Metasploit: The Penetration Tester’s Guide
by David Kennedy, Jim O'Gorman, Devon Kearns, Mati Aharoni · David Kennedy, Jim O’Gorman, Devon Kearns, Mati Aharoni
A No Starch Press guide to the Metasploit Framework by experienced penetration testers. Walks through intelligence gathering, vulnerability scanning, exploitation, Meterpreter, client-side attacks, and writing custom modules, so readers can use Metasploit across every phase of a penetration test.
This link may earn us a small commission at no extra cost to you. Affiliate disclosure
More resources on Penetration Testing
tryhackme.com
TryHackMe is an online cybersecurity training platform offering hands-on labs, guided learning paths, and real-world scenarios (rooms and challenges) to practice penetration testing, web security, and network defense in an interactive, gamified environment.
Hacking Exposed: Network Security Secrets and Solutions
Long-running reference on network attack techniques, organized around the attacker's workflow: footprinting, scanning and enumeration, then exploitation of Windows, UNIX, remote-access and wireless systems, each paired with countermeasures. Readers learn how intrusions unfold so they can harden networks; some tool coverage is dated.
pentesterlab.com
PentesterLab is an online platform offering hands-on penetration testing and web security labs. It provides guided, real-world exercises across web app vulnerabilities (e.g., SQL injection, XSS, CSRF, authentication flaws) with progress tracking and completion certificates.
Pre Security Learning Path
Start your penetration testing journey! Learn essential cybersecurity & networking skills with TryHackMe's Pre Security Learning Path.
NetSec Focus
Community-run site pairing a large Mattermost chat server with study guides, most notably TJnull's OSCP preparation list. Use it to find vetted practice boxes, certification study paths, and peers working through the same offensive security material.
Practical Ethical Hacking
Practitioner video course on network penetration testing, covering reconnaissance, scanning and enumeration, exploitation, Active Directory attacks, post-exploitation, web application basics and report writing using Kali Linux. Learners finish able to run a small internal pentest in a lab and document findings for a client.