'Phishing Exposed' by Lance James is a practical operational guide dedicated to Security Operations Center (SOC) workflows, SIEM engineering, and defensive threat hunting. Focusing on the methodologies needed to detect, analyze, and remediate enterprise intrusions, this text provides actionable blueprints for cyber defense.
The book explores log ingestion, Splunk search processing language (SPL), alert correlation rule development, incident triage, memory and endpoint analysis, threat intelligence integration, and MITRE ATT&CK alignment. Real-world scenario drills and interview preparation questions prepare readers for operational SOC roles.
A must-read for SOC analysts, SIEM administrators, threat hunters, and IT security engineers working in modern enterprise defense centers.
Contents at a Glance
Chapter 1: Psychological Principles of Social Engineering
Chapter 2: Information Gathering and OSINT Targeting
Chapter 3: Elicitation Techniques and Pretexting
Chapter 4: Phishing, Spear Phishing, and Whaling Attack Campaigns
Chapter 5: Vishing (Voice Phishing) and Smishing (SMS Attacks)
Chapter 6: Physical Security Penetration Testing and Lock Picking
Chapter 7: Malicious USB Drops and Rogue Hardware Implants
Chapter 8: Social Engineering Defense, Employee Training, and Policy
Index & Further Reading