Leanpub Header

Skip to main content

Offensive Security with Kali Linux

A Comprehensive Guide to Ethical Hacking and Penetration Testing

This book is 100% completeLast updated on 2026-07-14

Offensive Security with Kali Linux is a practical guide to ethical hacking and penetration testing, taking you from foundational Linux and networking concepts to advanced exploitation techniques. With a strong emphasis on ethical practice and real-world methodology, you'll learn to identify vulnerabilities, assess systems responsibly, and strengthen security using Kali Linux.

Minimum price

$19.00

$29.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
230
Pages
About

About

About the Book

This book takes you on a structured journey through the complete offensive security lifecycle, from foundational Linux and networking concepts to advanced exploitation techniques and professional reporting. Using Kali Linux as your primary platform, you will learn the theory behind every attack vector, the methodology for systematic assessment, and the practical skills needed to conduct authorized penetration tests. Every chapter builds upon previous material, ensuring that complex topics are grounded in solid fundamentals. The emphasis throughout is on ethical practice, defensive understanding, and responsible disclosure within legal, controlled environments.

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 400 engineers and researchers from Ukraine, Belarus and Russia. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

A Comprehensive Guide to Ethical Hacking and Penetration Testing

Introduction

  1. What This Book Is
  2. What This Book Is Not
  3. Who Should Read This Book
  4. How This Book Is Structured
  5. The Ethical Foundation
  6. Setting Up Your Lab
  7. A Note on Tool Evolution
  8. What Comes Next

Chapter 1: Foundations of Offensive Security

  1. What Is Offensive Security
  2. Historical Context: The Evolution of Offensive Security
  3. Common Pitfalls: Starting Your Offensive Security Journey
  4. The Penetration Testing Methodology
  5. Legal and Ethical Frameworks
  6. Rules of Engagement and Scoping
  7. Building Your Lab Environment
  8. Chapter Summary

Chapter 2: Kali Linux Fundamentals

  1. What Is Kali Linux
  2. Historical Context: From WHAX to Kali
  3. Installation and Deployment Options
  4. Essential Command Line Skills
  5. File System and Permissions
  6. Package Management and Updates
  7. Networking Configuration
  8. Chapter Summary

Chapter 3: Networking Fundamentals for Security Professionals

  1. The OSI Model and Packet Flow
  2. Historical Context: How Network Protocols Evolved
  3. TCP/IP Protocol Suite
  4. Essential Network Protocols
  5. Subnetting and Addressing
  6. Network Architecture and Security Zones
  7. Common Network Services and Ports
  8. Chapter Summary

Chapter 4: Information Gathering and Reconnaissance

  1. Passive vs Active Reconnaissance
  2. Historical Context: The Reconnaissance Evolution
  3. Open Source Intelligence (OSINT) Methodology
  4. Domain and DNS Enumeration
  5. Network Mapping Techniques
  6. Building the Target Profile
  7. Tool Spotlight: Maltego, theHarvester, and Recon-ng
  8. Chapter Summary

Chapter 5: Scanning and Enumeration

  1. Port Scanning Techniques
  2. Nmap: The Scanner’s Swiss Army Knife
  3. Historical Context: Nmap’s Development Journey
  4. Service Enumeration Strategies
  5. OS Fingerprinting Methods
  6. Extracting Intelligence from Scan Results
  7. Tool Spotlight: Masscan, Zmap, and RustScan
  8. Chapter Summary

Chapter 6: Vulnerability Analysis

  1. Understanding Vulnerabilities and CVEs
  2. Historical Context: How Vulnerability Management Evolved
  3. Automated Vulnerability Scanning
  4. Manual Vulnerability Verification
  5. Risk Prioritization Frameworks
  6. Tool Spotlight: OpenVAS, Nessus, and Vulners
  7. From Vulnerability to Exploit Path
  8. Chapter Summary

Chapter 7: Web Application Security

  1. Web Application Architecture
  2. Historical Context: The Evolution of Web Application Security
  3. The OWASP Top Ten Threats
  4. Injection Attacks
  5. Authentication and Session Vulnerabilities
  6. Server-Side Vulnerabilities
  7. Tool Spotlight: Burp Suite, SQLmap, and Nikto
  8. Chapter Summary

Chapter 8: Wireless Security Assessment

  1. Wireless Network Fundamentals
  2. Wi-Fi Protocols and Encryption Standards
  3. Historical Context: The Evolution of Wi-Fi Security
  4. Common Wireless Attack Vectors
  5. Wireless Assessment Methodology
  6. Tool Spotlight: Aircrack-ng Suite and Wifite
  7. Common Pitfalls: Wireless Assessment Mistakes
  8. Troubleshooting: Wireless Assessment Issues
  9. Securing Wireless Networks
  10. Chapter Summary

Chapter 9: Active Directory Security Concepts

  1. Active Directory Architecture
  2. Historical Context: Active Directory and Its Attack Surface
  3. Common Pitfalls: Active Directory Assessment Mistakes
  4. Common Attack Paths in Active Directory
  5. Kerberos Protocol and Attacks
  6. Lateral Movement Concepts
  7. Privilege Escalation in Active Directory
  8. Tool Spotlight: BloodHound, CrackMapExec, and Impacket
  9. Chapter Summary

Chapter 10: Exploitation Fundamentals

  1. The Exploitation Lifecycle
  2. Vulnerability Research Methodology
  3. Payload Development Concepts
  4. Meterpreter and Post-Exploitation Frameworks
  5. Tool Spotlight: Metasploit Framework
  6. Historical Context: Metasploit’s Journey
  7. Common Pitfalls: Exploitation Assessment Mistakes
  8. Troubleshooting: Exploitation Issues
  9. From Exploit to Reportable Finding
  10. Chapter Summary

Chapter 11: Password Security Assessment

  1. Hashing Algorithms and Password Storage
  2. Historical Context: The Evolution of Password Hashing
  3. Offline Cracking Methodologies
  4. Online Attack Techniques
  5. Rainbow Tables and Precomputation
  6. Tool Spotlight: John the Ripper and Hashcat
  7. Evaluating Password Policies
  8. Chapter Summary

Chapter 12: Privilege Escalation Concepts

  1. Understanding Privilege Levels
  2. Historical Context: The Privilege Escalation Landscape
  3. Linux Privilege Escalation Techniques
  4. Windows Privilege Escalation Techniques
  5. Common Misconfiguration Patterns
  6. Tool Spotlight: LinPEAS, WinPEAS, and PowerUp
  7. Common Pitfalls: Privilege Escalation Assessment Mistakes
  8. Defending Against Privilege Escalation
  9. Chapter Summary

Chapter 13: Scripting and Automation for Security Professionals

  1. Why Scripting Matters in Security
  2. Historical Context: The Evolution of Security Automation
  3. Bash Scripting for Security Tasks
  4. Python for Security Automation
  5. Building Custom Enumeration Scripts
  6. Automating the Assessment Workflow
  7. Integrating Tools into Pipelines
  8. Common Pitfalls: Scripting and Automation Mistakes
  9. Troubleshooting: Common Scripting Issues
  10. Chapter Summary

Chapter 14: Reporting and Operational Best Practices

  1. The Importance of Professional Reporting
  2. Historical Context: The Evolution of Security Reporting
  3. Evidence Collection and Documentation
  4. Executive and Technical Report Structure
  5. Operational Security During Engagements
  6. Tool Management and Maintenance
  7. Common Pitfalls: Reporting and Engagement Mistakes
  8. Case Study: From Technical Finding to Business Impact
  9. Chapter Summary

Conclusion

Glossary

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub