Penetration Testing: A Hands-On Introduction
by Georgia Weidman · Georgia Weidman
A No Starch Press introduction to penetration testing built around a home lab of virtual machines. Covers reconnaissance, exploitation with Metasploit, password attacks, web and wireless attacks, post-exploitation, and basic exploit development, so readers can run a full assessment end to end.
This link may earn us a small commission at no extra cost to you. Affiliate disclosure
More resources on Penetration Testing
tryhackme.com
TryHackMe is an online cybersecurity training platform offering hands-on labs, guided learning paths, and real-world scenarios (rooms and challenges) to practice penetration testing, web security, and network defense in an interactive, gamified environment.
Hacking Exposed: Network Security Secrets and Solutions
Long-running reference on network attack techniques, organized around the attacker's workflow: footprinting, scanning and enumeration, then exploitation of Windows, UNIX, remote-access and wireless systems, each paired with countermeasures. Readers learn how intrusions unfold so they can harden networks; some tool coverage is dated.
pentesterlab.com
PentesterLab is an online platform offering hands-on penetration testing and web security labs. It provides guided, real-world exercises across web app vulnerabilities (e.g., SQL injection, XSS, CSRF, authentication flaws) with progress tracking and completion certificates.
Pre Security Learning Path
Start your penetration testing journey! Learn essential cybersecurity & networking skills with TryHackMe's Pre Security Learning Path.
NetSec Focus
Community-run site pairing a large Mattermost chat server with study guides, most notably TJnull's OSCP preparation list. Use it to find vetted practice boxes, certification study paths, and peers working through the same offensive security material.
Practical Ethical Hacking
Practitioner video course on network penetration testing, covering reconnaissance, scanning and enumeration, exploitation, Active Directory attacks, post-exploitation, web application basics and report writing using Kali Linux. Learners finish able to run a small internal pentest in a lab and document findings for a client.