Summary: Blue Team Field Manual

  • Starts with nmap, Nessus, and OpenVAS scanning for discovery
  • Like the network monitoring section, top talkers command is nice
  • Love the clear-text protocol password finder
  • Love the tshark stuff
  • Like the rkhunter mention
  • Love the sysinternals tools mention and checks
  • Typo on page 86 (stings instead of strings) That stings for me because I had typos in my book too
  • Love the identify malware section
  • Love the OS cheats / tricks section
  • Love the Snort section, esp detecting meterpreter
  • Love the incident management checklist

Lessons / Takeaways

  • It’s a reference book of helpful commands and resources
  • It got better as I got further into it and realized how important it’d be to parse it for useful commands as a defender

