The Practice of Network Security Monitoring: Understanding Incident Detection and Response
Richard Bejtlich · No Starch Press · 2013
Identifier: ISBN 978-1-59327-509-9
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
How to build and run network security monitoring: where to place sensors, what to collect (full packet capture, session data, alert data), and how to work a case from an alert through the collected evidence to a conclusion about scope.
Who it is for, and when
The clearest published statement of why you collect network evidence before you need it, and of the difference between an alert and a finding. Useful to anyone who has to assess whether an organisation monitoring was adequate, and to an examiner who inherits packet captures and session logs and has to make them tell a story. The publisher offers the preface and first chapter free, which is enough to judge whether the rest is for you.
What it does not cover
Written in 2013 against Security Onion of that era and a network model where most traffic was inspectable. It predates ubiquitous TLS, encrypted SNI, QUIC, cloud-native east-west traffic and the shift of visibility from the wire to identity and endpoint telemetry. The reasoning about collection tiers survives; the assumption that you can read the payload does not.
Go to the source
Open at nostarch.com (opens in a new tab)https://nostarch.com/nsm
Details
- Type
- Book
- Written for
- Working examinerWorking examiner
- Author
- Richard Bejtlich
- Publisher
- No Starch Press
- Year
- 2013
- Identifier
- ISBN 978-1-59327-509-9
- Topics
- network, incident-response, threat-hunting, log-analysis
- Checked at source
Related entries
A daily handler diary — distinct from the SANS DFIR blog — in which a rotating roster of volunteer handlers writes up whatever they are currently seeing in honeypot data, malware samples, exploit traffic and log telemetry.
Two complementary open-source network monitoring engines, both actively released. Zeek (formerly Bro) turns traffic into structured, protocol-aware logs — connections, HTTP requests, DNS queries, TLS handshakes, files seen — using its own scripting language. Suricata, from OISF, is a signature and rule-driven IDS/IPS that also produces rich EVE JSON records and can extract files.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
FIRST Conference
PaidThe annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.