📊 Save 30% on Corporate Finance Institute with code AFF30. FMVA, financial modeling & more. Claim the deal →
ethical hacking courses

Best Ethical Hacking Courses in 2026 (Ranked & Reviewed)

Last updated: August 2026. Written by Josh Hutcheson, OnlineCourseing editor. See our review methodology.

QUICK VERDICT

Bottom line: Learn Ethical Hacking From Scratch by Zaid Sabih is the best starting point for most people — 4.6 from 137,367 ratings and, unusually for this category, still actively maintained (updated November 2025). Add hands-on practice on a platform that gives you legal targets, then earn CompTIA Security+ for the credential. Be sceptical of CEH until an employer specifically asks for it.

  • Best overall: Learn Ethical Hacking From Scratch (Udemy) — 142 lectures, beginner to intermediate.
  • Best career path: Zero To Mastery’s Complete Ethical Hacker path — structure and community.
  • Best free practice: TryHackMe, then Hack The Box. Non-negotiable, and both have free tiers.
  • Skip if: you are hoping to skip the fundamentals. Networking and Linux come first, always.

Ethical hacking is the authorised practice of attacking systems to find weaknesses before someone unauthorised does. It is a real, well-paid profession with a genuine entry route that does not require a degree — and it is also the single most over-marketed corner of technical education, which makes choosing a course unusually difficult.

Worth knowing before you read any guide to this topic, including this one: two of the highest-ranking pages for “best ethical hacking courses” are published by EC-Council — the organisation that sells the CEH certification — and every paid advertisement on that search page is a CEH bootcamp. That does not make their content wrong, but it does mean the loudest voices in this space have a product to move. We do not sell a certification, and we say plainly below where we think CEH is and is not worth the money.

Every course below was opened at the provider in August 2026 and checked for liveness, rating and last-updated date. This category rots faster than most — while checking, we found one widely-recommended course last updated in 2020 and another that has been withdrawn entirely while lists still link to it. Both are named further down.

The best ethical hacking courses in 2026, compared

Before you spend money on the wrong online course, read this.

Get the free 2026 Platform Comparison Guide — 12 platforms compared on price, certificates, and refund policies. Instant PDF, plus my honest Tuesday picks.

No spam. Unsubscribe anytime.

Course Provider Currency Best for
Learn Ethical Hacking From Scratch Udemy Updated 11/2025 Best overall
Complete Ethical Hacker career path Zero To Mastery Maintained Best career path
Google Cybersecurity Professional Certificate Coursera Maintained Best foundations first
Advanced Ethical Hacking: Network Hacking Zero To Mastery Maintained Best next step
IBM Cybersecurity Analyst Professional Certificate Coursera Maintained Best recognised credential
CompTIA Security+ (SY0-701) Complete Course Udemy Updated 8/2026 Best certification prep
TryHackMe / Hack The Box Continuously Best free practice

1. Learn Ethical Hacking From Scratch — Udemy (best overall)

Zaid Sabih’s course has been the default recommendation in this category for years, and it has earned that position twice over: 4.6 from 137,367 ratings across 142 lectures, and — the part that actually distinguishes it — it was last updated in November 2025. In a catalogue where the median ethical hacking course has not been touched since 2020, maintenance is the rarest feature on offer.

The structure is right too. You install Kali in the first section and spend the rest of the course doing things with it: network penetration testing, gaining access to systems, post-exploitation, and web application testing. It teaches technique through practice rather than touring a tool menu, and it assumes no prior security knowledge.

Best for: almost everyone starting out, and the one course to buy if you are buying one. Watch out for: breadth over depth — it makes you competent across many areas rather than expert in one, and you will still need practice platforms to consolidate any of it.

Check Current Price on Udemy →

2. Complete Ethical Hacker career path — Zero To Mastery (best career path)

Where the Udemy course is a course, this is a route. ZTM’s ethical hacker path sequences fundamentals, networking, offensive technique and career preparation into a defined order, so you are not assembling a curriculum from twelve separate purchases and guessing at the sequence.

The subscription includes their networking, Security+ and advanced hacking material, which is what makes it good value if you will genuinely use more than one. The active Discord is a real asset in a field where being stuck alone on a lab problem is the most common reason people quit.

Best for: career changers who need structure and accountability rather than more video. Watch out for: subscriptions only pay off if you finish — if you are fast and self-directed, one-off purchases cost less.

View the ZTM Ethical Hacker Path →

3. Google Cybersecurity Professional Certificate — Coursera (best foundations)

This is not an ethical hacking course, and that is precisely why it is here. 4.8 from 68,956 reviews with 1,597,984 enrolled across a 9-course series, it builds the security, networking and Linux foundations that offensive work sits on top of — the layer beginners most often skip and then stall on.

If you cannot read a routing table or navigate a Linux filesystem, an ethical hacking course will wash over you and you will conclude you are not clever enough. You are simply missing the prerequisite. Six months here first is the least glamorous and most effective advice on this page.

Best for: complete beginners, and anyone who has tried a hacking course and bounced off it. Watch out for: it is defensive in orientation — it will not teach you to attack anything.

View the Google Certificate →

4. Advanced Ethical Hacking: Network Hacking — Zero To Mastery (best next step)

The gap most people hit is between “I finished a beginner course” and “I can do this on a real network”. This fills it, going deeper on network attacks, traffic manipulation and the defensive countermeasures that make those attacks fail in a properly configured environment.

It genuinely is advanced — attempting it without solid networking will not work. Treat it as the second year, not the second week.

Best for: people who have finished a beginner course and want depth in one area. Watch out for: the prerequisite is real, and it is networking.

View Advanced Ethical Hacking →

5. IBM Cybersecurity Analyst Professional Certificate — Coursera

A 14-course series rated 4.6 from 28,353 reviews with 363,228 learners enrolled, running about four months at ten hours a week. IBM state that it prepares you for the CompTIA Security+ exam, which makes it the most efficient way to build skills and move toward a recognised credential at the same time.

It leans defensive — threat intelligence, incident response, forensics — which is worth understanding rather than avoiding. Almost nobody is hired straight into a purely offensive role; most ethical hackers arrive via analyst or systems work, and this is the content those roles actually run on.

Best for: anyone who wants employability rather than only technique. Watch out for: 14 courses is a real commitment, and it overlaps heavily with the Google certificate — do one.

View the IBM Certificate →

6. CompTIA Security+ (SY0-701) Complete Course — Udemy (best certification prep)

At some point the question stops being “what should I learn” and becomes “what will get me past a filter”. For almost everyone that answer is Security+, not CEH, and Jason Dion’s course is the most efficient route to it: 4.7 from 122,465 ratings, 265 lectures, last updated August 2026.

One timing note: CompTIA publish that SY0-701 launched in November 2023 and that their exams usually retire about three years after launch, estimating 2026. Your certification stays valid three years from the day you pass regardless — but check the calendar if you are more than six months out. Detail in our Security+ courses guide.

Check the Security+ Course →

7. Free practice platforms — the part you cannot skip

Watching someone else run a tool teaches you almost nothing. Ethical hacking is a practical skill and hiring managers ask what you have done. These are free to start, we earn nothing from any of them, and they matter more than any single course on this page:

  • TryHackMe — guided rooms in the browser with a generous free tier. Start here. The hand-holding is a feature when you are new.
  • Hack The Box — harder, less guidance, closer to a real engagement. Move across when TryHackMe stops feeling difficult.
  • ISC2 Certified in Cybersecurity — a genuine entry-level certification from the body behind CISSP, with a long-standing free training and exam initiative for newcomers. Check current terms; it is the cheapest real credential available.
  • Your own lab — a couple of VMs on an isolated virtual network costs nothing and teaches you as much building it as attacking it.

The crucial point is legal as much as educational: these platforms give you targets you are explicitly authorised to attack. That is the only lawful way to practise unless you own the system.

Authorisation is what makes it “ethical”

The word doing the work in “ethical hacking” is not hacking. The techniques are identical to those used by criminals; the tools are the same tools. What separates a professional from a defendant is documented authorisation from someone with authority over the system — and nothing else.

In the United States, unauthorised access is prosecuted under the Computer Fraud and Abuse Act; in the United Kingdom, the Computer Misuse Act 1990 makes unauthorised access an offence whether or not any damage results. Good intentions are not a defence, and neither is “I was only testing”. We cover the edge cases in is ethical hacking legal?

Practically: practise on platforms that grant permission, on your own lab, or on a bug bounty programme within its published scope. Never on your employer’s systems without written sign-off, never on a former employer’s, and never on a site because it “looked insecure”.

CEH vs the certifications that actually matter

CEH — Certified Ethical Hacker, from EC-Council — is the most heavily marketed credential in this field by a wide margin. Here is the balanced version, from someone who does not sell it.

The case for it: it appears by name in a real number of job listings, particularly in government, defence contracting and large enterprises whose HR functions built their filters years ago. If a specific employer or contract requires CEH, that requirement is real and no amount of forum opinion changes it. Get it.

The case against it: it is expensive relative to what it demonstrates, and among practitioners it is widely regarded as a knowledge test rather than a skills test. For offensive work specifically, OSCP+ carries considerably more weight because it is a 24-hour practical exam where you either compromise the machines or you do not. For general security roles, Security+ costs a fraction and clears more filters.

Certification Format Get it when
CompTIA Security+ Multiple-choice + performance-based First, almost always
ISC2 CC Multiple-choice Budget is the constraint
CEH Multiple-choice (practical exam separate) An employer or contract names it
OSCP+ 24-hour practical You want offensive work specifically
CompTIA SecurityX (formerly CASP+) Multiple-choice + performance-based You are senior and staying technical

Our recommendation for most people: Security+ first, then decide between the offensive track toward OSCP+ and the architecture track toward SecurityX. The full ladder is mapped in our cybersecurity certifications guide.

What we left out, and why

Competing lists for this term run to thirteen, twenty, even thirty-plus courses. Ours has six paid picks, and that is deliberate — padding a list with stale material is not a service. Concretely, while checking candidates in August 2026:

  • A widely-recommended Nmap ethical hacking course is rated 4.5 from 4,456 ratings and was last updated in August 2020. Six years is a long time in tooling. It still appears on current lists without a date anywhere near it.
  • A course at udemy.com/course/website-hacking-penetration-testing/ has been withdrawn. Its URL returns HTTP 200 but serves the Udemy homepage — the documented signature of a removed course, and distinct from a slug that never existed, which returns a 404. That is exactly why stale lists keep linking to withdrawn courses. Note the near-identical name: Zaid Sabih’s Learn Website Hacking / Penetration Testing From Scratch is a different, very much live course and is our top pick on the penetration testing courses page.
  • CEH bootcamps costing several thousand pounds. Every advertisement on this search page is one. See the section above — worth it if an employer names CEH, poor value otherwise.
  • Tutorial-site courses with no visible maintenance. A large tail of ethical hacking content exists whose ratings were earned years ago. A high rating on a 2019 course is a historical record, not a recommendation.

Ethical hacking vs penetration testing

Used loosely as synonyms, and the distinction is worth holding. Ethical hacking is the broad practice: thinking like an attacker to find weaknesses, across any technique or target. Penetration testing is a defined engagement — agreed scope, agreed window, a methodology, and a report the client can act on.

Practically, “penetration tester” is the job title you will be hired under, and the reporting half is what separates a professional from a hobbyist with good tooling. Clients pay for findings they can act on, not for a list of things you popped. If that is the direction you want, our penetration testing courses guide and the penetration testing methodology walkthrough cover the structured side.

What you actually learn in an ethical hacking course

Course descriptions list tools; the job is a sequence. Every credible course teaches the same five phases in the same order, because that is how a real engagement runs. Knowing them lets you spot a syllabus that stops halfway:

  • Reconnaissance. Gathering information about the target before touching it — domains, employees, exposed services, technology stack. Unglamorous, and it determines how good everything after it is.
  • Scanning and enumeration. Mapping live hosts, open ports, service versions and users. This is where Nmap lives, and where most beginners rush.
  • Gaining access. Exploiting what you found — the phase everyone signs up for, and typically the shortest.
  • Maintaining access and post-exploitation. Establishing what the access is actually worth: reachable data, recoverable credentials, privilege escalation, lateral movement. This is where an engagement’s real findings come from.
  • Analysis and reporting. Turning it into something a client can act on, with severity, impact, reproduction steps and remediation. The phase courses skimp on and employers care about most.

If a course spends nine hours on exploitation and twenty minutes on reporting, it is teaching you the fun part and leaving out the billable one. Our penetration testing methodology guide covers the formal frameworks — PTES, OWASP WSTG, NIST — that structure this properly.

Alongside the phases, expect to build working knowledge of networking and protocols, Linux and Windows administration, web application mechanics, cryptography at a practical level, and enough scripting to automate the repetitive parts. That list is the honest prerequisite set, and it is why the fundamentals advice above keeps recurring.

Bug bounties: the other way in

Worth knowing about because it is the one route that produces evidence and income without anyone hiring you first. Organisations publish programmes inviting researchers to find vulnerabilities in defined systems, within a published scope, and pay for valid findings. The scope document is your authorisation — which makes bug bounty one of the few places a beginner can legally test real production systems.

Two honest caveats. First, earnings are heavily skewed — a small number of experienced hunters take most of the payouts, and treating it as reliable early income is a mistake. Second, the scope is a legal boundary, not a suggestion: testing an asset outside a programme’s published scope is unauthorised access, and the programme’s existence is no defence.

Used properly, its value is the writeups. A public record of valid findings is the strongest portfolio evidence available to someone with no professional experience, and it answers the interview question no certificate can: what have you actually found?

A realistic learning roadmap

  • Months 1–3: foundations. Networking and Linux. Not optional, and the reason most people stall. Start with networking courses if this is a gap.
  • Months 2–5: a core hacking course. Zaid’s, or the ZTM path. Do the labs; do not just watch.
  • Throughout: practice weekly. TryHackMe from day one, moving to Hack The Box. Consistency beats intensity.
  • Months 4–7: tooling depth. Learn the instruments properly — our Kali Linux tools guide and Kali courses cover the standard kit.
  • Months 6–9: a credential. Security+ for most people. It is the step that changes your reply rate.
  • Months 9+: specialise and evidence it. Web, network, mobile or cloud — and write up what you have done. A public writeup beats a certificate in an interview.

Nine to twelve months of consistent part-time study is a realistic run to entry-level employability from a standing start. Anyone promising it in six weeks is selling something.

Where to specialise after the basics

Generalists get hired; specialists get retained. Once you have the fundamentals and a credential, picking a lane is what turns a job into a career. The main ones, and where our coverage goes deeper:

  • Web application security. The largest employment market by some distance, and the most accessible entry specialism — every organisation has web applications. See web application pentesting tools.
  • Network and infrastructure. Internal assessment, Active Directory, lateral movement — the bread and butter of internal engagements. See network penetration testing and Windows pentesting tools.
  • Mobile. A smaller field with correspondingly less competition, and a genuine skills shortage. See mobile app security testing tools and iOS penetration testing.
  • Wireless. Narrow, but it comes up on most physical-premises engagements. See Wi-Fi pentesting tools.
  • Cloud. The fastest-growing area, and the one where demand most outstrips supply — misconfigured cloud estates are the modern equivalent of unpatched servers.
  • Social engineering and physical. People and premises rather than systems. Requires a temperament as much as a skill set, and the authorisation paperwork is stricter, not looser.

You do not need to choose early — most people discover a preference by doing enough breadth to notice what they keep returning to.

Mistakes beginners make

  • Skipping networking. The single biggest predictor of giving up.
  • Collecting courses instead of finishing one. Four half-watched courses teach less than one completed with its labs.
  • Learning tools rather than concepts. Tools change; the reason an attack works does not.
  • Practising on things you do not own. Career-ending, and occasionally prosecutable. Use the platforms.
  • Buying CEH first because it sounds official. Security+ is cheaper and opens more doors for most people.
  • Expecting a certificate to produce offers. Evidence of work does that. Certificates get you read.

Do you need a degree, and what does it pay?

No degree is required, and this remains one of the few well-paid technical fields where certifications plus demonstrable skill are genuinely accepted in place of one. The exceptions are government and defence roles, which may impose degree or clearance requirements independent of your ability.

On pay, we would rather give you a method than a number we cannot source. Salary figures for “ethical hacker” vary enormously by country, seniority and whether the role is in-house or consultancy, and the aggregator numbers quoted around this topic are frequently stale or drawn from tiny samples. Look at live listings for penetration tester and security analyst roles in your own market and read the ranges employers are actually advertising this month — that is a better estimate than any figure we could print here.

Start With the Top-Rated Course →

Frequently asked questions

What is the best ethical hacking course?

Learn Ethical Hacking From Scratch by Zaid Sabih on Udemy — 4.6 from 137,367 ratings across 142 lectures, and last updated November 2025, which makes it one of the few genuinely maintained courses in this category. Pair it with free practice on TryHackMe.

Is CEH worth it?

Only if an employer or contract names it — which does genuinely happen in government, defence and large enterprises. Otherwise it is expensive for what it demonstrates. For offensive roles OSCP+ carries more weight because it is a practical exam; for general roles Security+ costs a fraction and clears more filters.

Can I learn ethical hacking for free?

Yes, substantially. TryHackMe and Hack The Box both have free tiers and are the most important part of learning anyway, ISC2’s Certified in Cybersecurity offers a free route to a real certification, and a home lab costs nothing. Pay for structure when you want it, not because free material is inadequate.

How long does it take to become an ethical hacker?

Nine to twelve months of consistent part-time study to reach entry-level employability from a standing start, assuming you build networking and Linux foundations first. Coming from an IT or sysadmin role, considerably less. Anyone promising six weeks is selling something.

Is ethical hacking legal?

Only with documented authorisation from someone with authority over the system. Without it, the same actions are prosecuted under the Computer Fraud and Abuse Act in the US and the Computer Misuse Act 1990 in the UK, where unauthorised access is an offence regardless of whether damage results. Practise on platforms that grant permission or on your own lab.

Do I need to know programming?

Not to start, but it becomes limiting quickly. Python is the usual first choice for automation and tooling, with Bash and some PowerShell for the environments you will meet. Our guide to programming languages for ethical hacking covers what is worth your time.

Which certification should I get first?

CompTIA Security+ for almost everyone. It is vendor-neutral, has no enforced prerequisite, maps to US federal work roles and is the credential most commonly filtered on. ISC2’s CC is a reasonable free stepping stone. Save OSCP+ for when you have real hands-on capability.

Is a Udemy ethical hacking course enough to get hired?

Not on its own. The combination that gets interviews is a solid course, sustained practice you can point to, and a recognised certification. The course teaches technique; the practice profile and the certification are what a hiring manager can actually evaluate.

Related guides