OSINT book

Intelligence-Driven Incident Response

Scott J. Roberts & Rebekah Brown

An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.

BookAdvancedCTIIncident responsePrioritisation

Who it’s for

  • SOC and IR analysts who enrich alerts with open sources
  • CTI analysts writing for operators, not for slides
  • Security engineers connecting collection to outcomes

What you get

  • Process models for adversary-focused incident response
  • Language for prioritising collection during an incident
  • A bridge between OSINT enrichment and SOC decision-making

How to use it

  1. 01

    Read before you buy more tools

    If your enrichment does not change a ticket decision, you do not need another provider — you need this framing.

  2. 02

    Map chapters to your runbooks

    Take one incident type (phishing, exposed host, leaked credential) and rewrite the runbook with intel questions first.

Strengths

  • Connects open sources to detection and response outcomes
  • Useful shared vocabulary for SOC + CTI handoffs
  • Keeps OSINT honest about purpose

Watch out for

  • Not a beginner OSINT techniques book
  • Confirm current edition/ISBN with O’Reilly or your bookseller

FAQ

Questions, answered

What is Intelligence-Driven Incident Response?

An O’Reilly text on how CTI and IR teams use intelligence — including open sources — to prioritise detection and response. It is not a people-search OSINT manual; it is the framing that keeps enrichment from becoming hobby collecting.

Who is this book for?

SOC and IR analysts who enrich alerts with open sources; CTI analysts writing for operators, not for slides. You’ll get: Process models for adversary-focused incident response; Language for prioritising collection during an incident.