Build offensive security tools that go beyond simple scripts. BlackHat Ruby shows how to create scanners, fuzzers, protocol analyzers and exploit frameworks with clean, practical Ruby code. Along the way you'll see how these techniques work, where the legal boundaries are and how defenders spot and stop them.
AI-generated code can look flawless while hiding invented APIs, security gaps and subtle logic errors. This practical guide shows you how to build production-ready analyzers that catch what tests miss, from taint tracking and symbolic execution to custom rules for CI/CD and IDEs.
The Effective Bug Bounty Playbook teaches a systematic approach to finding high-impact vulnerabilities. Through real-world case studies and proven methodologies, you'll learn how to think like an experienced bug bounty hunter and uncover impactful security flaws more consistently.
APIs are the foundation of modern software and one of its most critical attack surfaces. API Security: A Definitive Reference for Building Secure APIs at Scale shows you how to build APIs that are secure by design, resilient under attack, and ready for production.
Here's a shorter version:Go beyond DNS lookups and build a high-performance recursive DNS resolver in Zig from the ground up. Through a hands-on implementation, you will master the protocols, algorithms, and systems programming techniques that power one of the internet's most essential services.
Master AArch64 assembly with a practical guide that covers ARM64 fundamentals, advanced instruction sets, performance optimization, debugging, and systems programming. From your first instructions to writing efficient low-level code, this book provides the knowledge and hands-on examples you need.
Offensive Security with Kali Linux is a practical guide to ethical hacking and penetration testing, taking you from foundational Linux and networking concepts to advanced exploitation techniques. With a strong emphasis on ethical practice and real-world methodology, you'll learn to identify vulnerabilities, assess systems responsibly, and strengthen security using Kali Linux.
Build a source-level debugger in Rust from the ground up while uncovering the operating system, CPU, and compiler mechanisms behind modern debugging. Through hands-on implementation, you'll learn how processes, memory, breakpoints, and DWARF debug information come together to make source-level debugging possible.
Discover how to uncover, preserve, and analyze digital evidence with confidence. From fundamental forensic principles to advanced investigative techniques, this practical guide combines hands-on exercises, real-world case studies, and industry-standard tools to help you conduct modern digital investigations with accuracy and credibility.
Master AWS incident response from CloudTrail to courtroom-ready evidence. Learn to acquire EC2 and container evidence, trace identity-based attacks, investigate S3 exfiltration, and build forensic readiness, all through three real-world incidents walked end to end.
Discover how software works beneath the surface with The Reverse Engineering Handbook. From assembly language and debugging to malware analysis, firmware, and AI-assisted techniques, this practical guide takes you from beginner to expert in understanding and deconstructing compiled software.
Cloud security is built, not bought. This practical guide goes beyond checklists and compliance to teach the engineering principles behind secure cloud environments. Learn how to design resilient identity systems, protect workloads, secure data, detect threats, and respond to incidents across AWS, Microsoft Azure, and Google Cloud using production-tested techniques and real-world architectures.
Master the complete lifecycle of authorized adversary emulation, from threat modeling and initial access through objective completion. Every offensive technique paired with detection and remediation, complete with ready-to-use templates for rules of engagement, ATT&CK mapping, and findings reports.
A practical, multi-cloud guide to securing AWS, Azure, and GCP workloads. Twelve chapters cover IAM hardening, CSPM/CWPP, IaC scanning, Kubernetes defense, and cloud incident response, each paired with runnable policies, scan configs, and detection rules you can put to work immediately.
Learn to investigate Windows, Linux, macOS, memory, network, and cloud evidence with the rigor courts and regulators expect. Packed with runnable tool examples (Volatility 3, Plaso, KAPE, The Sleuth Kit) and a full worked case study, this book turns forensic theory into repeatable, defensible practice.