Last updated: September 2026. Written by Josh Hutcheson, OnlineCourseing editor. See our review methodology.
THE SHORT ANSWER
Three hat colors have stable meanings. The rest are folklore. White, black and gray hat are used consistently across the industry. Red, blue and green hat are not: three of the sites currently ranking for this question define blue hat in three incompatible ways, one of which makes it a defender and another an attacker.
- The line that actually matters: authorization. Not intent, not skill, not employment.
- What the reference works use: NIST defines hacker; it has no entry for any hat color. MITRE ATT&CK names groups by APT number, never by hat.
- If you only learn three: white hat, black hat, gray hat. The rest you will meet in blog posts, not in reports.
Ask what separates a hacker from an ethical hacker and you will usually be handed a list of colored hats. It is a memorable framing and a poor one, because the moment you compare the lists side by side they stop agreeing with each other. This guide sorts the categories that hold up from the ones that do not, then sets out the seven dimensions on which hacking and ethical hacking genuinely differ.
The only line that carries legal weight is authorization
Before you spend money on the wrong online course, read this.
Get the free 2026 Platform Comparison Guide — 12 platforms compared on price, certificates, and refund policies. Instant PDF, plus my honest Tuesday picks.
No spam. Unsubscribe anytime.
The US government’s own definition is built on one word. NIST’s Computer Security Resource Center defines a hacker as an “unauthorized user who attempts to or gains access to an information system” (NIST glossary entry for “hacker”, sourced to CNSSI 4009-2022 and NIST SP 800-12 Rev. 1). There is no mention of skill, motive, employment or headwear. The whole definition turns on whether permission existed.
That matches how the law works. Under the 18 U.S.C. §1030, the offense is accessing a computer without authorization or exceeding authorized access. A tester with a signed scope document and a tester without one can run identical commands against identical systems and end up in entirely different places. We cover the boundaries and the genuine gray areas in is ethical hacking legal?.
Everything else in this guide sits downstream of that one distinction. Intent explains why someone acted; authorization determines what they can be charged with.
What the reference works actually use
It is worth checking where the hat vocabulary appears, because the answer is instructive: it appears in vendor blog posts and almost nowhere else.
| Reference work | Defines | Has no entry for |
|---|---|---|
| NIST CSRC glossary | hacker, threat, penetration testing, insider threat | white hat, black hat, gray hat, blue hat, green hat, red hat, script kiddie |
| MITRE ATT&CK | named threat groups, APT designations | any hat color at all |
We checked this rather than assuming it. Every term in the middle column returns a live NIST glossary page; every term in the right column returns a 404 on the same URL pattern, which is what makes the absence meaningful rather than a broken link. The MITRE ATT&CK group index, which catalogs real adversary groups, uses APT numbering and group names throughout and contains no hat colors.
This does not make the hat vocabulary useless. It makes it informal. Use it in conversation; do not use it in a report where a specific claim about authorization is doing the work.
The three hats that hold up
White hat
A security professional testing systems with the owner’s documented permission. The permission is the definition. White hats work to an agreed scope, follow a penetration testing methodology, and report findings rather than using them.
Black hat
Someone accessing systems without authorization, typically for money, data or disruption. In formal writing you will more often see threat actor or adversary, which carry no assumption about motive or skill.
Gray hat
Someone who probes without permission but discloses what they find instead of exploiting it. The category describes real behavior and is legally hazardous: disclosure is not a defense to unauthorized access. Gray hat is where well-intentioned people get prosecuted.
Red, blue and green hat: three sources, three incompatible definitions
Here is the problem with the extended taxonomy. We read the pages currently ranking for this question and compared what each one says. They do not describe the same categories, and on blue hat they disagree about the thing that matters most: whether the person is authorized.
| Term | Source | What it says | Authorized? |
|---|---|---|---|
| Blue hat | Norton | Heads the section “Blue hat hackers: Security-focused software developers” and describes people a business brings in to test software before release. | Yes |
| AVG | “Blue hat hackers are white hat hackers who are employed by an organization.” | Yes, but a different group entirely | |
| Geekflare | “They are revenge seekers who hack computer systems to take personal revenge on an organization.” | No. This is an attacker. | |
| Red hat | Norton | Filed under the heading “Red hat hackers: Ethical hackers”, taking “a vigilante approach to directly stop black hats”. | Implied yes |
| Geekflare | “Somewhat the same as white hat hackers, but they are not authorized to perform hacking operations.” | Explicitly no | |
| Green hat | AVG | The most consistent of the three: a novice. AVG separates green hats from script kiddies by ambition, noting green hats “may aspire to become white or black hats”. Others merge the two. | Not a property of the term |
Read that table again on the blue hat rows. One source has a company inviting them in, one has them on the payroll, and one has them attacking the company out of spite. A category that can mean an employee or an attacker is not carrying information. Nobody is lying here; the term simply never had an owner, so each publisher settled it differently and presented their version as established.
There is a further trap worth naming: red hat is not red team. Red team is a precise, contracted engagement in which an authorized group emulates an adversary against a defending blue team. It is standard enterprise vocabulary with real deliverables. Red hat, as these sources use it, means a vigilante attacking criminals. Treating them as the same word in an interview is a tell.
The categories practitioners use instead
When the hats stop being useful, this is the vocabulary that replaces them. It classifies by capability, resourcing and relationship to the target, which is what defenders actually need to know.
Threat actor
The neutral umbrella term for anyone conducting an attack. Preferred in incident reports precisely because it assumes nothing about motive or skill.
Advanced persistent threat (APT)
A well-resourced adversary that establishes long-term access and stays quiet, typically state-sponsored or organized crime. Defined by patience and persistence, not by any single technique. Public groups are cataloged and numbered in MITRE ATT&CK.
Nation-state actor
An adversary operating with government backing, which changes the calculus: budget is effectively unbounded and prosecution is usually unavailable as a remedy.
Hacktivist
Motivated by a political or ideological cause rather than money. Methods skew toward defacement, leaks and denial of service, chosen for visibility over stealth.
Insider threat
Misuse of legitimate access by an employee, contractor or partner. It defeats perimeter controls by definition. Note that NIST does define this one.
Script kiddie
A low-skill attacker running other people’s tools. Operationally meaningful because it predicts noisy, untargeted, easily detected activity.
Initial access broker
A specialist who compromises organizations and sells the access on rather than using it. Part of why a breach and its consequences can be months apart.
Ransomware affiliate
An operator renting ransomware and infrastructure from its developers for a share of proceeds. The reason ransomware capability no longer implies ransomware skill.
Cyberterrorist
An actor pursuing intimidation or disruption of critical services for ideological ends. The label carries legal and political consequences well beyond the technical activity, so it is applied sparingly in serious reporting and liberally in headlines.
Cryptojacker
An attacker who quietly uses someone else’s compute to mine cryptocurrency. Distinctive because the goal is to remain profitable rather than to escalate, which makes it one of the longest-dwelling and least-noticed compromises.
Botnet operator
Someone controlling a fleet of compromised machines and renting it out for denial of service, spam or credential stuffing. Scale, rather than sophistication, is the product.
Each of these is defined in full, alongside seventy-odd others, in our glossary of hacking terms.
Hacking vs ethical hacking: the seven dimensions
With the categories straight, the original comparison becomes tractable. These are the axes on which the two genuinely differ, in rough order of how much they matter.
1. Authorization
The decisive one. Ethical hacking is performed under documented permission defining systems, methods, timing and disclosure. Hacking is not. Every other difference below is downstream of this.
2. Scope
An ethical engagement is bounded: named targets, agreed techniques, a stated window. An attacker has no scope, which is why real adversaries routinely reach places a test was contractually forbidden to touch. A clean pentest report is not proof the estate is safe.
3. Intent
Commonly given as the primary difference, and it is the weakest of the set. Intent is invisible, unprovable at the moment of access, and does not appear in the statute. Good intentions are exactly what gray hats have.
4. Disclosure
Ethical hackers report findings to the owner and withhold them until a fix exists. Attackers use or sell them. This is the practical difference a client feels, and it is contractual rather than moral.
5. Tools
Effectively identical, and this surprises people. Nmap, Burp Suite, Metasploit, Hydra and sqlmap are the standard kit on both sides. There is no ethical toolset. See ethical hacking tools and website hacking techniques. The paperwork differs; the software does not.
6. Compensation
Ethical hackers are paid by the target, through salary, a contract or a bug bounty with published rules. Attackers are paid by someone else, or by the target under duress. Follow the money and the authorization question usually answers itself.
7. Accountability
An ethical hacker is identifiable, insured and answerable, and typically holds credentials that can be revoked. That accountability is most of what a client is buying. An attacker’s defining professional advantage is that no one can find them.
Where the hat metaphor came from
The colors are borrowed from Western films, where the hero wore a white hat and the villain a black one. It transferred into computing culture as shorthand, and it works for exactly the reason films used it: two clearly opposed roles, instantly legible.
The trouble began when the palette was extended. White and black describe a genuine binary (permitted, not permitted) and gray describes the real space between them. Red, blue and green have no such underlying distinction to name, so each publisher invented one. That is why the three original colors are stable and everything added since is not: the first three were describing something, and the rest were filling out a set.
What each category actually changes for defenders
Categories are only worth learning if they change a decision. This is the practical version: what each type wants, and what actually stops them. Note how rarely the answer is a firewall.
| Category | What they want | What actually stops them |
|---|---|---|
| Script kiddie | Any easy target | Patching. They run public exploits against known flaws, so a current estate is close to immune. |
| Ransomware affiliate | Leverage, fast | Tested offline backups plus MFA on remote access. Paying restores data; it does not restore the access they still hold. |
| APT / nation-state | Long-term quiet access | Detection, not prevention. Assume entry and hunt for lateral movement and command-and-control traffic. |
| Insider | Data they can already reach | Least privilege and logging. Perimeter controls are irrelevant by definition here. |
| Hacktivist | Attention | Availability engineering and a communications plan. The reputational damage usually exceeds the technical damage. |
| Initial access broker | Credentials to resell | Phishing-resistant MFA and session monitoring. The breach and its consequences may be months apart. |
The pattern in that last column is the argument for reading the taxonomy at all. Two of the six are answered by patching and credential hygiene, one is answered only by detection, and one is not a perimeter problem in any sense. A defense built around a single control fails at least four of these.
How ethical hackers actually qualify
The distinction is not self-declared. Working ethical hackers carry three things an attacker does not: a contract, an identity, and usually a credential that can be taken away.
The common route runs through a foundational security certification, then a practical offensive one. CompTIA Security+ establishes the defensive baseline that employers screen for. EC-Council’s CEH is the credential most often named in job listings, and is knowledge-based. OffSec’s OSCP is the one practitioners respect most, because it is a twenty-four-hour practical exam against live machines rather than a multiple choice paper. CompTIA PenTest+ sits between them.
None of that is required to test a system you own. All of it becomes relevant the moment you want to be paid to test somebody else’s, because the client is buying accountability as much as skill. We rank the training routes on merit in best ethical hacking courses, including which certifications we think are overpriced for what they return.
What the two have in common
The differences get the attention, but the overlap is larger and it is the reason the authorization question carries so much weight. If the two activities looked different, nobody would need a contract to tell them apart.
The same toolkit
Not similar tools. The same tools, usually the same versions. An attacker and a consultant both reach for Nmap to map a network, Burp Suite to intercept web traffic, and Metasploit to weaponize a known flaw. Nothing in the software knows or cares which one is running it.
The same method
Reconnaissance, enumeration, exploitation, escalation, persistence. A professional engagement follows that sequence because attackers do, and a test that skipped a phase would not tell you anything about how you would actually be attacked.
The same knowledge base
Both sides read the same CVE feeds, the same vendor advisories, the same conference talks and the same exploit write-ups. Public security research is genuinely public, and the argument for keeping it that way is that defenders are the ones who lose when it is not.
The same mindset
The habit of asking what a system does when you give it something unexpected is the whole job in both cases. This is why the career path from curiosity to profession is short, and why a lot of good defensive engineers are people who once poked at something they probably should not have.
The same legal exposure, minus one document
This is the one people underestimate. An ethical hacker who strays outside the agreed scope is, for that period, doing unauthorized access. The authorization is not a status you hold; it is a boundary you stay inside, and it is written down precisely so both sides can tell when it has been crossed.
Frequently asked questions
What is the main difference between hacking and ethical hacking?
Authorization. Ethical hacking is carried out with the system owner’s documented permission and within an agreed scope; hacking is not. The techniques and the tools can be identical, which is why permission rather than method is what separates lawful security work from an offense.
Are red hat, blue hat and green hat real categories?
Not in any consistent sense. They appear in vendor blog posts rather than in reference works, and the definitions conflict: of three sites ranking for this question, one describes a blue hat as an invited software tester, one as an employee, and one as someone attacking a company out of revenge. White, black and gray hat are the three worth learning.
Is red hat the same as red team?
No, and conflating them is a common error. Red team is a contracted engagement in which an authorized group emulates an adversary against a defending blue team. Red hat, as popular listicles use it, means a vigilante who attacks criminals. One is a standard enterprise exercise, the other is folklore.
Does NIST define white hat and black hat hackers?
No. NIST’s glossary defines hacker, threat, penetration testing and insider threat, but has no entry for any hat color or for script kiddie. Its definition of hacker turns entirely on authorization: an unauthorized user who attempts to or gains access to an information system.
Do ethical hackers use the same tools as criminals?
Yes. Nmap, Burp Suite, Metasploit, Hydra and sqlmap are standard on both sides, and there is no such thing as an ethical-only toolset. What differs is the authorization behind their use and the obligation to report rather than exploit what they find.
Can you be prosecuted for hacking with good intentions?
Yes. Unauthorized access is unauthorized regardless of what you do afterward, and disclosing a flaw is not a defense to obtaining it. This is precisely the gray hat exposure, and it is why bug bounty programs publish rules: the rules are what convert the same activity into authorized testing.
Where to learn this properly
Knowing the categories is vocabulary. Doing the work means scoping an engagement, running the tools against a lab you are allowed to break, and writing findings someone can act on. We rank the options on merit in best ethical hacking courses for the offensive path, and best cyber security courses for the broader defensive and governance track, including which ones we would not spend money on.
See the ranked ethical hacking courses →
Related guides
- Hacking terms — the 78-term glossary, grouped by attack stage
- Is ethical hacking legal? — authorization and the CFAA in full
- Penetration testing methodology — how a scoped engagement runs
- Website hacking techniques — the attacks themselves
- Ethical hacking tools — the shared toolkit
- Is ethical hacking a good career? — the honest numbers, including the downsides
- Network pentesting checklist — the network-side walkthrough
- Programming languages for hacking — what the tools are actually written in
