· 3 min read
Top 100 Hacking Books
A hundred books on offensive security, reverse engineering, network defence and forensics — assembled in 2018 from the titles that came up most often when practitioners were asked what they actually learned from.
This is a reading list, nothing more. There are no downloads here. Every one of these is in print or sold as an ebook by its publisher, and that is where they should come from — the people who wrote them are largely the same community the list is aimed at. The earlier version of this page linked to scanned copies on third-party hosts; those links are gone and will not be coming back.
Titles are listed as originally recorded, so a few are now several editions out of date. Check for a current edition before buying — in this field a 2016 book on tooling ages faster than one on fundamentals. For what I am reading now, see the library.
1. Advanced Penetration Testing Hacking 2017
2. CEH v9 Certified Ethical Hacker Version 9
3. Begin Ethical Hacking with Python
4. Certified Ethical Hacker 2016
5. Essential Skills for Hackers
6. Hacking 2016
7. Hacking the Hacker 2017
8. The Art of Invisibility 2017
9. Penetration Testing Basics
10. Penetration Testing Essentials 2017
11. Security
12. Hackers Beware
13. Network Performance and Security
14. Advanced_Persistent_Threat_Hacking
15. Modern Web Penetration Testing 2016
16. From Hacking to Report Writing
17. Python Web Penetration Testing Cookbook
18. CompTIA Cybersecurit 2017
18.IT final
19. Wireshark for Security Professionals 2016
20. Cyber-Physical Attack Recover
21. Honeypots and Routers_ Collecting Internet Attacks
22. Practical Information Security Management 2016
23. Phishing Dark Waters
24. Network Attacks and Exploitation
25. A Hacker
26. Hacker School
27. Automated Credit Card Fraud
28. A Beginners Guide To Hacking Computer Systems
29. 501 Website Hacking Secrets
30. Cracking Passwords Guide
31. Eldad Eilam – Reversing: Secrets of Reverse Engineering – Wiley 2005
32. Metasploit Toolkit – Presentation
33. Metasploit Toolkit – Syngress
34. Oracle Rootkits 2.0
35. Pest Control – Taming the RATS
36. Practical Malware Analysis
37. Return Oriented Programming
38. Web App Hacking (Hackers Handbook)
39. The Basics of Web Hacking – Tools and Techniques to Attack the Web(2013)
40. Syngress – Sockets, Shellcode, Porting & Coding – Reverse Engineering Exploits And Tool Coding For Security Professionals
41. Stack Smashing
42. SQL Injection Attacks and Defense
43. Reverse Engineering for Beginners
44. Black Book of Viruses and Hacking
45. Bluepilling the Xen Hypervisor
46. Computer Viruses, Hacking and Malware attacks for Dummies
47. Cracking Passwords Guide
48. Hackers_Secrets
49. Buffer Overflow Attacks
50. Exploiting Software – How To Break Code
51. Grumpy Old Fart’s Big Book of Hacking
53. Comptia Security+
54. Hack Attacks Revealed
55. Hacking Exposed (Laxxuss)
56. Hacking For Dummies (2004) Wiley
57. Hacking For Dummies – Access To Other Peoples Systems Made Simple
58. Hacking Into Computer Systems – A Beginners Guide
59. How To Hack Windows Xp Admin Passwords
61. ETH – Attacks on P2P Networks (Freenet) (2005)
62. Francisco Amato – evilgrade – ENG
67. KALI-LINUX-COMMANDS
68. DEFCON-24-Anto-Joseph-Fuzzing-Android-Devices
69. DEFCON-24-Bigezy-Saci-Pinworm-MITM-for-Metadata
70. DEFCON-24-Brad-Dixon-Pin2Pwn-How-to-Root-An-Embedded-Linux-Box-With-A-Sewing-Needle
71. DEFCON-24-Brad-Woodberg-Malware-Command-And-Control-Channels-A-Journey-Into-Darkness
72. DEFCON-24-Bryant-Zadegan-Ryan-Lester-Abusing-Bleeding-Edge-Web-Standards-For-Appsec-Glory
73. DEFCON-24-Chapman-Stone-Toxic-Proxies-Bypassing-HTTPS-and-VPNs
74. DEFCON-24-Demay-Auditing-6LoWPAN-Networks-Using-Standard-Penetration-Testing-Tools-WP
75. DEFCON-24-Demay-Auditing-6LoWPAN-Networks-Using-Standard-Penetration-Testing-Tools
76. DEFCON-24-Fitzpatrick-and-Grand-101-Ways-To-Brick-Your-Hardware
77. DEFCON-24-Seymour-Tully-Weaponizing-Data-Science-For-Social-Engineering
78. DEFCON-24-Thomas-Wilhelm-Hacking-Network-Protocols-Using-Kali
79. DEFCON-24-Thomas-Wilhelm-Intrusion-Prevention-System-Evasion-Techniques
80. DEFCON-24-Ulf-Frisk-Direct-Memory-Attack-the-Kernel
81. EN-Hacking Web Applications Using Cookie Poisoning
82. EN – NoSQL, No injection – Ron, Shulman-Peleg, Bronshtein
83. Ethical Hacking and Penetration Testing Guide – Baloch, Rafay
84. Faille-CSRF
85. Metasploit, Penetration Testers Guide
86. Next Generation Web Attacks – HTML 5, DOM(L3) and XHR(L2)
87. Ninja Hacking
88. OWASP_Stammtisch_Frankfurt_WAF_Profiling_and_Evasion
89. Pentesting With Burp Suite
90. Phishing Dark Waters The Offensive and Defensive Sides of Malicious Emails
91. Seven Deadliest Network Attacks
92. Seven Deadliest USB Attacks
93. Seven Deadliest USB Attacks
94. Seven Deadliest Web Application Attacks
95. Seven Deadliest Wireless Technologies Attacks
96. The 60 Minute Network Security Guide, National Security Agency
97. The Basics of Hacking and Penetration
98. WAF Bypassing
99. Windows_Services_-_All_roads_lead_to_SYSTEM
100. Web Penetration Testing with Kali Linux