Definitely dig the Hacker Playbooks, first and second editions. Also, Metasploit : The Penetration Testers Guide, Hacking the Art of Exploitation and A Hands-On Introduction to Hacking are some that I've enjoyed. Some other good resources (IMHO, your mileage may vary) are the NIST 800-115, Open Source Testing Methodology Manual (OSSTMM) and the Penetration Testers Execution Standard (and yes, I just realized how many of those sites not only do not default to HTTPS but don't support it, ironic). At any rate, I tend to be a bit OCD when it comes to reading, so that may have been overkill for your needs but they're all books / sources that I've either enjoyed, found very informative and helpful or both.
Comment