---
title: Penetration Testing
description: Penetration testing is the practice of authorized simulated attacks on computer systems to evaluate security. You will understand how to identify vulnerabilities, exploit weaknesses, and recommend remediation steps to secure digital infrastructure.
category: programming-tech
subcategory: cybersecurity
difficulty: beginner, intermediate, advanced
url: /subject/penetration-testing
---

# Penetration Testing

Penetration testing is the practice of authorized simulated attacks on computer systems to evaluate security. You will understand how to identify vulnerabilities, exploit weaknesses, and recommend remediation steps to secure digital infrastructure.

## Available Resources

5 Books • 3 Courses • 6 Websites

## Courses

### 1. Pre Security Learning Path

Start your penetration testing journey! Learn essential cybersecurity & networking skills with TryHackMe's Pre Security Learning Path.

**Difficulty:** Beginner | **Price:** Free

**Link:** https://tryhackme.com/path/outline/presecurity

**Tags:** cybersecurity-fundamentals, networking, linux, web-fundamentals, penetration-testing

### 2. Practical Ethical Hacking

**Author:** Heath Adams

Practitioner video course on network penetration testing, covering reconnaissance, scanning and enumeration, exploitation, Active Directory attacks, post-exploitation, web application basics and report writing using Kali Linux. Learners finish able to run a small internal pentest in a lab and document findings for a client.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://academy.tcm-sec.com/p/practical-ethical-hacking

**Tags:** penetration-testing, ethical-hacking, active-directory, kali-linux, exploitation

### 3. Practical Ethical Hacking

**Author:** Heath Adams

Heath Adams's 25-hour course, the paid and maintained version of his free YouTube series. Covers networking and Linux, Python scripting, external and internal penetration testing methodology, Active Directory attacks, web application testing, and report writing, with a lab you build yourself.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://academy.tcm-sec.com/p/practical-ethical-hacking-the-complete-course

**Tags:** penetration-testing, active-directory, web-application-testing, report-writing, home-lab

## Websites

### 1. NetSec Focus

Community-run site pairing a large Mattermost chat server with study guides, most notably TJnull's OSCP preparation list. Use it to find vetted practice boxes, certification study paths, and peers working through the same offensive security material.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://www.netsecfocus.com/

**Tags:** offensive-security, oscp, penetration-testing, community, study-guides

### 2. VulnHub

Community-maintained catalogue of downloadable, intentionally vulnerable virtual machines you run locally in VirtualBox or VMware. Working through boxes teaches enumeration, exploitation, and privilege escalation end to end, and most have public walkthroughs to check your approach against.

**Difficulty:** Intermediate | **Price:** Free

**Link:** https://www.vulnhub.com/

**Tags:** vulnerable-machines, ctf, privilege-escalation, home-lab, hands-on-practice

### 3. HackTricks

**Author:** Carlos Polop

Community-maintained open-source pentesting knowledge base by Carlos Polop, organized by methodology: pentesting network services by port, web vulnerabilities, Linux and Windows privilege escalation, Active Directory, and cloud, with concrete commands and checklists.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://book.hacktricks.wiki/

**Tags:** penetration-testing, privilege-escalation, web-security, active-directory, cheat-sheets

### 4. PortSwigger Web Security Academy

Free interactive web-hacking curriculum from the makers of Burp Suite, with written learning paths and over 250 deliberately vulnerable labs covering SQL injection, XSS, SSRF, authentication flaws, access control, and other web vulnerability classes.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://portswigger.net/web-security

**Tags:** web-security, burp-suite, sql-injection, xss, hands-on-labs, owasp

### 5. tryhackme.com

TryHackMe is an online cybersecurity training platform offering hands-on labs, guided learning paths, and real-world scenarios (rooms and challenges) to practice penetration testing, web security, and network defense in an interactive, gamified environment.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://tryhackme.com

**Tags:** websites, technology-computer-science, computer-sciences

### 6. pentesterlab.com

PentesterLab is an online platform offering hands-on penetration testing and web security labs. It provides guided, real-world exercises across web app vulnerabilities (e.g., SQL injection, XSS, CSRF, authentication flaws) with progress tracking and completion certificates.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://pentesterlab.com

**Tags:** websites, technology-computer-science, cybersecurity

## Youtubes

### 1. IppSec (YouTube)

**Author:** IppSec

Weekly full-length walkthroughs of retired Hack The Box machines showing a complete attack chain: enumeration, foothold, privilege escalation, and the reasoning behind each step. Several hundred videos, searchable by technique via the companion ippsec.rocks index.

**Difficulty:** Intermediate | **Language:** English | **Price:** Free

**Link:** https://www.youtube.com/@ippsec

**Tags:** hack-the-box, penetration-testing, walkthroughs, privilege-escalation, enumeration

## Books

### 1. The Web Application Hacker's Handbook, 2nd Edition

**Author:** Dafydd Stuttard, Marcus Pinto

Stuttard and Pinto's 900-page methodology for attacking web applications: mapping, bypassing client-side controls, authentication and session flaws, access control, injection, logic bugs, and a step-by-step testing checklist. Written by Burp Suite's creator.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/1118026470?tag=edmonddante07-20

**Tags:** web-security, penetration-testing, web-application-testing, injection-attacks, authentication

### 2. Penetration Testing: A Hands-On Introduction

**Author:** Georgia Weidman

A No Starch Press introduction to penetration testing built around a home lab of virtual machines. Covers reconnaissance, exploitation with Metasploit, password attacks, web and wireless attacks, post-exploitation, and basic exploit development, so readers can run a full assessment end to end.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/1593275641?tag=edmonddante07-20

**Tags:** penetration-testing, ethical-hacking, metasploit, kali-linux, exploitation

### 3. The Hacker Playbook 3

**Author:** Peter Kim

A practitioner's guide to red team engagements, organized like a game playbook from reconnaissance through lateral movement. Explains Active Directory attacks, evading endpoint defenses, privilege escalation, and post-exploitation, preparing readers to emulate realistic adversaries rather than run scanner-driven tests.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/1980901759?tag=edmonddante07-20

**Tags:** red-teaming, penetration-testing, active-directory, privilege-escalation, lateral-movement

### 4. Hacking Exposed: Network Security Secrets and Solutions

**Author:** Stuart McClure, Joel Scambray, George Kurtz

Long-running reference on network attack techniques, organized around the attacker's workflow: footprinting, scanning and enumeration, then exploitation of Windows, UNIX, remote-access and wireless systems, each paired with countermeasures. Readers learn how intrusions unfold so they can harden networks; some tool coverage is dated.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/0071613749?tag=edmonddante07-20

**Tags:** network-security, penetration-testing, ethical-hacking, network-attacks, countermeasures

### 5. Metasploit: The Penetration Tester’s Guide

**Author:** David Kennedy, Jim O'Gorman, Devon Kearns, Mati Aharoni

A No Starch Press guide to the Metasploit Framework by experienced penetration testers. Walks through intelligence gathering, vulnerability scanning, exploitation, Meterpreter, client-side attacks, and writing custom modules, so readers can use Metasploit across every phase of a penetration test.

**Difficulty:** Intermediate | **Language:** English | **Price:** Paid

**Link:** https://www.amazon.com/dp/159327288X?tag=edmonddante07-20

**Tags:** metasploit, penetration-testing, exploitation, meterpreter, vulnerability-scanning

---

*This content is part of Dantes.io - Your Treasure Map to Knowledge*

*Curated by humans at Dantes.io. Personal study use welcome; republishing this curation requires permission (team@dantes.io).*

View this page online: https://dantes.io/subject/penetration-testing