Poradniki zawodowe i specjalistyczne
Glen D. Singh
Build practical ethical hacking skills through realistic attack scenarios that reflect how security assessments are performed in real organizations. This book helps you move beyond theory by showing how vulnerabilities are discovered, exploited responsibly, and reported clearly.Written by Glen D. Singh, a cybersecurity instructor and author with deep experience in offensive security, networking, and security operations, this book emphasizes practical skill development and responsible testing practices. You begin by setting up a safe lab and learning ethical hacking principles, methodologies, and legal considerations. Then you progress through reconnaissance, scanning, and enumeration to understand how attackers gather intelligence and how defenders reduce exposure. You’ll continue with vulnerability assessment, system hacking, malware basics, and network attacks using structured labs.As environments grow more complex, you explore wireless attacks, IoT and OT threats, and gain awareness of SIEM and EDR detection. The final chapters focus on professional reporting and career development, showing how to present findings clearly and ethically.By the end of this book, you will be able to perform ethical hacking engagements from reconnaissance to reporting with confidence.
Threat Modeling Best Practices. Proven frameworks and practical techniques to secure modern systems
Derek Fisher
Threat modeling has become a cornerstone of modern cybersecurity, yet it is often overlooked, leaving security gaps that attackers can exploit. With the rise in system complexity, cloud adoption, AI-driven threats, and stricter compliance requirements, security teams need a structured approach to proactively spot and stop risks before attackers do. This book delivers exactly that, offering actionable insights for applying industry best practices and emerging technologies to secure systems. It breaks down the fundamentals of threat modeling and walks you through key frameworks and tools such as STRIDE, MITRE ATT&CK, PyTM, and Attack Paths, helping you choose the right model and create a roadmap tailored to your business. You'll learn how to use leading threat modeling tools, identify and prioritize potential threats, and integrate these practices into the software development life cycle to detect risks early. The book also examines how AI can enhance analysis and streamline security decision-making for faster, stronger defenses.By the end, you'll have everything you need to build systems that anticipate and withstand evolving threats, keeping your organization secure in an ever-changing digital landscape.*Email sign-up and proof of purchase required
Threat Modeling Gameplay with EoP. A reference manual for spotting threats in software architecture
Brett Crawley, Adam Shostack
Are you looking to navigate security risks, but want to make your learning experience fun? Here's a comprehensive guide that introduces the concept of play to protect, helping you discover the threats that could affect your software design via gameplay.Each chapter in this book covers a suit in the Elevation of Privilege (EoP) card deck (a threat category), providing example threats, references, and suggested mitigations for each card. You’ll explore the methodology for threat modeling—Spoofing, Tampering, Repudiation, Information Disclosure, and Elevation of Privilege (S.T.R.I.D.E.) with Privacy deck and the T.R.I.M. extension pack. T.R.I.M. is a framework for privacy that stands for Transfer, Retention/Removal, Inference, and Minimization. Throughout the book, you’ll learn the meanings of these terms and how they should be applied. From spotting vulnerabilities to implementing practical solutions, the chapters provide actionable strategies for fortifying the security of software systems.By the end of this book, you will be able to recognize threats, understand privacy regulations, access references for further exploration, and get familiarized with techniques to protect against these threats and minimize risks.
Dr. Paul Duplys, Dr. Roland Schmitz
TLS is the most widely used cryptographic protocol today, enabling e-commerce, online banking, and secure online communication. Written by Dr. Paul Duplys, Security, Privacy & Safety Research Lead at Bosch, and Dr. Roland Schmitz, Internet Security Professor at Stuttgart Media University, this book will help you gain a deep understanding of how and why TLS works, how past attacks on TLS were possible, and how vulnerabilities that enabled them were addressed in the latest TLS version 1.3. By exploring the inner workings of TLS, you’ll be able to configure it and use it more securely.Starting with the basic concepts, you’ll be led step by step through the world of modern cryptography, guided by the TLS protocol. As you advance, you’ll be learning about the necessary mathematical concepts from scratch. Topics such as public-key cryptography based on elliptic curves will be explained with a view on real-world applications in TLS. With easy-to-understand concepts, you’ll find out how secret keys are generated and exchanged in TLS, and how they are used to creating a secure channel between a client and a server.By the end of this book, you’ll have the knowledge to configure TLS servers securely. Moreover, you’ll have gained a deep knowledge of the cryptographic primitives that make up TLS.
Eric Richardson, Filipi Pires
Modern organizations rely on complex vendor ecosystems, but third-party risk management (TPRM) and cybersecurity often operate in silos. This book shows how to connect vendor risk management with supply chain cybersecurity using a practical, lifecycle-driven approach.You’ll design a program covering onboarding, vendor risk assessment, continuous monitoring, and offboarding. You’ll begin by examining why TPRM and cybersecurity often operate in separate lanes, and what that gap costs in downtime, breach impact, and compliance exposure. Next, you’ll develop a modern taxonomy of supply chain risk, including fourth-party dependencies and software supply chain concerns, so risk discussions use consistent categories and measurable assumptions.From there, you’ll adopt a lifecycle-based model to structure vendor onboarding, assessment, monitoring, and offboarding—supported by vendor tiering, segmentation, and control mapping. The final chapter focuses on the regulatory blueprint: how to interpret NIST C-SCRM, ISO/IEC 27036, DORA, GDPR, and Executive Order 14028, then convert them into evidence-driven controls and audit-ready documentation.
Jacek Popczyk, Jan Sieczkowski
Przedmiotem opracowania są warunki techniczne wykonania i odbioru robót tynkowych dotyczące rozwiązań najczęściej występujących w praktyce. Warunki dla rozwiązań szczególnych powinny być ustalane indywidualnie. Niniejsze warunki techniczne obejmują: terminy i definicje, wymagania dotyczące dokumentacji budowy, warunki wykonania oraz kryteria odbioru robót tynkowych. Niniejsze warunki techniczne nie dotyczą: tynków o zwiększonej izolacyjności akustycznej, tynków przeciwpożarowych oraz osłaniających przed promieniowaniem, tynków renowacyjnych, tynków cienkowarstwowych stosowanych w systemach ociepleniowych ETICS oraz suchych tynków.
Jose Lazaro, Marcus Burnap, Rod Trent
In the evolving cybersecurity landscape, the integration of Microsoft Defender XDR and Security Copilot presents a game-changing approach to modern threat detection and response. With this book, you’ll understand how these tools, in conjunction with Microsoft’s extensive ecosystem, enable organizations to outpace emerging threats.Starting with core XDR concepts, security frameworks, and Microsoft’s competitive advantages in cybersecurity, you’ll master the foundational aspects of deploying Microsoft Sentinel, configuring security infrastructure, and optimizing security operations using AI-driven tools. Advanced topics, including Zero-Trust strategies, DevSecOps integration, and partner programs, prepare you for increasingly sophisticated scenarios in Microsoft cloud security. You’ll also explore practical deployment workflows, covering cost analysis, role-based access configurations, and fast-tracked Sentinel deployment using CI/CD pipelines.By the end of this book, you’ll have gained insights into security automation, threat detection, and AI integration with Security Copilot for optimized operations and have the confidence to implement and manage Microsoft Defender XDR and Sentinel in complex environments, driving scalable and secure solutions.*Email sign-up and proof of purchase required
Tyson Butler-Boschma, Manea Castet
Written by multi-award-winning Unreal generalist Tyson J. Butler-Boschma, Founder and Creative Director of Toybox Games Studios, this book addresses common challenges you face when advancing your expertise in lighting, environment design, and cinematic storytelling. The chapters help you move quickly from mastering core skills to exploring the most innovative Unreal Engine 5 features, such as Lumen, ray tracing, Nanite, and Chaos Physics, to craft professional-quality immersive scenes and experiences.Packed with actionable insights and step-by-step workflows, this hands-on guide teaches you how to optimize performance without sacrificing visual fidelity, use Unreal’s built-in tools to create interactive environments, and implement cutting-edge techniques to enhance storytelling and interactivity. Each chapter features practical examples and troubleshooting tips to help you overcome real-world obstacles and bring your creative visions to life.By the end of this book, you’ll be fully equipped to design visually stunning, high-performance projects in Unreal Engine 5.*Email sign-up and proof of purchase required