// Prerequisites
What to read before The Art of Mac Malware, Volume 2
If The Art of Mac Malware, Volume 2 feels too steep at advanced level, here is what to read first. Lighter books in the same topics that build the prerequisites this one assumes.
01 · 2018
Malware Data Science
Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.
Intermediate4/5Joshua Saxe, Hillary Sanders02 · 2024
Evading EDR
A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.
Advanced4/5Matt Hand03 · 2022
The Art of Mac Malware, Volume 1
Patrick Wardle's deep dive on macOS malware analysis: persistence patterns, injection techniques, anti-analysis tricks, and the macOS-specific tooling needed to triage real samples.
Advanced4/5Patrick Wardle04 · 2012
Practical Malware Analysis
Still the gold standard textbook for static and dynamic malware analysis on Windows.
Intermediate5/5Michael Sikorski, Andrew Honig05 · 2013
The Practice of Network Security Monitoring
Richard Bejtlich's NSM playbook: how to deploy collection sensors, validate that you actually see what you think you see, and build detection workflows around open-source tools.
Intermediate5/5Richard Bejtlich06 · 2013
Applied Network Security Monitoring
A practitioner's walkthrough of building an NSM capability end to end, from deciding what to collect through detection and the analysis workflow that ties it together. The tooling is dated, but the way it teaches you to think about monitoring is not.
Intermediate4/5Chris Sanders, Jason Smith07 · 2026
Le Security Operations Center au cœur de la cybersécurité
Thomas Le Bourlot, nine years into operationalizing SOCs, delivers a systemic approach to the Security Operations Center that combines technology and governance, from supervision fundamentals through cloud, AI, and SOC-as-a-service models.
Intermediate4/5Thomas Le Bourlot08 · 2017
Network Security Through Data Analysis
Michael Collins on building situational awareness from network telemetry: collection architecture, statistical baseline-setting, and the analytic patterns that turn raw flows into detection.
Intermediate4/5Michael Collins