Könyv Python for Security Automation Marcus Iyer

Python for Security Automation

Automate Incident Response, Threat Intelligence, and Security Operations

Szerző: Marcus Iyer
Nyelv: Angol
Kötés: Puha kötésű
Elérhetőség: Beszállítói készleten
Küldés 14-21 napon belül
7 653 Ft
PYTHON FOR SECURITY AUTOMATIONAutomate Incident Response, Threat Intelligence, and Security Operatio...

Információk a könyvről

Szerző
Nyelv
Angol
Kötés
Könyv - Puha kötésű
Kiadva
2026
oldal
354
EAN
9798175633253
Enbook ID
53969880
Súly
616
Méretek
178 x 254 x 19

Teljes leírás

PYTHON FOR SECURITY AUTOMATION
Automate Incident Response, Threat Intelligence, and Security Operations

Security teams can detect thousands of threats - but detection is only the beginning. The real challenge is turning alerts into timely, consistent, and auditable action.

Python for Security Automation is the third book in the Python for Security Engineering series. It takes you beyond monitoring and detection into the engineering of automated incident response, threat intelligence workflows, and security operations.

Through a practical, project-driven approach, you will build AutoSOC - a modular Security Orchestration, Automation, and Response (SOAR) platform that connects detection to enrichment, investigation, containment, and reporting.

You will learn how to:

• Use asynchronous Python to handle high-volume security workflows.

• Manage configuration, secrets, and audit logs securely.

• Build a flexible playbook engine with conditions, branching, and rollback procedures.

• Integrate ticketing and case management into response workflows.

• Automate evidence collection and forensic packaging.

• Implement containment and remediation actions through integration adapters.

• Ingest and normalize threat intelligence from STIX, TAXII, and MISP sources.

• Enrich indicators of compromise at scale using parallel processing and caching.

• Map security events and responses to the MITRE ATT&CK framework.

• Automate proactive threat hunting across historical security data.

• Build operational metrics, service-level indicators, and security reports.

• Test and validate automated workflows before production deployment.

• Package and deploy a modular security platform with Docker and systemd.

• Integrate secure secrets management and self-monitoring into a production-oriented architecture.

From Security Alerts to Structured Response

AutoSOC is developed progressively, with every chapter contributing a component to the complete platform. You will explore the four levels of security automation - enrichment, triage, response, and orchestration - and learn how to define the boundaries between automated actions and human judgment.

The book emphasizes modular design, explicit error handling, auditability, rollback procedures, and controlled deployment. Automation is presented not as a replacement for security professionals, but as a way to reduce repetitive work and give analysts more time for decisions that require experience and context.

The final capstone brings the platforms from the series together in a simulated attack scenario, demonstrating how attack-surface knowledge, monitoring, and automated response can form a connected security operations workflow.

This book is intended for security engineers, DevSecOps practitioners, and SOC analysts who want to build practical automation capabilities with Python. Intermediate Python knowledge is assumed. You should be familiar with basic security concepts, such as firewalls, endpoint security, and identity systems.

You will need Python 3.11 or later, Docker for the deployment chapters, and a Linux or macOS environment. Windows users can use WSL2.

Build the automation layer that turns security knowledge into repeatable action.

Continue the Python for Security Engineering series and learn how to engineer more responsive, measurable, and maintainable security operations.

Use all techniques only on systems and networks you own or are explicitly authorized to operate.