Lab gear & reading

What our Ethical Hacking and SOC students actually need to build a working lab — and, just as usefully, what they do not.

Hardware

Needed for one week

WiFi adapter with monitor mode and packet injection

The single piece of kit the course cannot substitute. Built-in laptop WiFi cards almost never support monitor mode, and without it you cannot capture a WPA2 handshake — so the whole wireless week becomes a video you watch.

CEH Week 10, Class 28 — WiFi hacking (Aircrack-ng, airodump-ng, Wifite)

See options on Amazon

Recommended

RAM upgrade to 16 GB

The lab runs Kali, a Windows victim and Metasploitable at the same time. 8 GB is the floor and it will swap; 16 GB is where the lab stops being painful.

Both programmes, Week 1 — building the lab

See options on Amazon

Recommended

External SSD, 500 GB or larger

Virtual machines and memory images are large. The outline asks for roughly 100 GB free; an external SSD keeps the lab off your main drive and lets you carry it between machines.

SOC Week 10 — memory and disk forensics (Volatility, Autopsy, FTK Imager)

See options on Amazon

Optional

USB flash drive, 32 GB

For a bootable Kali stick and for moving evidence images around without touching the host you are investigating.

CEH Week 1 and SOC Week 9 — evidence handling

See options on Amazon

Books worth owning

Nothing here is required reading — the classes are self-contained. These are the titles students keep asking about, split by which half of the programme they serve.

Ethical Hacking

CEH Certified Ethical Hacker All-in-One Exam Guide

Matt Walker

The closest thing to a syllabus companion for the exam itself.

Find it on Amazon

Ethical Hacking

The Web Application Hacker's Handbook

Dafydd Stuttard & Marcus Pinto

Still the reference for Week 9. Older than the frameworks it describes, and still right.

Find it on Amazon

Ethical Hacking

Practical Malware Analysis

Michael Sikorski & Andrew Honig

Where the payload week stops being "run msfvenom" and starts being understanding.

Find it on Amazon

SOC / Blue Team

The Practice of Network Security Monitoring

Richard Bejtlich

The thinking behind the SOC weeks on Zeek, Suricata and traffic analysis.

Find it on Amazon

SOC / Blue Team

Blue Team Handbook: Incident Response Edition

Don Murdoch

Short, and the one people actually keep on the desk during an incident.

Find it on Amazon

SOC / Blue Team

Applied Incident Response

Steve Anson

Pairs with SOC Weeks 9 and 10 — containment, evidence and forensics in order.

Find it on Amazon

Where this list comes from

Both three-month programmes publish a full class-by-class outline — 36 classes each, with the tools named for every class. The requirements above are read straight off those outlines, so if a class changes, this page changes with it.

Ethical Hacking programme SOC Analyst programme