A network defender's guide to threat detection: Using Zeek, Elasticsearch, Logstash, Kibana, Tor, and more. - Paperback >
/ A network defender's guide to threat detection: Using Zeek, Elasticsearch, Logstash, Kibana, Tor, and more. - Paperback

A network defender's guide to threat detection: Using Zeek, Elasticsearch, Logstash, Kibana, Tor, and more. - Paperback

Regular price$26.98
/
(Tax included. Shipping calculated at checkout.)
✔ Authenticity Guaranteed — Verified Designer Goods
✔ 100% Money-Back Guarantee on Eligible Items
✔ Prices Displayed in Your Local Currency
✔ Final Price = No Surprise Import Fees
✔ Complimentary Insured Worldwide Shipping on Qualifying Orders
✔ Select Collector & Specialty Pieces May Require Secured Delivery Handling
Our authentication process ensures every item meets strict luxury verification standards. Learn more
Complimentary worldwide shipping on qualifying orders

by Jeremy Martin (Editor), Richard Medlin (Author)

Have you ever found yourself questioning whether your network is in good hands? Did you do everything you could to defend against exploits on your network? Is your employer safe because you have one of the best Security Information Event Management (SIEM) setups you can use monitoring the network for you? Or, maybe you are new to Information Security and you want to learn how to employ a robust Intrusion Detection System (IDS) but you do not know where to start. If you have ever asked yourself any of these questions, or you just want to learn about ELK Stack and Zeek (Bro), you have come to the right place. A quick Google search will show you there isn't a lot of information for configuring Zeek (Bro), ElasticSearch, Logstash, Filebeat, and Kibana- it is rather complicated because the websites will describe how to install, but they don't really lead you to specifics on what else you need to do, or they are really outdated. That is where you must piece together the information yourself, and really research - lucky for you, I did the leg work for you and decided to write this book. Whether you have been in the Information Security industry for many years or you're just getting started this book has something for you. In my time studying over the years I've always found that a lot of books are interesting reads, but they add a lot of fluff. That was not my goal with this book; I wanted to provide you with a straight forward book without the fluff, that will show you exactly what you need - I cover the basics, and then explain the intricacies involved with configuring a SIEM that is reliable. I also provide a step-by-step process, while including any pertinent notes that you need to pay attention to, and lastly providing a breakdown of what is occurring at that time. Having background to each section and knowing what is happening is extremely important to learning and understanding what is happening on your network. Likewise, this book covers a brief overview of different programming languages, and their configuration nuances when applied to Zeek (Bro) and Elk Stack. I tried my best to approach this as if you did not know anything, so that anyone can read this and understand what is happening throughout the installation and configuration process. Let us get to the basics of what will be covered in this book so that you have a good idea of what you will learn. The first section of this book covers the Zeek(Bro) IDS installation and configuration. Furthermore, you will learn about the origin of Zeek (Bro), and the many features that Zeek (Bro) has to offer. This section will walk you through the entire installation process, while providing explanations for the configuration changes that we make on the system. There are a lot of dependencies needed to install Zeek (bro), and I will walk you through that entire process. We will also go over installing PF_ring - a tool for increased capture speeds and network capture optimization. The tool is very useful when capturing data on large networks, and from multiple nodes. In the next section we will go over installing Tor, and Privoxy for network anonymity. You're probably asking yourself why you would want to do that when setting up a SIEM or IDS. The simple answer is that in order to know what's traversing the network, you need to understand what it is doing and how to use it yourself. Sometimes the best defense comes from knowing what the offense is using. Once we install Tor, you can generate some Tor traffic on your network, and watch as one of the custom Zeek (Bro) signatures - I will teach you about in this book - detects this traffic so you can see what it looks like once a notice is generated. It's also good to know how to remain anonymous on the network if you're ever doing any type of forensic investigations too, so learning this is always a plus. ...

Number of Pages: 202
Dimensions: 0.43 x 11 x 8.5 IN
Publication Date: May 28, 2020
  • In stock, ready to ship
  • Backordered, shipping soon
Shop with Confidence
  • ✔ Authenticity Guaranteed — Verified Designer Goods
  • ✔ Sourced from Authorized European/U.S. Luxury Distributors
  • ✔ Secure Checkout — SSL Encrypted Payments
  • ✔ Fast Global Delivery — 3–11 Business Days
  • ✔ Easy Returns on Eligible Items
  • ✔ 100% Money-Back Guarantee — Full Refund if Not Satisfied
Verified Trust Rating: 91/100
Amazon American Express Apple Pay Bancontact Diners Club Discover Google Pay Mastercard PayPal Shop Pay USDC Visa SSL Secure
Amazon Pay Logo Fast checkout with Amazon Pay. Use your Amazon account to skip entering shipping or card info.
Trusted by discerning buyers worldwide — secure, verified luxury sourcing

AUTHENTICITY GUARANTEED

Reserved for you — complete your purchase to secure this piece.

Authorized Designer Inventory Secure & Encrypted Checkout Tracked & Insured Delivery

OFFICIALLY AUTHORIZED RESELLER

Discover Officially Authorized Authentic Items at STORE7994.com - Certificates Available on Request!

Independently verified for store quality and customer safety.
Trust score: 91/100

All designer items offered by STORE 7994 are sourced from trusted luxury distributors and verified through independent authentication services.

Learn how STORE 7994 authenticates luxury items

Guaranteed Authentic — Includes Brand Documentation & Third-Party Verification Options.

Shipping information

  • Free Shipping* on all orders over $300 USD to most countries* Estimated delivery: 2-5 business days Mon-Sat to U.S., CA, EU etc.
  • Tracking available: DHL Express
  • Store 7994 Shipping policy
  • Global delivery in 3–9 business days (location dependent).
  • Free Worldwide Shipping $300+. International duties & VAT are calculated by destination country and may be collected upon delivery. UK orders are subject to 20% import VAT upon delivery.

Our innovation isn’t just in the brands we carry — it’s in the way we connect them. From our automation engine that keeps collections globally updated to our commitment to authenticity-first presentation, STORE 7994 exists where timeless design meets modern precision.

Every product we offer is:
Elevated · Intentional · Exclusive · Authentic

STORE 7994 is an authorized reseller of luxury fashion houses. Certificates and proof of authenticity are available to brand owners and partners upon request.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.

Returns & Refunds

We want you to shop with confidence at STORE 7994. If your purchase does not meet expectations, eligible items may be returned under the conditions below.

Return Eligibility
Items must be unused, unworn, and in original condition with all tags, packaging, and accessories included. Items showing any signs of wear or damage will not be accepted.

Return Window
Return requests must be made within 14 days of delivery.

Return Shipping
Customers are responsible for return shipping costs unless the item is defective, damaged, or incorrect.

Luxury Items
Items valued over $1,000 may be subject to a 7% restocking fee upon approved return.

Non-Returnable Items
For hygiene and product integrity reasons, the following items are final sale once opened or used:

• Underwear
• Fragrances
• Any worn or used items

Made-to-Order Items
Custom-designed products, including STORE 7994 hoodies, are made exclusively for each customer and are final sale. These items are not eligible for return or exchange unless defective or incorrect.

If you receive a defective or incorrect item, please contact us and we will make it right.

International Shipping & Duties
Many of our products ship directly from trusted international partners. Any applicable customs duties or import taxes are calculated at checkout and are non-refundable, even if the item is returned.

Returns & Associated Fees
All approved returns are subject to a $24 return processing fee. For international orders, duties, taxes, and return fees will be deducted from the original payment.

Shipping Policy
Complimentary shipping is offered on orders over $300. Orders below this threshold are subject to standard shipping rates at checkout.