Curated books on reconnaissance, OSINT, automation, threat intelligence, and vulnerability management.
π Recommended Reading List for Attack Surface Management (ASM)
This curated list covers reconnaissance, OSINT, threat intelligence, vulnerability management, and automation β all crucial topics for modern ASM strategies.
π Reconnaissance and Enumeration
-
The Hacker Playbook 3 β Peter Kim
Advanced red teaming strategies, recon workflows, and attack simulation techniques. -
Red Team Field Manual (RTFM) β Ben Clark
A compact, no-fluff field reference with Unix, Windows, networking, and enumeration commands. -
Network Attacks and Exploitation β Matthew Monte
Describes how attackers leverage protocols and architecture for recon and exploitation. -
Penetration Testing: A Hands-On Introduction to Hacking β Georgia Weidman
Introductory book covering scanning, enumeration, exploitation, and post-exploitation.
π OSINT and Passive Intelligence
-
Open Source Intelligence Techniques β Michael Bazzell
Covers internet investigation, profiling, and OSINT tool usage. -
Practical Social Engineering β Joe Gray
Emphasizes digital footprinting, recon, and pretexting techniques. -
The Web Application Hackerβs Handbook β Dafydd Stuttard & Marcus Pinto
Deep dive into web attack surfaces and enumeration paths.
βοΈ Automation and Scripting
-
Black Hat Python β Justin Seitz
Learn to build your own recon bots, scanners, and parsing scripts. -
Violent Python β TJ O'Connor
Scripts and techniques for enumeration, scanning, and network recon.
π§ Threat Intelligence and Defensive ASM
-
The Practice of Network Security Monitoring β Richard Bejtlich
Learn how monitoring correlates with exposure and risk surface visibility. -
Intelligence-Driven Incident Response β Scott Roberts, Rebekah Brown
Threat intelligence as a structured process to inform incident readiness. -
Cyber Threat Intelligence β Henry Dalziel
Overview of CTI processes and how they relate to surface discovery and profiling.
π‘οΈ Risk and Vulnerability Management
-
Practical Vulnerability Management β Andrew Magnusson
Practical guidance on prioritizing, remediating, and tracking vulnerabilities within an organization. -
Asset Attack Vectors β Morey J. Haber & Brad Hibbert
Framework for understanding how exposed assets become attack vectors in real-world breaches. -
IT Security Risk Control Management β Raymond Pompon
Methodologies for managing cybersecurity risk and control frameworks in complex IT environments.
Disclosure: As an Amazon Associate, I may earn from qualifying purchases. This helps support the project at no additional cost to you.