---
title: Ethical Hacking
description: Ethical hacking involves identifying and exploiting security vulnerabilities to improve system defense. You will understand penetration testing methodologies, reconnaissance, vulnerability scanning, and exploitation techniques, enabling you to secure networks and applications against malicious attacks.
category: programming-tech
subcategory: cybersecurity
difficulty: beginner, intermediate, advanced
url: /subject/cybersecurity-ethical-hacking
---

# Ethical Hacking

Ethical hacking involves identifying and exploiting security vulnerabilities to improve system defense. You will understand penetration testing methodologies, reconnaissance, vulnerability scanning, and exploitation techniques, enabling you to secure networks and applications against malicious attacks.

## Where to start

Start with TryHackMe Learning Paths, whose Pre-Security and Jr Penetration Tester paths take a complete novice from networking and Linux to exploitation; some rooms are free, but full paths need a subscription. If you only use one resource, make it Heath Adams' paid Practical Ethical Hacking course from TCM Security, covering testing methodology, Active Directory attacks and report writing. For web applications, continue with the free PortSwigger Web Security Academy.

## Available Resources

1 Videos • 2 Books • 5 Courses • 7 Websites

## Videos

### 1. NetworkChuck - Ethical Hacking Full Course

**Author:** Heath Adams

First half of TCM Security's free 2023 Practical Ethical Hacking course on YouTube, taught by Heath Adams: networking and Linux refreshers, Python basics, information gathering, scanning and enumeration, and exploitation of a first vulnerable machine. Part 2 continues into Active Directory.

**Difficulty:** Beginner | **Price:** Free

**Link:** https://www.youtube.com/watch?v=3FNYvj2U0HM

**Tags:** penetration-testing, video-course, enumeration, kali-linux, tcm-security

## Courses

### 1. Practical Ethical Hacking

**Author:** Heath Adams

Practitioner video course on network penetration testing, covering reconnaissance, scanning and enumeration, exploitation, Active Directory attacks, post-exploitation, web application basics and report writing using Kali Linux. Learners finish able to run a small internal pentest in a lab and document findings for a client.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://academy.tcm-sec.com/p/practical-ethical-hacking

**Tags:** penetration-testing, ethical-hacking, active-directory, kali-linux, exploitation

### 2. HackTheBox Academy

Hack The Box's structured, module-based learning platform, separate from its labs. Modules pair written theory with browser-based target machines and end in graded skills assessments; job-role paths lead to the CPTS and CBBH certifications. Fundamentals tier is free, most modules cost cubes.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://academy.hackthebox.com/

**Tags:** penetration-testing, hands-on-labs, cpts, red-teaming, web-security

### 3. TryHackMe Learning Paths

Guided sequences of TryHackMe rooms, each combining short reading with browser-accessible target machines. The Pre-Security and Jr Penetration Tester paths take a complete novice through networking, Linux, web basics, enumeration and exploitation; some rooms are free, full paths require a subscription.

**Difficulty:** Beginner | **Price:** Free

**Link:** https://tryhackme.com/paths

**Tags:** hands-on-labs, penetration-testing, networking-basics, linux, beginner-path

### 4. Practical Ethical Hacking

**Author:** Heath Adams

Heath Adams's 25-hour course, the paid and maintained version of his free YouTube series. Covers networking and Linux, Python scripting, external and internal penetration testing methodology, Active Directory attacks, web application testing, and report writing, with a lab you build yourself.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course

**Tags:** penetration-testing, active-directory, web-application-testing, report-writing, home-lab

### 5. pwn.college

Arizona State University's free hands-on security platform: lecture videos plus hundreds of in-browser challenges progressing from Linux basics and program interaction through reverse engineering, memory corruption, shellcoding, kernel security, and web exploitation.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://pwn.college/

**Tags:** binary-exploitation, reverse-engineering, shellcode, kernel-security, capture-the-flag

## Websites

### 1. VulnHub

Community-maintained catalogue of downloadable, intentionally vulnerable virtual machines you run locally in VirtualBox or VMware. Working through boxes teaches enumeration, exploitation, and privilege escalation end to end, and most have public walkthroughs to check your approach against.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://www.vulnhub.com/

**Tags:** vulnerable-machines, ctf, privilege-escalation, home-lab, hands-on-practice

### 2. HackTricks

**Author:** Carlos Polop

Community-maintained open-source pentesting knowledge base by Carlos Polop, organized by methodology: pentesting network services by port, web vulnerabilities, Linux and Windows privilege escalation, Active Directory, and cloud, with concrete commands and checklists.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://book.hacktricks.wiki/

**Tags:** penetration-testing, privilege-escalation, web-security, active-directory, cheat-sheets

### 3. picoCTF (CyLab Security Academy)

Carnegie Mellon's free capture-the-flag platform, now branded CyLab Security Academy, with a year-round practice gym of beginner-friendly challenges in web exploitation, cryptography, forensics, reverse engineering, and binary exploitation, plus an annual competition.

**Difficulty:** Beginner | **Language:** English | **Price:** Free

**Link:** https://picoctf.org/

**Tags:** capture-the-flag, cryptography, digital-forensics, reverse-engineering, web-exploitation

### 4. PortSwigger Web Security Academy

Free interactive web-hacking curriculum from the makers of Burp Suite, with written learning paths and over 250 deliberately vulnerable labs covering SQL injection, XSS, SSRF, authentication flaws, access control, and other web vulnerability classes.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://portswigger.net/web-security

**Tags:** web-security, burp-suite, sql-injection, xss, hands-on-labs, owasp

### 5. OWASP Foundation

Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://owasp.org

**Tags:** owasp-top-ten, application-security, secure-coding, vulnerability-testing, web-vulnerabilities

### 6. tryhackme.com

TryHackMe is an online cybersecurity training platform offering hands-on labs, guided learning paths, and real-world scenarios (rooms and challenges) to practice penetration testing, web security, and network defense in an interactive, gamified environment.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://tryhackme.com

**Tags:** websites, technology-computer-science, computer-sciences

### 7. overthewire.org

OverTheWire is a free, hands-on security training platform offering interactive wargames (like Bandit and Natas) that teach Linux, networking, and web security concepts through progressively challenging levels.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://overthewire.org

**Tags:** websites, technology-computer-science, cybersecurity

## Youtubes

### 1. The Cyber Mentors

**Author:** Heath Adams

Heath Adams's TCM Security channel teaches practical penetration testing: Linux and Python basics, network and web application hacking, Active Directory attacks, and privilege escalation. Free full-length courses let viewers build a lab and follow a realistic ethical-hacking methodology.

**Difficulty:** Beginner | **Language:** English | **Price:** Free

**Link:** https://youtube.com/@tcmsecurityacademy

**Tags:** penetration-testing, ethical-hacking, active-directory, web-application-security, privilege-escalation

### 2. IppSec (YouTube)

**Author:** IppSec

Weekly full-length walkthroughs of retired Hack The Box machines showing a complete attack chain: enumeration, foothold, privilege escalation, and the reasoning behind each step. Several hundred videos, searchable by technique via the companion ippsec.rocks index.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://www.youtube.com/@ippsec

**Tags:** hack-the-box, penetration-testing, walkthroughs, privilege-escalation, enumeration

## Books

### 1. The Web Application Hacker's Handbook, 2nd Edition

**Author:** Dafydd Stuttard, Marcus Pinto

Stuttard and Pinto's 900-page methodology for attacking web applications: mapping, bypassing client-side controls, authentication and session flaws, access control, injection, logic bugs, and a step-by-step testing checklist. Written by Burp Suite's creator.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/1118026470?tag=edmonddante07-20

**Tags:** web-security, penetration-testing, web-application-testing, injection-attacks, authentication

### 2. The Basics of Hacking and Penetration Testing

**Author:** Patrick Engebretson

Short Syngress introduction to penetration testing, organized around a four-phase methodology: reconnaissance, scanning, exploitation, and maintaining access. Walks through Kali tools (Nmap, Nessus, Metasploit, Netcat) on a lab you build yourself. Second edition (2013) is dated on tool versions but a clear first book.

**Difficulty:** Beginner | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/0124116442?tag=edmonddante07-20

**Tags:** penetration-testing, methodology, metasploit, nmap, introductory-book

---

*This content is part of Dantes.io - Your Treasure Map to Knowledge*

*Curated by humans at Dantes.io. Personal study use welcome; republishing this curation requires permission (team@dantes.io).*

View this page online: https://dantes.io/subject/cybersecurity-ethical-hacking