Library
The 20 books the curriculum cites, one page each. Every page says what the book is actually about, works through the chapters a module points at, and ends with what to take into a challenge and where the book stops being useful for that.
These are notes, not reviews and not summaries that let you skip the book. Nothing here is affiliate-linked, sponsored or sold by us, and no page reproduces the text it describes. A module cites a chapter; this is where that citation goes.
Method
How to look at a system at all, before any particular bug class.
- 2024No Starch Press2 modules
Black Hat Bash
Dolev Farhi and Nick Aleks
The book to read once you are on the box. Its enumeration and privilege-escalation chapters are a checklist you can run by hand.
Read the notes - 2021No Starch Press9 modules
Designing Secure Software
Loren Kohnfelder
The book to read when you want to know what the primitive was supposed to promise, so you can see which promise the challenge broke.
Read the notes - 2024No Starch Press2 modules
Hacks, Leaks, and Revelations
Micah Lee
The only book here about scale. Read it when the challenge is not one file but a directory tree you cannot possibly read.
Read the notes - 2025No Starch Press1 module
Practical AI Security
Harriet Farlow
The reference for the prompt-injection challenge category, and the book that explains why it is an attack rather than a conversation.
Read the notes
Web and applications
The request, the parser behind it, and the trust the application places in both.
- 2021No Starch Press8 modules
Bug Bounty Bootcamp
Vickie Li
One chapter per web bug class, each ending in a numbered hunting procedure. The closest thing here to a web category walkthrough.
Read the notes - 2022No Starch Press4 modules
Hacking APIs
Corey Ball
Read it when the challenge has no user interface. Everything it covers is a bug in the layer under the page.
Read the notes - 2006Microsoft Press4 modules
Hunting Security Bugs
Tom Gallagher, Bryan Jeffries, and Lawrence Landauer
Old, unfashionable and unusually thorough. Its canonicalization chapter explains a bug class that most modern books mention in one paragraph.
Read the notes - 2019No Starch Press3 modules
Real-World Bug Hunting
Peter Yaworski
Case studies rather than theory. Read it for the noticing, which is the part no methodology teaches.
Read the notes
Cryptography and protocols
What the primitives promise, and what a protocol does with them.
- 2017No Starch Press5 modules
Attacking Network Protocols
James Forshaw
The book that explains why a strange binary blob still has recognisable shape: length prefixes, tag-length-value, endianness, framing.
Read the notes - 2020No Starch Press6 modules
Black Hat Go
Tom Steele, Chris Patten, and Dan Kottmann
The book for building the tool rather than running one. Its crypto chapter is the fastest cure for treating a cipher as a black box.
Read the notes
Forensics and malware
Disks, memory, captures and samples: reading what happened out of what was left.
- 2023No Starch Press1 module
Evading EDR
Matt Hand
Read it as a defender to know what your telemetry actually covers, or as an analyst to know which artefact a given event came from.
Read the notes - 2024No Starch Press3 modules
Evasive Malware
Kyle Cucci
The book for a sample that behaves differently when you watch it. Also the best single account of why a binary is full of unreadable bytes.
Read the notes - 2018No Starch Press2 modules
Malware Data Science
Joshua Saxe with Hillary Sanders
Read it for chapter one on static features and chapter five on similarity. Both are useful long before any machine learning is involved.
Read the notes - 2016No Starch Press3 modules
Practical Forensic Imaging
Bruce Nikkel
Where the other half of hashing lives: not secrecy, but proving that these bytes are those bytes.
Read the notes - 2019No Starch Press2 modules
Rootkits and Bootkits
Alex Matrosov, Eugene Rodionov, and Sergey Bratus
The reference for the boot process itself. Read chapter five even if you never care about a bootkit.
Read the notes
Binaries and systems
ELF and PE, the kernel underneath, the firmware under that.
- 2011No Starch Press1 module
A Bug Hunter's Diary
Tobias Klein
Short, narrative, and the best answer to the question nobody else answers: what does the process of finding a bug actually feel like?
Read the notes - 2025No Starch Press2 modules
From Day Zero to Zero Day
Eugene Lim
The newest book here and the one closest to how bugs are actually found now. Its fuzzing chapters are the best short introduction in print.
Read the notes - 2018No Starch Press3 modules
Practical Binary Analysis
Dennis Andriesse
The book that makes ELF stop being a mystery, and the only one here that explains why your disassembler is lying to you.
Read the notes - 2021No Starch Press3 modules
Practical IoT Hacking
Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, and Beau Woods
The one book here that goes below the file. If a challenge involves a logic capture, a flash dump or a firmware image, this is the reference.
Read the notes - 2024No Starch Press2 modules
Windows Security Internals
James Forshaw
The reference for why a Windows process can do a thing. Also the clearest account anywhere of what a captured NTLM exchange contains.
Read the notes