Cybersecurity Books: Offensive security

Pentesting, exploitation, and red team work: the books after which you have practice, not just vocabulary.

8/20/2026
Cybersecurity Books: Offensive security
Part 2 of 9: offensive security

Cybersecurity Books: Offensive security

Part two of nine. Pentesting, exploitation, and red team work. The books after which you have practice, not just vocabulary.

One requirement is non-negotiable: your own lab, and written authorisation for anything you do outside it.

Jon Erickson. Hacking: The Art of Exploitation (2nd edition, 2008)

The only book on the list that starts with C and assembly and takes you to a working exploit. The publication year is alarming, but nobody has explained the mechanics of a buffer overflow better since.

Topics: working with the stack and the heap, buffer overflows, format strings, shellcode, network attacks, bypassing the simplest protections, the basics of crypto attacks.

Georgia Weidman. Penetration Testing: A Hands-On Introduction to Hacking (2014)

The full penetration test cycle from reconnaissance to the report, with a step-by-step build of the lab. The best first practical book.

Topics: information gathering, scanning and service identification, exploiting common vulnerabilities, post-exploitation and persistence, attacks on wireless networks, mobile applications, writing your own exploit.

Peter Kim. The Hacker Playbook 3 (2018)

A collection of scenarios laid out like sports plays. Aimed at red teams rather than checklist audits.

Topics: external perimeter reconnaissance, phishing campaigns, evading antivirus and monitoring tools, lateral movement, compromising Active Directory, physical intrusion.

David Kennedy, Jim O'Gorman, Devon Kearns, Mati Aharoni. Metasploit: The Penetration Tester's Guide (2011)

The canonical guide to the framework. The interfaces have changed since; the working logic has not.

Topics: Metasploit architecture, modules and payloads, Meterpreter, evading defences, automation, writing your own modules.

Justin Seitz, Tim Arnold. Black Hat Python (2nd edition, 2021)

How to write your own tools instead of assembling other people's. The second edition has been rewritten for Python 3.

Topics: network clients and servers from scratch, sniffers, proxies, a trojan controlled over email, stealing data from the browser, automating Burp, working with the Windows API.

Vickie Li. Bug Bounty Bootcamp (2021)

On finding vulnerabilities in live web applications and the rules of the game on bounty platforms.

Topics: domain reconnaissance, choosing targets, the common classes of web vulnerabilities, escalating the severity of a finding, writing the report, working with the triage team.

Peter Yaworski. Real-World Bug Hunting (2019)

A breakdown of real public reports: what the researcher was looking for, what they found, and how much it paid.

Topics: XSS, CSRF, SSRF, access control bypasses, business logic flaws, vulnerabilities in OAuth flows, subdomain takeover.


Read more