Skip to content

Latest commit

Β 

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Awesome Cybersecurity Books

A curated, structured shelf of 70+ cybersecurity, hacking, and supporting fundamentals organized by domain and difficultyβ€”no paywall required.

GitHub stars GitHub forks License Last Commit Contributors


πŸ“‚ Direct Drive Library Access

πŸ‘‰ Access Full Google Drive Library Folder

πŸ“ Pair this library with our hands-on Penetration Testing Roadmap (500+ free labs, OWASP Top 10, weekly curriculum).

πŸ’¬ Join the Discussion: πŸ›‘οΈ Welcome to awesome-cybersecurity-books Discussions! || πŸ’‘ Book Suggestions & Missing Gems


⚑ Why This Library?

Unlike flat "awesome lists" that dump hundreds of unsorted links, this repository provides a guided, battle-tested curriculum:

  • πŸ“Š Ordered by Difficulty: Within every domain, books progress strictly from 🟒 Beginner β†’ 🟑 Intermediate β†’ πŸ”΄ Advanced.
  • πŸ—ΊοΈ Structured Learning Roadmap: Clear progression paths depending on your career goals (Red Team, Blue Team, Reverse Engineering, Web Security).
  • πŸ”“ 100% Free Self-Study: Designed so anyone can start from scratch without hitting a paywall.
  • 🀝 Community Maintained: Living list continuously updated by security researchers and practitioners.

πŸ—ΊοΈ Visual Learning Path

graph TD
    A["πŸ”° 0. Supporting / Prerequisites<br/>(Python, C, Linux, Networking, HTML/CSS)"] --> B["πŸ“˜ 1. Foundations & Mindset<br/>(Ethical Hacking Intro, Security Playbook)"]
    
    B --> C1["🌐 Track A: Web Security"]
    B --> C2["βš”οΈ Track B: Red Teaming"]
    B --> C3["πŸ”¬ Track C: Exploit & RE"]
    B --> C4["πŸ›‘οΈ Track D: Defense & IR"]

    C1 --> D1["🟒 Web Hacking 101<br/>🟑 WAHH & OWASP Guide<br/>πŸ”΄ Browser Hacker's Handbook"]
    C2 --> D2["🟒 Basics of Pentesting<br/>🟑 Hacker Playbook 3<br/>πŸ”΄ Advanced Pentesting & Metasploit"]
    C3 --> D3["🟒 Art of Exploitation<br/>🟑 Shellcoder's Handbook<br/>πŸ”΄ Practical Malware Analysis & RE"]
    C4 --> D4["🟒 Cybersecurity Playbook<br/>🟑 Network Security Monitoring<br/>πŸ”΄ Antivirus Hacker's Handbook"]

    D1 --> E["πŸ† Research & Mastery"]
    D2 --> E
    D3 --> E
    D4 --> E
Loading

πŸ“Œ Legend & Difficulty Tags

  • 🟒 Beginner: Accessible entry point. Requires minimal prior security background.
  • 🟑 Intermediate: Requires solid networking, operating systems, or programming literacy.
  • πŸ”΄ Advanced: Low-level internals, assembly, kernel manipulation, and complex vulnerability engineering.

πŸ“‹ Table of Contents

  1. Supporting / Prerequisite Resources (11 Books)
  2. Foundations / General Cybersecurity & Mindset (5 Books)
  3. Penetration Testing / Red Team Methodology (5 Books)
  4. Web Application Security & Bug Bounties (10 Books)
  5. Network Security & Monitoring (4 Books)
  6. Exploit Development & Binary / Memory Vulnerabilities (8 Books)
  7. Reverse Engineering & Malware Analysis (6 Books)
  8. Mobile Application Security (4 Books)
  9. Cryptography (2 Books)
  10. Defensive Security / Incident Response (3 Books)
  11. Programming & Secure Coding (6 Books)
  12. Scripting, Tooling & Automation (7 Books)
  13. Browser & Client-Side Security (4 Books)
  14. Social Engineering & Human Factors (2 Books)
  15. Specialized / Miscellaneous Extras (5 Books)
  16. Suggested Learning Path
  17. Contributing

0. Supporting / Prerequisite Resources (11 Books)

πŸ“– Detailed Track Guide: docs/prerequisites.md

Tackle these first if any fundamental category feels unfamiliar; they shorten the time required to appreciate the security-focused titles.

Programming Fundamentals

  • 🟒 Python Crash Course by Eric Matthes β€” Approachable way to build the scripting foundation you will reuse everywhere.
  • 🟒 Python Notes for Professionals (GoalKicker) β€” Quick-reference companion while practicing Python.
  • 🟑 The C Programming Language (2nd Edition) by Kernighan & Ritchie β€” Essential systems-level literacy required for low-level security work.
  • 🟑 C++ for Hackers by Steve Oualline β€” Extends C foundations into modern C++ with a security mindset.

Operating Systems & Linux

  • 🟒 Linux Basics for Hackers by OccupyTheWeb β€” Command-line, permissions, networking, and security toolchain essentials.
  • 🟑 Linux Command Line and Shell Scripting Bible by Richard Blum & Christine Bresnahan β€” Deeper shell automation and scripting coverage.
  • πŸ”΄ Linux System Programming by Robert Love β€” Bridges user space, system calls, and kernel interactions.

Networking Fundamentals

  • 🟒 CCNA 200-301 Official Cert Guide by Wendell Odom β€” Structured walkthrough of networking core concepts (TCP/IP, routing, switching).
  • 🟑 TCP/IP in C by Michael J. Donahoo & Kenneth L. Calvert β€” Applies networking theory directly through C sockets code.

Web Fundamentals

  • 🟒 HTML & CSS: Design and Build Websites by Jon Duckett β€” Front-end basics that clarify web attack surfaces.
  • 🟑 HTML5 Canvas by Steve Fulton & Jeff Fulton β€” Interactive graphics surface insights for client-side exploits.

1. Foundations / General Cybersecurity & Mindset (5 Books)

πŸ“– Detailed Track Guide: docs/foundations.md

  • 🟒 The Cybersecurity Playbook by Allison Cerra β€” Programmatic, operational, and managerial perspective for defenders.
  • 🟒 The Basics of Hacking and Penetration Testing by Patrick Engebretson β€” Practical first steps into penetration testing workflows.
  • 🟒 Ethical Hacking: A Hands-on Introduction to Breaking In by Daniel G. Graham β€” Lab-driven entry point to ethical hacking.
  • 🟑 CEH v10 by Ric Messier β€” Certification-friendly overview across core security domains.
  • 🟑 Ethical Hacking: Techniques, Tools, and Countermeasures by Michael G. Solomon & Sean-Philip Oriyano β€” Practical defense-aware offensive techniques.

2. Penetration Testing / Red Team Methodology (5 Books)

πŸ“– Detailed Track Guide: docs/penetration-testing.md

  • 🟒 Coding for Penetration Testers by Jason Andress & Ryan Linn β€” Building custom scripting tooling in support of security engagements.
  • 🟑 Metasploit: The Penetration Tester's Guide by David Kennedy et al. β€” Tool-driven exploitation methodologies and framework usage.
  • 🟑 The Hacker Playbook 3: Practical Guide to Penetration Testing by Peter Kim β€” Playbook approach to planning and executing modern offensive engagements.
  • 🟑 Hacking: The Art of Exploitation (2nd Edition) by Jon Erickson β€” Foundational exploitation concepts with C and assembly hands-on labs.
  • πŸ”΄ Advanced Penetration Testing (Wiley) β€” Red-team tradecraft, complex adversary simulation, and stealth methodology.

3. Web Application Security & Bug Bounties (10 Books)

πŸ“– Detailed Track Guide: docs/web-security.md

  • 🟒 Web Hacking 101 by Peter Yaworski β€” Gentle intro to web vulnerabilities and bug bounty hunting case studies.
  • 🟒 All About SQL by GoalKicker / Community β€” Baseline database knowledge required to understand relational targets.
  • 🟑 Real-World Bug Hunting by Peter Yaworski β€” Modern web bug bounty case studies, reconnaissance, and exploitation strategies.
  • 🟑 The Web Application Hacker's Handbook by Dafydd Stuttard & Marcus Pinto β€” Deep-dive testing methodology for web apps.
  • 🟑 OWASP Testing Guide (v2 / v3 / v4) by OWASP Foundation β€” Community standard checklists and methodology for consistent web assessments.
  • 🟑 Blind SQL Injection by Kevin Spett β€” Handling blind, time-based, and out-of-band database exploitation.
  • πŸ”΄ The Browser Hacker's Handbook by Wade Alcorn et al. β€” Browser internals, DOM manipulation, and client-side exploitation.
  • πŸ”΄ Advanced SQL Injection by Justin Seitz β€” Evasion techniques, filter bypasses, and advanced payload strategies.
  • πŸ”΄ XSS Sheet by Rodolfo Assis β€” Payload reference and edge cases for client-side injection attacks.
  • πŸ”΄ WEB_HACKING by Dafydd Stuttard & Marcus Pinto β€” Companion reference covering advanced web application attack scenarios.

4. Network Security & Monitoring (4 Books)

πŸ“– Detailed Track Guide: docs/network-security.md

  • 🟒 CCNA 200-301 Official Cert Guide by Wendell Odom β€” Core networking foundations to anchor packet analysis and monitoring.
  • 🟑 The Practice of Network Security Monitoring by Richard Bejtlich β€” Intrusion detection, SOC operations, and network-centric defense.
  • 🟑 TCP/IP in C by Michael J. Donahoo & Kenneth L. Calvert β€” Low-level network programming with TCP/IP protocol internals.
  • 🟑 Sockets in C by Panagiota Fatourou & Eleftherios Kosmas β€” Socket patterns for security tooling and network exploit development.

5. Exploit Development & Binary / Memory Vulnerabilities (8 Books)

πŸ“– Detailed Track Guide: docs/exploit-development.md

  • 🟒 Linux Stack Based Buffer Overflow Exploitation by Saif El-Sherei β€” Step-by-step Linux stack overflow walkthroughs.
  • 🟑 Buffer Overflow Exploitation by Chester Rebeiro β€” Practical overflow walk-throughs and memory execution flow control.
  • 🟑 Hacking: The Art of Exploitation by Jon Erickson β€” Low-level C programming, stack manipulation, and shellcode construction.
  • 🟑 Linux Assembly by Jeff Duntemann β€” Assembly primer tailored specifically to Linux environments.
  • πŸ”΄ The Shellcoder's Handbook by Chris Anley et al. β€” Advanced shellcode craft, vulnerability classes, and architecture bypasses.
  • πŸ”΄ The Art of High Level Assembly by Randall Hyde β€” Advanced assembly programming techniques for security analysts.
  • πŸ”΄ OS Dev by Nick Blundell β€” Bare-metal operating system development concepts.
  • πŸ”΄ Linux System Programming by Robert Love β€” System calls, kernel interface background, and memory management for exploit writers.

6. Reverse Engineering & Malware Analysis (6 Books)

πŸ“– Detailed Track Guide: docs/malware-analysis.md

  • 🟒 Practical Malware Analysis by Michael Sikorski & Andrew Honig β€” The gold-standard hands-on lab series for malware dissection.
  • 🟑 The Android Malware Handbook by Qian Han et al. β€” Mobile-focused reverse engineering and Android malware analysis.
  • 🟑 The Art of Computer Virus Research and Defense by Peter Szor β€” Theoretical and historical grounding in virus construction and defense.
  • πŸ”΄ Practical Reverse Engineering by Bruce Dang et al. β€” Covers x86, x64, ARM, Windows Kernel, and reverse engineering toolchains.
  • πŸ”΄ The Antivirus Hacker's Handbook by Joxean Koret & Elias Bachaalany β€” Antivirus internals, engine architecture, and evasion strategies.
  • πŸ”΄ Practical Malware Analysis (Hands-on Lab Edition) by Michael Sikorski & Andrew Honig β€” Alternate reference guide covering lab execution and sample isolation.

7. Mobile Application Security (4 Books)

πŸ“– Detailed Track Guide: docs/mobile-security.md

  • 🟒 Hacking Android by Srinivasa Rao Koti β€” Hands-on Android exploitation projects and setup.
  • 🟑 The Mobile Application Hacker's Handbook by Dominic Chell et al. β€” Mobile application security testing methodology (iOS & Android).
  • 🟑 The Android Malware Handbook by Qian Han et al. β€” Android malware reverse engineering, unpacking, and dynamic analysis.
  • πŸ”΄ Android Hacker's Handbook by Joshua J. Drake et al. β€” Deep platform internals, kernel drivers, and Android exploit paths.

8. Cryptography (2 Books)

πŸ“– Detailed Track Guide: docs/cryptography.md

  • 🟑 Cryptography in C and C++ (2nd Edition) by Michael Welschenbach β€” Implementation guidance bridging mathematical theory to code.
  • πŸ”΄ Applied Cryptography by Bruce Schneier β€” Classic treatise blending cryptographic protocols, algorithms, and real-world usage.

9. Defensive Security / Incident Response (3 Books)

πŸ“– Detailed Track Guide: docs/defensive-security.md

  • 🟒 The Cybersecurity Playbook by Allison Cerra β€” Incident response planning, organizational defense, and SOC runbooks.
  • 🟑 The Practice of Network Security Monitoring by Richard Bejtlich β€” Threat hunting, continuous monitoring, and detection engineering.
  • πŸ”΄ Pair Practical Malware Analysis by Michael Sikorski & Andrew Honig with The Antivirus Hacker's Handbook by Joxean Koret & Elias Bachaalany for end-to-end incident investigation.

10. Programming & Secure Coding (6 Books)

πŸ“– Detailed Track Guide: docs/programming-secure-coding.md

  • 🟒 The C Programming Language (2nd Edition) by Kernighan & Ritchie β€” Foundational C literacy for security engineers.
  • 🟒 Programmer's Guide to NCurses by Dan Gookin β€” System programming UI utilities.
  • 🟑 C++ for Hackers by Steve Oualline β€” C++ programming concepts framed specifically for security practitioners.
  • 🟑 Best Book to Master C++ Programming by Bjarne Stroustrup β€” Comprehensive deep dive into standard C++.
  • 🟑 Sockets in C by Panagiota Fatourou & Eleftherios Kosmas β€” Network socket programming utilities and secure I/O.
  • πŸ”΄ Advanced Data Structures in C++ by Peter Brass β€” Algorithmic grounding for low-level optimization and research.

11. Scripting, Tooling & Automation (7 Books)

πŸ“– Detailed Track Guide: docs/scripting-automation.md

  • 🟒 50 Useful Python Scripts by GoalKicker / Community β€” Small, actionable automation examples for daily security workflows.
  • 🟒 Python Crash Course by Eric Matthes β€” Beginner-friendly Python scripting primer.
  • 🟒 Python Notes for Professionals (GoalKicker) β€” Reference-style recap of core language features.
  • 🟒 Coding Games in Python by DK Publishing β€” Fun practice-heavy scripting reinforcement.
  • 🟑 Black Hat Python by Justin Seitz & Tim Arnold β€” Offensive Python automation, raw sockets, and payload crafting.
  • 🟑 Black Hat Bash by Dolev Farhi & Nick Aleks β€” Shell scripting for offensive and defensive automation scenarios.
  • 🟑 Python Complete Notes by QuantInsti β€” Advanced scripting and data manipulation reference.

12. Browser & Client-Side Security (4 Books)

πŸ“– Detailed Track Guide: docs/browser-security.md

  • 🟒 HTML, CSS: Design and Build Websites by Jon Duckett β€” Front-end presentation fundamentals.
  • 🟑 HTML5 Canvas by Steve Fulton & Jeff Fulton β€” Graphics internals and scriptable attack surfaces.
  • 🟑 The Web Application Hacker's Handbook by Dafydd Stuttard & Marcus Pinto & XSS Sheet by Rodolfo Assis β€” Practical payload design and DOM analysis.
  • πŸ”΄ The Browser Hacker's Handbook by Wade Alcorn et al. β€” Central authority on browser sandboxes, extensions, and client-side exploits.

13. Social Engineering & Human Factors (2 Books)

πŸ“– Detailed Track Guide: docs/social-engineering.md

  • 🟒 Social Engineering: The Art of Human Hacking by Christopher Hadnagy β€” Reconnaissance, influence, and physical tactics.
  • 🟑 The Science of Human Hacking by Chris Hadnagy β€” Data-driven perspective and psychological mechanics of social engineering.

14. Specialized / Miscellaneous Extras (5 Books)

πŸ“– Detailed Track Guide: docs/specialized-extras.md

  • 🟒 VS Code Shortcuts by Microsoft Docs / Community β€” Productivity guide for building security tools and writing scripts quickly.
  • 🟒 Top 40 Python Interview Questions & Answers by Community Reference β€” Technical interview preparation for security/developer roles.
  • 🟑 Real-World Bug Hunting by Peter Yaworski & Web Hacking 101 by Peter Yaworski β€” Applied bounty hunting stories and methodology.
  • 🟑 Metasploit: The Penetration Tester's Guide by David Kennedy et al. & The Hacker Playbook 3 by Peter Kim β€” Offensive toolsets and engagement runbooks.
  • πŸ”΄ The Antivirus Hacker's Handbook by Joxean Koret & Elias Bachaalany & The Art of Computer Virus Research and Defense by Peter Szor β€” Advanced malware and security software research.

15. Suggested Learning Path

Phase 1: Prerequisites & Foundations (1–2 Months)

  1. Networking: Start with CCNA 200-301 or the overview in TCP/IP in C.
  2. Linux: Master command-line basics using Linux Basics for Hackers.
  3. Scripting: Build your automation base with Python Crash Course.

Phase 2: Choose Your Primary Track (2–4 Months)

Track A: Web Application Security / Bug Bounties

  • Web Hacking 101 βž” Real-World Bug Hunting βž” The Web Application Hacker's Handbook βž” OWASP Testing Guide

Track B: Penetration Testing / Red Teaming

  • Basics of Hacking & Pentesting βž” The Hacker Playbook 3 βž” Metasploit Guide βž” Advanced Penetration Testing

Track C: Exploit Development & Reverse Engineering

  • The C Programming Language βž” Hacking: Art of Exploitation βž” Shellcoder's Handbook βž” Practical Reverse Engineering βž” Practical Malware Analysis

Track D: Defensive Security / SOC Analyst

  • Cybersecurity Playbook βž” Practice of Network Security Monitoring βž” Practical Malware Analysis

Contributing

Contributions are warmly welcomed! Please see our CONTRIBUTING.md guide before submitting suggestions or Pull Requests.

Please review our Code of Conduct and Security Policy.


πŸ“œ License

This curated educational repository is distributed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). See LICENSE for details.

Knowledge should be free and accessible to all. Happy studying!

About

A curated collection of 70+ free cybersecurity books organized by domain and difficulty (🟒 Beginner β†’ 🟑 Intermediate β†’ πŸ”΄ Advanced). Structured learning paths for ethical hacking, penetration testing, exploit development, malware analysis, web security, and more. No paywall. Community maintained.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

44 stars

Watchers

0 watching

Forks

Releases

Contributors