Last updated: August 2026. Written by Josh Hutcheson, OnlineCourseing editor. See our review methodology.
QUICK VERDICT
Bottom line: Website Hacking / Penetration Testing by Zaid Sabih is the best starting point — 4.5 from 23,163 ratings, 100 lectures, and updated November 2025. Web is the discipline most testers start with and the one with the most jobs. Then practise relentlessly on TryHackMe and Hack The Box, and aim at OSCP+ only once you can actually compromise machines unaided.
- Best overall: Website Hacking / Penetration Testing (Udemy) — hands-on web application testing.
- Best career path: Zero To Mastery’s Learn Penetration Testing — structure, community, bug-bounty framing.
- Best credential: OSCP+ via OffSec’s PEN-200 — a 24-hour practical exam, from around $1,749.
- Skip if: you cannot yet read a routing table. Networking first, always — it is why most people stall.
Penetration testing is the most job-ready corner of offensive security: a defined engagement with an agreed scope, a methodology, and a report a client pays for. It is also a field where the training market is unusually conflicted, and that is worth naming before you read anyone’s recommendations.
Look at who ranks for this search. Among the top organic results are EC-Council, who sell the CEH certification; StationX, who sell a course subscription; and Infosec, who sell bootcamps. All three paid advertisements are certification bootcamps or a degree programme. Every one of those pages may be perfectly good — but the people telling you which penetration testing course to buy are, overwhelmingly, people who sell penetration testing courses.
We sell no course and no certification. We do earn affiliate commission on some links below, which we mark, and two of our strongest recommendations on this page — OSCP+ and the free practice platforms — earn us nothing at all. Every course was opened at the provider in August 2026 and its rating and last-updated date recorded.
The best penetration testing courses in 2026, compared
Before you spend money on the wrong online course, read this.
Get the free 2026 Platform Comparison Guide — 12 platforms compared on price, certificates, and refund policies. Instant PDF, plus my honest Tuesday picks.
No spam. Unsubscribe anytime.
| Course | Focus | Currency | Best for |
|---|---|---|---|
| Website Hacking / Penetration Testing | Web apps | Updated 11/2025 | Best overall |
| Learn Penetration Testing (ZTM) | Career path | Maintained | Structure + bug bounty |
| Learn Ethical Hacking From Scratch | Broad foundations | Updated 11/2025 | Starting from zero |
| Pen Testing, Threat Hunting & Cryptography | Analyst-side | Maintained | A recognised credential |
| Advanced Ethical Hacking: Network Hacking | Network | Maintained | Network specialism |
| CompTIA Security+ (SY0-701) | Certification prep | Updated 8/2026 | Clearing HR filters |
| TryHackMe / Hack The Box | Practice | Continuous | Non-negotiable, free tier |
1. Website Hacking / Penetration Testing — Udemy (best overall)
Zaid Sabih’s web-focused course is the best single purchase for most people entering penetration testing. 4.5 from 23,163 ratings across 100 lectures, and last updated November 2025 — genuine maintenance in a category where most material is years stale.
The reason to start with web rather than network is practical: it is the largest employment market, the barrier to practising is lowest, and the vulnerability classes it teaches — injection, broken access control, file upload flaws, cross-site scripting — are the ones that appear in real reports most often. The course works through discovery, exploitation and post-exploitation on a deliberately vulnerable target, which is exactly the right shape.
Best for: your first real pen testing course, especially if you already have basic networking. Watch out for: it is web-specific by design — it will not teach you Active Directory or wireless, and you should not expect it to.
Check Current Price on Udemy →
2. Learn Penetration Testing — Zero To Mastery (best career path)
ZTM’s course is framed around the outcome rather than the syllabus — becoming employable and, specifically, capable of hunting bug bounties. That framing matters more than it sounds, because bug bounty is the one route where a beginner can produce public evidence of real findings before anyone hires them.
The subscription includes their ethical hacking, advanced network hacking and Security+ material, which makes it good value if you will use more than one. The active community is the differentiator over a standalone video course — being stuck alone on a lab is the most common reason people abandon this field.
Best for: people who need structure and accountability, and anyone interested in bug bounty as a route in. Watch out for: subscriptions only pay off if you finish.
View the ZTM Pen Testing Course →
3. Learn Ethical Hacking From Scratch — Udemy (best if starting from zero)
If the web course above assumes more than you have, start here instead. Zaid’s broader course — 4.6 from 137,367 ratings, 142 lectures, updated November 2025 — covers network penetration testing, gaining access, post-exploitation and web testing, building the general foundation before you specialise.
The two courses overlap on web content, so buy one first and add the other only when you want depth in that area. Most people should do this one, then the web-specific one. More detail in our ethical hacking courses guide.
Check Current Price on Udemy →
4. Penetration Testing, Threat Hunting & Cryptography — Coursera (IBM)
A focused 6-module, roughly 10-hour intermediate course rated 4.6 from 2,543 reviews with 118,124 enrolled. It sits inside IBM’s wider cybersecurity programme but works standalone, and it approaches the subject from the defender’s side as well as the attacker’s.
That dual perspective is genuinely useful. Most penetration testers are hired into or alongside defensive teams, and understanding threat hunting makes your reports considerably more actionable — you write remediation someone can actually implement rather than a list of findings.
Best for: filling a gap in a week, and for a credential from a name recruiters know. Watch out for: it is shorter and more conceptual than the hands-on picks — a complement, not a replacement.
5. Advanced Ethical Hacking: Network Hacking — Zero To Mastery
Web is where most people start; network is where internal engagements live. This goes deeper on network attacks, traffic manipulation and the countermeasures that defeat them in a properly configured environment — the material that makes you useful on an internal test rather than only an external one.
It is genuinely advanced and the networking prerequisite is real. Pair it with our network penetration testing walkthrough and the Windows pentesting toolkit, since most internal networks are Active Directory networks.
View Advanced Ethical Hacking →
6. CompTIA Security+ (SY0-701) — Udemy (the credential most people need first)
Almost nobody is hired straight into penetration testing. The common route runs through an analyst, helpdesk or sysadmin role, and Security+ is the credential that gets those applications read. Jason Dion’s course is the most efficient route to it: 4.7 from 122,465 ratings, 265 lectures, updated August 2026.
One timing note: CompTIA state SY0-701 launched in November 2023 and that exams usually retire about three years after launch, estimating 2026. Your certification remains valid three years from the day you pass. Detail in our Security+ courses guide.
Free practice — the part that actually gets you hired
No course makes you a penetration tester. Compromising machines does. These are free to start, we earn nothing from them, and a hiring manager will ask about them before they ask about your certificates:
- TryHackMe — guided rooms in the browser with a generous free tier. Start here; the structure is a feature when you are new.
- Hack The Box — less guidance, closer to a real engagement. Move here when TryHackMe stops feeling hard, and treat their machines as OSCP+ preparation.
- Bug bounty programmes — real production systems you are explicitly authorised to test, within a published scope. The scope is a legal boundary, not a suggestion. Earnings are heavily skewed toward experienced hunters, so treat the writeups as the payoff rather than the money.
- Your own lab — a few VMs on an isolated virtual network. Building the vulnerable environment teaches you as much as attacking it.
Write up what you do. A public record of machines you have compromised and how is the single most persuasive artefact a candidate without professional experience can present. It answers the question no certificate answers: what have you actually done?
Authorisation: the line between the job and the offence
Penetration testing is the one security discipline defined by paperwork as much as by skill. The techniques are identical to those used by criminals; what makes yours lawful is documented authorisation from someone with authority over the systems, and nothing else. Not intent, not a disclosure afterwards, not the fact that you found something real.
In the US, unauthorised access is prosecuted under the Computer Fraud and Abuse Act; in the UK, the Computer Misuse Act 1990 makes unauthorised access an offence whether or not damage results.
A professional engagement is defined before any tool runs: a signed statement of work, a scope document listing exactly which ranges and applications are in and out of bounds, a testing window, named emergency contacts on both sides, agreed rules on destructive testing and data handling, and confirmation that the signatory actually has authority over the assets. Learning to insist on that paperwork is part of the craft — see is ethical hacking legal? for the edge cases.
Certifications: OSCP+, PNPT, PenTest+ and CEH
This is the decision people agonise over, and the honest answer is that one of them is clearly the standard for this specific job.
| Certification | Exam format | Verdict |
|---|---|---|
| OSCP+ (PEN-200) | 24-hour practical + report | The standard for this job |
| PNPT | 5-day practical + report + debrief | Excellent value; less name recognition |
| CompTIA PenTest+ | Multiple-choice + performance-based | Good for DoD work-role mapping |
| CEH | Multiple-choice (practical separate) | Only when an employer names it |
OSCP+ is the one that moves salaries. OffSec’s PEN-200 course leads to it, and the exam is a genuine 24-hour practical — you compromise the machines and write the report, or you do not pass. Pricing starts around $1,749 for a course-and-exam bundle, with their Learn One subscription at $2,749 a year at the time of writing. We have no affiliate relationship with OffSec and earn nothing if you buy it; it is here because it is the honest answer.
Do not attempt it early. OSCP+ assumes you can already enumerate, exploit and escalate without hand-holding, and the failure rate among people who rush it is the reason it carries weight. Build capability on Hack The Box first; the money is wasted otherwise. The full certification landscape is mapped in our cybersecurity certifications guide, and the expert-tier CompTIA route in SecurityX.
Penetration testing vs ethical hacking
Used interchangeably, but the distinction is real and it matters for what you buy. Ethical hacking is the broad practice of thinking like an attacker. Penetration testing is a bounded professional engagement: agreed scope, agreed window, a methodology, and a deliverable.
The practical consequence is that the report is half the job and almost no course teaches it. Clients pay for findings ranked by severity with reproduction steps and remediation they can act on — not for a list of things you popped. If a course spends nine hours on exploitation and twenty minutes on reporting, it is teaching the enjoyable half. Our penetration testing methodology guide covers the frameworks that structure this properly, including where the industry standards are and are not still maintained.
Which specialism to start with
| Specialism | Market | Our coverage |
|---|---|---|
| Web applications | Largest; easiest to practise | Web pentesting tools |
| Network / internal | Core of internal engagements | Network pen testing · Windows tools |
| Mobile | Smaller; genuine skills shortage | Mobile testing tools · iOS |
| Wireless | Narrow, but common on-site | Wi-Fi pentesting tools |
| Cloud | Fastest-growing; supply-constrained | — |
Start web, add network, then specialise toward whatever you keep returning to. The toolkit itself is covered in our guides to Kali Linux tools and Kali courses.
The toolkit you will actually use
Courses introduce dozens of tools and you will use a fraction of them daily. The working set is smaller and more stable than the catalogue suggests, which is good news — depth in a few beats familiarity with many:
- Nmap for discovery and enumeration, on essentially every engagement.
- Burp Suite for anything involving a web application — the single most-used tool in the field.
- Metasploit for validating known vulnerabilities quickly, and for learning how exploitation works.
- Wireshark when you need to prove what is actually crossing the wire.
- Active Directory tooling — BloodHound, Impacket, NetExec and friends — on internal engagements, because most enterprise networks are AD networks.
- Hashcat for offline cracking, where the finding is usually the password statistics rather than any individual password.
Most of these ship with Kali, which is why it is the default working environment — though a Windows machine with WSL2 does the job and is genuinely better for the Active Directory work. We cover the toolkit in depth in Kali Linux tools, web pentesting tools and Windows pentesting tools.
A caution worth carrying: tool lists rot fast. Several tools that dominated recommendations a few years ago have been archived or renamed — CrackMapExec became NetExec, PowerSploit has been unmaintained since 2020 — while their old repositories still load normally. Check a tool’s most recent commit before you build a workflow on it.
A realistic roadmap
- Months 1–3: fundamentals. Networking and Linux. The most common reason people stall, and the least skippable step. Start with networking courses if this is thin.
- Months 2–6: a core course, with the labs done. Zaid’s web course or the ZTM path.
- Throughout: TryHackMe weekly. Consistency beats intensity by a wide margin.
- Months 6–9: Security+ and a first role. Analyst, helpdesk or sysadmin. Internal moves into security are far easier than external ones.
- Months 9–18: Hack The Box seriously, then OSCP+. Only once you are compromising machines unaided.
- Ongoing: write. Writeups are portfolio, and reporting is the half of the job that is billable.
Mistakes beginners make
- Attempting OSCP+ too early. The most expensive mistake in this field, and the most common.
- Skipping networking. Everything downstream depends on it.
- Watching instead of doing. Nobody has ever learned to compromise a machine by watching someone else compromise it.
- Ignoring reporting. It is half the job and the half clients pay for.
- Testing without authorisation. Career-ending and prosecutable. Use the platforms.
- Expecting to walk into a pen testing role. Most people arrive via an adjacent job. Plan for that rather than resenting it.
Degree requirements and pay
No degree is required, and penetration testing is among the most credential-and-portfolio-driven roles in technology — a strong Hack The Box profile and an OSCP+ will beat a degree with neither. Government and defence roles are the exception, where clearance and formal requirements apply regardless of ability.
On salary, we would rather give you a method than a figure we cannot stand behind. Published numbers for “penetration tester” vary enormously by country, seniority and whether the role is in-house or consultancy, and the aggregator figures repeated across this topic are frequently stale or drawn from small samples. Read the ranges employers are advertising in your own market this month — that is a better estimate than any number we could print, and it costs you ten minutes.
Frequently asked questions
What is the best penetration testing course?
Website Hacking / Penetration Testing by Zaid Sabih on Udemy — 4.5 from 23,163 ratings, 100 lectures, updated November 2025. Web is the specialism with the most jobs and the lowest barrier to practising. If you are starting from zero, take his broader Learn Ethical Hacking From Scratch first.
Is OSCP worth it?
Yes — it is the standard credential for penetration testing roles specifically, and it is now branded OSCP+. It is a 24-hour practical exam rather than a knowledge test, which is why it carries weight. Pricing starts around $1,749. Do not attempt it until you can compromise machines unaided; attempting it early is the most expensive common mistake in this field.
Can I become a penetration tester without a degree?
Yes. This is one of the most portfolio-driven roles in technology — demonstrable capability plus OSCP+ outweighs a degree without them. Government and defence roles may impose clearance or formal requirements independently of skill.
How long does it take to become a penetration tester?
Twelve to eighteen months of consistent study to be genuinely employable from a standing start, including foundations, a core course, sustained practice and a credential. Most people also pass through an adjacent IT or analyst role on the way, which is normal rather than a detour.
Penetration testing or ethical hacking — which should I study?
The material overlaps almost entirely; the difference is framing. Penetration testing courses tend to include scoping, methodology and reporting — the professional wrapper around the technique — which is what employers hire for. If you are choosing between two otherwise similar courses, take the one that covers reporting.
Is it legal to practise penetration testing?
Only against systems you own or have written authorisation to test. Without it, the same actions are offences under the Computer Fraud and Abuse Act in the US and the Computer Misuse Act 1990 in the UK, regardless of intent or outcome. TryHackMe, Hack The Box, in-scope bug bounty programmes and your own lab are the lawful options.
Do I need to learn programming?
Not to start, but it limits you quickly. Python for tooling and automation, Bash for Linux work, and enough PowerShell for Windows environments. Reading code well enough to spot a flaw matters more than writing it elegantly.
Which certification should I get first?
CompTIA Security+ for most people — it clears HR filters and gets you into the adjacent role that leads to pen testing. Then OSCP+ once you have real hands-on capability. PenTest+ is a reasonable middle step if you need DoD work-role mapping; CEH only when an employer names it.
Related guides
- Best ethical hacking courses — the broader offensive-security lane
- Best cyber security courses — the whole field, including defensive routes
- Penetration testing methodology — the frameworks behind a real engagement
- Best cybersecurity certifications — the full ladder by career stage
- Best CompTIA Security+ courses — the credential to earn first
- Kali Linux courses and Kali Linux tools — the toolkit
- Is ethical hacking legal? — authorisation and scope in full
- Best Linux distros for hacking: the platform these courses assume
