Reviewed in the United States on September 6, 2013
If you are in cyber security this is a must read. It starts off with a preface by Todd Heberlein, the guy who started the craft of network monitoring. Richard spares us the rehash of things like the TCP 3 way handshake and jumps into actionable content very quickly. The book is the best resource for tools I have seen anywhere. The charts, diagrams, and screen shots bring the information to life. It was particularly great to see the focus on Security Onion.
The favorite part for me was the Collection, Analysis, Escalation and Resolution section. Mr. Bejtlich has a lot of experience in incident response and I am thankful he is willing to share his insights.
My advice is that you buy the book, read it, download Security Onion and learn to use some of the tools.