//Topic

Best Detection books

7 books in our catalog cover Detection, ranked by rating. Each entry is an opinionated review with who the book is for and who should skip it.

// Reading guide

Read the full editorial pick: the best Detection books in 2026, ranked and reviewed.

  1. 01 · 2013

    The Practice of Network Security Monitoring

    Understanding Incident Detection and Response

    Richard Bejtlich's NSM playbook: how to deploy collection sensors, validate that you actually see what you think you see, and build detection workflows around open-source tools.

    Intermediate5/5Richard Bejtlich
  2. 02 · 2024

    Evading EDR

    The Definitive Guide to Defeating Endpoint Detection Systems

    A component-by-component teardown of how modern EDR sensors actually collect telemetry, and where each data source can be starved, blinded, or bypassed.

    Advanced4/5Matt Hand
  3. 03 · 2018

    Malware Data Science

    Attack Detection and Attribution

    Saxe and Sanders apply machine-learning techniques (classification, clustering, deep learning) to malware detection and attribution, with working Python code and real corpora.

    Intermediate4/5Joshua Saxe, Hillary Sanders
  4. 04 · 2017

    Network Security Through Data Analysis

    From Data to Action

    Michael Collins on building situational awareness from network telemetry: collection architecture, statistical baseline-setting, and the analytic patterns that turn raw flows into detection.

    Intermediate4/5Michael Collins
  5. 05 · 2015

    Sécurité et espionnage informatique

    Connaissance de la menace APT et du cyberespionnage

    A technical French guide to advanced persistent threats and cyber-espionage — how APT campaigns work, how to detect them, and how to defend — by one of France's APT specialists.

    Advanced4/5Cédric Pernet
  6. 06 · 2013

    Applied Network Security Monitoring

    Collection, Detection, and Analysis

    A practitioner's walkthrough of building an NSM capability end to end, from deciding what to collect through detection and the analysis workflow that ties it together. The tooling is dated, but the way it teaches you to think about monitoring is not.

    Intermediate4/5Chris Sanders, Jason Smith
  7. 07 · 2010

    Tableaux de bord de la sécurité réseau

    A practitioner's manual for measuring and steering network security — metrics, dashboards, monitoring and risk indicators — for the people who run security operations.

    Advanced3/5Cédric Llorens, Laurent Levier, Denis Valois

Related topics