Must Have Security Books
(In No Order of Preference. Hover over links for book previews)
Penetration Testing
- Penetration Tester’s Open Source Toolkit, Vol. 2
- Dissecting the Hack: The F0rb1dd3n Network, Revised Edition
- Ninja Hacking: Unconventional Penetration Testing Tactics and Techniques
- Hacking: The Next Generation (Animal Guide)
- Gray Hat Hacking, Second Edition: The Ethical Hacker’s Handbook
- Google Hacking for Penetration Testers
- Professional Pen Testing for Web Applications (Programmer to Programmer)
- WarDriving and Wireless Penetration Testing
- The Hacker’s Handbook: The Strategy Behind Breaking into and Defending Networks
Building a Security Lab
Professional Penetration Testing by Richard is good starting point for most of the average professional out there to start and operate a formal hacking and pentesting lab. For advanced folks, some chapters may be little generic but nevertheless provides good dos and don’ts while designing a lab. Both the books will help you to achive:
- If you already having some bit of pentesting and skills, you can turn it into a serious business!
- Learn to carry out attacks in a controlled enviroment with plenty of examples.
- Understand the basic project management skills required to gear up for a ethical hacking business.
- Security metrics which provides meaningful insights to findings and the pentest report.
- Professional Penetration Testing: Creating and Operating a Formal Hacking Lab
- Build Your Own Security Lab: A Field Guide for Network Testing
Application Security Books
- The Web Application Hacker’s Handbook: Discovering and Exploiting Security Flaws
- Web Application Vulnerabilities: Detect, Exploit, Prevent
- Foundations of Security: What Every Programmer Needs to Know (Expert’s Voice)
- Hacking Exposed Web Applications, 3rd Edition
- Seven Deadliest Web Application Attacks (Syngrass Seven Deadlest Attacks)
- Software Security: Building Security In
- The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities
- The Database Hacker’s Handbook: Defending Database Servers
- Web 2.0 Security – Defending AJAX, RIA, AND SOA
- Web Services Security
- Gray Hat Python: Python Programming for Hackers and Reverse Engineers
- SQL Injection Attacks and Defense
Network Security Books
- Z4ck – Bypass Any Network Security!
- Network Security Essentials: Applications and Standards (4th Edition)
- Counter Hack Reloaded: A Step-by-Step Guide to Computer Attacks and Effective Defenses (2nd Edition)
- Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning
- Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition
- Seven Deadliest Network Attacks (Syngress Seven Deadliest Attacks)
Exploitation and Vulnerability Research Books
- The Shellcoder’s Handbook: Discovering and Exploiting Security Holes
- Reversing: Secrets of Reverse Engineering
- The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System
- Hacking: The Art of Exploitation, 2nd Edition
- Malware Analyst’s Cookbook and DVD: Tools and Techniques for Fighting Malicious Code
- Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research
- The Mac Hacker’s Handbook
- Rootkits: Subverting the Windows Kernel
- The IDA Pro Book: The Unofficial Guide to the World’s Most Popular Disassembler
- Exploiting Software: How to Break Code
- Advanced Windows Debugging
Cryptography Books
- Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition
- Cryptography Engineering: Design Principles and Practical Applications
- Cryptography Demystified
General Security Management
- Information Security: Principles and Practices
- Corporate Computer and Network Security (2nd Edition)
- Security Policies and Procedures: Principles and Practices
- Managing Information Security
Certification Books
- CISSP All-in-One Exam Guide, Fifth Edition
- Official (ISC)2 Guide to the CISSP CBK, Second Edition ((ISC)2 Press)
- Mike Meyers’ CISSP(R) Certification Passport
- CEH Certified Ethical Hacker Study Guide
- The Official CHFI Study Guide (Exam 312-49): for Computer Hacking Forensic Investigator
- Ethical Hacking Official Guide from EC Council
- CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide












