

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Tunisia.
*** NOTICE *** Version 3.0 is now SCHEDULED to release Dec 15, 2025. Version 3 has 164 new pages of material to guide you on your cyber incident response journey, 180% larger t han the 2016 publication. ** *** YOU A RE LOOKNG AT V.2.2, WHICH WAS PRICED AT 99.00 TO DISCOURAGE ITS PURCHASE!!! *** BTHb:INRE - Version 2.2 now available.Voted #3 of the 100 Best Cyber Security Books of All Time by Vinod Khosla, Tim O'Reilly andMarcus Spoons Stevens on BookAuthority.com as of 06/09/2018!The Blue Team Handbook is a "zero fluff" reference guide for cyber security incident responders, security engineers, and InfoSec pros alike. The BTHb includes essential information in a condensed handbook format. Main topics include the incident response process, how attackers work, common tools for incident response, a methodology for network analysis, common indicators of compromise, Windows and Linux analysis processes, tcpdump usage examples, Snort IDS usage, packet headers, and numerous other quick reference topics. The book is designed specifically to share "real life experience", so it is peppered with practical techniques from the authors' extensive career in handling incidents. Whether you are writing up your cases notes, analyzing potentially suspicious traffic, or called in to look over a misbehaving server – this book should help you handle the case and teach you some new techniques along the way. Version 2.2 updates: - *** A new chapter on Indicators of Compromise added. - Table format slightly revised throughout book to improve readability. - Dozens of paragraphs updated and expanded for readability and completeness. - 15 pages of new content since version 2.0. Review: Great reference book - Perfect to keep in your desk draw and whip out when needed, hugely helpful book to have during an incident and to keep around for reference. I would also recommend the following book Blue Team Field Manual (BTFM) (RTFM) Review: If you don't have it get it - Enjoyable read, good humoured and very informative, a must have for any one in incident response. A good read with great planning and execution tips for the rest of us No point getting RTFM without this book
| Best Sellers Rank | 383,639 in Books ( See Top 100 in Books ) 1,158 in Web Administration 3,132 in Computer Science (Books) |
| Customer Reviews | 4.6 out of 5 stars 453 Reviews |
T**N
Great reference book
Perfect to keep in your desk draw and whip out when needed, hugely helpful book to have during an incident and to keep around for reference. I would also recommend the following book Blue Team Field Manual (BTFM) (RTFM)
T**N
If you don't have it get it
Enjoyable read, good humoured and very informative, a must have for any one in incident response. A good read with great planning and execution tips for the rest of us No point getting RTFM without this book
A**N
Four Stars
Very good for professionals working in incident response and information security in general.
T**R
Great book, perfect for anyone starting in the Blue ...
Great book, perfect for anyone starting in the Blue Team/CSIRT/SIEM and even for those already with some experience in the field. Short and concise, a must have in your desk.
K**N
A must read
Great book for the beginner, which most of us are. We know it all, this tells us to think again. Recommended for my year 1 undergraduate forensic computing students.
B**N
Excellent is thy content
What can I say - this book summarises the processes of Incidence Response in a clear, concise with no ambiguity. Packed with with commands and tool lists to aid you beginners and expert alike through the IR process. For the size and price of this book - It is surely a one of a kind companion.
D**E
Bloody Good Blue Booking Read..
If you dont know the difference between a Blue Team, a Red Team, a Tiger Team or a Gibson is, then you don't need this book.. However if you do know the difference then you need this to make your life; from either an offense or defence perspective, that little bit easier..
R**S
This book is better suited for managers than 'coal face' people
This book is better suited for managers than 'coal face' people. It talks about incident response at quite a high level and doesn't get into the weeds enough. When you compare this to the Red Team Field Manual you will notice they cannot be compared, which is quite sad. If you need a reference book to do your job, use the RTFM, or The Way of the Packet this is a book you give to your boss when s/he asks you to explain your job.
A**I
Good reading
Great book as a guide
A**R
As the name suggests, a condensed field guide
This book is quite good. Condensed commands and references to what needs to be looked at from an Incident Response perspective. I would highly recommend this to anyone willing to add to their knowledge. Please be aware, this book is not for learning Incident Response, but for bring a structure to how you handle these incidents/cases.
M**O
Ottimo libro sulla sicurezza informatica
Questo libro ha lo scopo di fornire un approccio rapido verso la difesa da eventuali attacchi informatici. Offre diversispunti per mettere insiemeuna procedura per definire/catalogare l'incidente fino ad offrire comandi e software per scoprire chi, come e quando è riuscito a creare una breccia nel sistema. Sono ancora ai primi capitoli, ma giá da lì ho scoperto alcune vulnerabilità di cui non ero a conoscenza. Con poche direttive aggiunte ad apache, ho un sistema più sicuro. Davvero, gli spunti e gli strumenti per analizzare la propria infrastruttura sono molti. Più lo leggo, più mi appassiono al versante "sicurezza". Consigliato a chi gestisce server e reti aziendali. Essendo un libriccino veloce, non si può dire di non avere tempo per leggerlo!
D**.
Reall the context shared in this guide is good, SANS guys always deliver quality.
Really great SOC uses-cases, very good to start guide for SOC engineers/managers. Great indepth coverage of basics and concepts critical for SOC/SIEM/D&R guys. Would really recommend this book to OT Cybersecurity Engineers or anyone from cys detection. As you can see from TOC, the micro topics, are covered, basics are always so critical in cybersecurity field. If you cannot apply fundamental into your program/projects, it's no use. So do get this guide. Handy and easy to digest! Highly recommended! :) cheers!
M**A
A real must have for all guys involved in cyber security
A real must have for all those involved in IR procedures design, a very useful summary for those who work in cyber security in general and want to have a
Trustpilot
2 months ago
1 week ago