical and the boardroom side of the conversation
CISOs and security managers who need to build or defend a red team program's budget
Red team operators and purple team analysts who want the governance context around their technical work
Security leaders navigating a new DORA, TIBER-EU, or CBEST compliance mandate
Practitioners studying for red team-adjacent certifications who want the program-level picture
Board members and executives who need a working vocabulary for a security validation conversation
Anyone standing up a first red team engagement and unsure how to make it a lasting program