The Identity Attack Lifecycle
Autor Marcus Walsheen Limba Engleză Paperback – 15 feb 2027
This book reframes how defenders understand and detect these threats. Rather than treating identity incidents as isolated credential failures, the book introduces a lifecycle-based model of attack progression. You will see how modern identity attacks advance through recognizable behavioral stages (accumulating capability, establishing trust relationships, activating latent access paths, coordinating actions across multiple identities and services) and how this progression can reveal attacker intent even when individual events appear legitimate.
Written for practitioners, the book delivers a practical, real-world detection methodology. You'll learn to model identity environments as interconnected graphs of permissions, tokens, workflows, and trust, enabling detection based on structure and behavior rather than alerts alone. Through concrete attack patterns-such as the Quiet Privilege Ladder, Token Ghosts, Session Chaining, and the Invisible Hand-the book shows how identity attacks actually operate, and how to introduce precise friction that disrupts attackers without disrupting business.
Concise, vendor-agnostic, and immediately applicable, this book offers a unifying framework for IAM practitioners, cloud security engineers, detection engineers, and security architects navigating a fragmented identity security landscape. By the final chapter, you will be equipped to spot identity-driven attacks early, design identity-aware detection systems, and respond decisively-while attack progression is still unfolding, even when traditional security alerts reveal little in isolation.
What You Will Learn:
- Recognize how modern identity attacks progress through lifecycle stages rather than isolated credential events
- Understand how workload identities, tokens, and delegated trust relationships create hidden attack paths in cloud systems
- Design detection approaches that identify behavioral patterns across identities instead of focusing only on compromised accounts
- Apply identity graph modelling to reconstruct attacks and track their progression
- Introduce friction-based controls that slow attackers without disrupting legitimate system operation
Security professionals responsible for protecting modern cloud and enterprise environments where identity systems control access across infrastructure and applications, including identity and access management (IAM) architects, cloud security engineers, security operations and detection engineers, and security architects and technical security leaders. Readers should have a working understanding of identity systems, authentication concepts, and cloud platforms. Familiarity with technologies such as OAuth, federation, privileged access management, and API security will help readers understand the examples in the book. The book does not require expertise in graph databases or data science; the focus is on conceptual modelling and practical detection approaches rather than specific implementation technologies.
Preț: 371.28 lei
Preț vechi: 464.10 lei
-20% Precomandă
Puncte Express: 557
Carte nepublicată încă
Livrare prin curier în România Precomanda se expediază când titlul devine disponibil.
Transport gratuit de la 400.00 lei Plată online sau ramburs, în funcție de opțiunile comenzii.
Retur gratuit în 14 zile Comandă securizată și suport în română.
Doresc să fiu notificat când acest titlu va fi disponibil:
Se trimite...
Specificații
ISBN-13: 9798868834455
Ilustrații: Approx. 250 p.
Dimensiuni: 155 x 235 mm
Ediția:First Edition
Editura: APRESS L.P.
Colecția Apress
Ilustrații: Approx. 250 p.
Dimensiuni: 155 x 235 mm
Ediția:First Edition
Editura: APRESS L.P.
Colecția Apress
Notă biografică
Marcus Walshe is a cybersecurity practitioner and security architect with more than 30 years of experience in enterprise technology, including more than a decade specializing in identity and access management, security architecture, and identity governance. He has designed, transformed, and operated identity systems in large, complex organizations across financial services, retail, aviation, and regulated enterprise environments.
Marcus's work sits at the intersection of security architecture and operations, spanning identity governance, access models, privileged access, cloud security, automation, and large-scale identity programs. His experience ranges from traditional enterprise identity platforms to modern cloud-native environments, where applications, workloads, service identities, and automation increasingly operate alongside human identities.
Marcus holds an MSc degree in Cybersecurity and is a CISSP. He has published peer-reviewed research into authentication for constrained IoT environments. The Identity Attack Lifecycle draws on his practical experience of how identity and authority behave in complex enterprise systems, and the challenges defenders face as those systems become increasingly distributed and automated.
Marcus's work sits at the intersection of security architecture and operations, spanning identity governance, access models, privileged access, cloud security, automation, and large-scale identity programs. His experience ranges from traditional enterprise identity platforms to modern cloud-native environments, where applications, workloads, service identities, and automation increasingly operate alongside human identities.
Marcus holds an MSc degree in Cybersecurity and is a CISSP. He has published peer-reviewed research into authentication for constrained IoT environments. The Identity Attack Lifecycle draws on his practical experience of how identity and authority behave in complex enterprise systems, and the challenges defenders face as those systems become increasingly distributed and automated.
Cuprins
Part I: Identity as the Attack Surface.- Chapter 1: When Identity Became the Control Plane.- Chapter 2: The Failure of Account-Centric Security.- Chapter 3: From Events to Lifecycles.- Chapter 4: Behavioural Continuity and the Inferred Actor.- Part II: The Identity Attack Lifecycle.- Chapter 5: Identity Species: Who (and What) Acts in Modern Systems.- Chapter 6: The Quiet Privilege Ladder.- Chapter 7: Consent as Persistence.- Chapter 8: First Access That Doesn’t Look Like First Access.- Chapter 9: Identity Drift.- Chapter 10: The One-Minute Admin.- Chapter 11: The Lateral Privilege Echo.- Chapter 12: Token Ghosts.- Chapter 13: Orphaned Power.- Chapter 14: Session Chaining.- Chapter 15: The Invisible Hand.- Chapter 16: The Shape of the Attack.- Chapter 17: Distributed Objectives.- Part III: The Identity Native Defence Model.- Chapter 18: Known ITDR Blind Spots and How an Identity Graph Model Confronts Them.- Chapter 19: Telemetry for Identity Reconstruction.- Chapter 20: Identity Graph Model: From Telemetry to Schema.- Chapter 21: Detector Families and FrictionalIntervention.- Chapter 22: Identity-Centric Forensics in Near Time.- Part IV: Reconstructing Identity Attacks Using the Detection Model.- Chapter 23: Defender Walkthrough: The Quiet Privilege Ladder.- Chapter 24: Defender Walkthrough: Consent as Persistence.- Chapter 25: Defender Walkthrough: First Access That Doesn’t Look Like First Access.- Chapter 26: Defender Walkthrough: Identity Drift.- Chapter 27: Defender Walkthrough: The One-Minute Admin.- Chapter 28: Defender Walkthrough: The Lateral Privilege Echo.- Chapter 29: Defender Walkthrough: Token Ghosts.- Chapter 30: Defender Walkthrough: Orphaned Power.- Chapter 31: Defender Walkthrough: Session Chaining.- Chapter 32: Defender Walkthrough: The Invisible Hand.- Part V: Operating Identity Defence.- Chapter 33: Operating the Methodology.- Chapter 34; Adaptive Identity Response.- Chapter 35: Maturity, Metrics, and Growing Identity Defence.- Chapter 36: The Future of Identity as an Attack Surface.- Appendix A: A Reference ITDR Detection Model for Modern IAM.- Appendix B: Reference Architecture Summary.- Appendix C: Building Identity-Native Detection Systems.