Professional Penetration Testing

Professional Penetration Testing, 2nd Edition

Creating and Learning in a Hacking Lab

Professional Penetration Testing, 2nd Edition,Thomas Wilhelm,ISBN9781597499934






235 X 191

Save yourself some money! This complete classroom-in-a-book on penetration testing provides material that can cost upwards of $1,000 for a fraction of the price!

Print Book + eBook

USD 95.94
USD 159.90

Buy both together and save 40%

Print Book


In Stock

Estimated Delivery Time
USD 79.95

eBook Overview

VST format:

DRM Free included formats: EPub, Mobi, PDF

USD 79.95
Add to Cart

Key Features

  • Find out how to turn hacking and pen testing skills into a professional career

  • Understand how to conduct controlled attacks on a network through real-world examples of vulnerable and exploitable servers

  • Master project management skills necessary for running a formal penetration test and setting up a professional ethical hacking business

  • Discover metrics and reporting methodologies that provide experience crucial to a professional penetration tester


Professional Penetration Testing walks you through the entire process of setting up and running a pen test lab. Penetration testing-the act of testing a computer network to find security vulnerabilities before they are maliciously exploited-is a crucial component of information security in any organization. With this book, you will find out how to turn hacking skills into a professional career. Chapters cover planning, metrics, and methodologies; the details of running a pen test, including identifying and verifying vulnerabilities; and archiving, reporting and management practices.

Author Thomas Wilhelm has delivered penetration testing training to countless security professionals, and now through the pages of this book you can benefit from his years of experience as a professional penetration tester and educator. After reading this book, you will be able to create a personal penetration test lab that can deal with real-world vulnerability scenarios.

All disc-based content for this title is now available on the Web.


Penetration testers, IT security consultants and practitioners

Thomas Wilhelm

Thomas Wilhelm has been involved in Information Security since 1990, where he served in the U.S. Army for 8 years as a Signals Intelligence Analyst / Russian Linguist / Cryptanalyst. A speaker at security conferences across the United States, including DefCon, HOPE, and CSI, he has been employed by Fortune 100 companies to conduct risk assessments, participate and lead in external and internal penetration testing efforts, and manage Information Systems Security projects.Thomas is also an Information Technology Doctoral student who holds Masters degrees in both Computer Science and Management. Additionally, he dedicates some of his time as an Associate Professor at Colorado Technical University and has contributed to multiple publications, including both magazines and books. Thomas currently performs security training courses for both civilian and government personnel through Heorot.net, and maintains the following security certifications: ISSMP, CISSP, SCSECA, and SCNA.

Affiliations and Expertise

ISSMP, CISSP, SCSECA, and SCNA, Associate Professor at Colorado Technical University

View additional works by Thomas Wilhelm

Professional Penetration Testing, 2nd Edition

PART I - Setting Up
Chapter 1: Introduction
Chapter 2: Ethics and Hacking
Chapter 3: Hacking as a Career
Chapter 4: Setting up Your Lab
Chapter 5: Creating and Using PenTest Targets in Your Lab
Chapter 6: Methodologies
Chapter 7: PenTest Metrics
Chapter 8: Management of a PenTest

PART II - Running a PenTest
Chapter 9: Information Gathering
Chapter 10: Vulnerability Identification
Chapter 11: Vulnerability Verification
Chapter 12: Compromising a System and Privilege Escalation
Chapter 13: Maintaining Access
Chapter 14: Covering Your Tracks

PART III - Wrapping Everything Up
Chapter 15: Reporting Results
Chapter 16: Archiving Data
Chapter 17: Cleaning Up Your Lab
Chapter 18: Planning for Your Next PenTest

Appendix A - Acronyms
Appendix B - Definitions

Quotes and reviews

"Have you ever wondered what might be involved in penetration testing? If you are searching for a book on that topic, this one is a great starting point, especially for system administrators and security professionals…From the view of a security newbie, this book provides a comprehensive account of how hacking works and how to counteract it."--ComputingReviews.com, January 22, 2014
"Wilhelm…divides his book into three rough sections. The first covers setting up a penetration test lab or ‘pentest lab’…The next section is on internal pentesting…The final section covers personal skills such as presentation of results to clients and career opportunities as a professional hacker…There are large numbers of b&w figures showing network diagrams and screenshots of the relevant programs."--Reference & Research Book News, December 2013
"I was impressed with the overall flow of information that was presented to the reader, as well as the interweaving of technical and soft skills that are required to successfully establish oneself as a penetration tester…it is a solid resource for those new to the field and for those that may be looking to expand their skill set and understanding."--Journal of Digital Forensics, Security and Law, Volume 8(3), 2013
"Wilhelm has created the ultimate handbook for becoming a pen tester. This is going to help launch many a career."--Richard Stiennon, Chief Research Analyst, IT-Harvest
"Professional Penetration Testing covers everything from ethical concerns, to advance concepts, to setting up your own custom laboratory. It is the most comprehensive and authoritative guide at penetration testing that I have seen. Tom Wilhelm is a true expert in the field who not only is in the trenches on a daily basis, but also takes the time to instruct others on the ways and means of pen testing."--Frank Thornton, Owner, Blackthorn Systems

Shop with Confidence

Free Shipping around the world
▪ Broad range of products
▪ 30 days return policy