Hardware for Kali Linux & Pentesting
The right hardware makes a massive difference. Built-in laptop WiFi cards don't work for most wireless pentesting, and weak GPUs make password cracking impractical. Here's what I actually use and recommend.
WiFi Adapters
You need a USB WiFi adapter that supports monitor mode and packet injection. Built-in laptop WiFi cards almost never work. Read my complete WiFi adapter guide for the full breakdown.
- Alfa AWUS036ACH — current gold standard, dual-band, RTL8812AU chipset. View on Amazon →
- Alfa AWUS036AXML — WiFi 6E support, future-proof, MT7921AUN chipset. View on Amazon →
- Alfa AWUS036NHA — affordable starter option, AR9271 chipset, 2.4 GHz only. View on Amazon →
- Alfa AWUS036ACS — compact "thumb drive" form factor with dual-band support. View on Amazon →
Raspberry Pi for Portable Pentesting
A Pi 5 with Kali makes a great portable pentesting rig.
- Raspberry Pi 5 (8GB) — board only, fast enough for most Kali workflows. View on Amazon →
- RasTech Pi 5 8GB Full Kit — includes board, case, active cooler, 27W power supply, microSD card. The simplest way to get started. View on Amazon →
- Pi 5 8GB Starter Kit — alternative kit if the full kit is out of stock. View on Amazon →
- Official Pi 5 Power Supply (27W USB-C) — don't skimp on this if buying the board separately
- Active cooler / fan case — Pi 5 throttles without one
Storage for Wordlists & Captures
- SanDisk Extreme Pro microSD (128GB) — fast SD card for Pi 5 or general storage. View on Amazon →
- Samsung T7 External SSD (1TB) — fast, reliable external SSD for wordlists, VM images, and captures. View on Amazon →
- SanDisk Extreme Portable SSD (1TB) — rugged alternative to the Samsung T7. View on Amazon →
- SanDisk Ultra Fit (USB 3.0) — compact, low-profile USB drive that stays flush in the port; ideal for a Kali Live USB. View on Amazon →
Learning Platforms
Reading is fine but the best way to learn security is by doing. These are the platforms I actually use.
- TryHackMe — best for beginners. Structured learning paths, guided rooms, gentle difficulty curve. The free tier is generous.
- HackTheBox — harder, more realistic. Best once you've finished TryHackMe's intro paths.
- PortSwigger Web Security Academy — completely free. The best web app testing training online, full stop. By the makers of Burp Suite.
- OverTheWire — free wargames. Great for learning Linux command line basics.
Books
A short list — only the books I've actually read cover to cover and would recommend.
- The Web Application Hacker's Handbook by Dafydd Stuttard & Marcus Pinto. Dated in spots but still the foundational web pentesting book. View on Amazon →
- The Hacker Playbook 3 by Peter Kim. Practical, scenario-based, modern. View on Amazon →
- RTFM: Red Team Field Manual by Ben Clark. Pocket reference for common commands and techniques.
- Linux Basics for Hackers by OccupyTheWeb. Best intro for people new to Linux. View on Amazon →
- Practical Malware Analysis by Sikorski & Honig. If you want to get into malware reverse engineering.
Privacy & Security Services
Tools I use personally to protect my own privacy and data online.
Data Broker Removal
Manual opt-outs take dozens of hours. These services automate it. See my complete guide to removing personal info for the full breakdown.
- Optery — most transparent. Provides before/after screenshots proving removal. Free tier available.
- Incogni — cheapest legit option (~$8/month). Covers 420+ data brokers.
- DeleteMe — longest-running service. Uses human agents.
VPN
For privacy when on public WiFi, geo-restricted content, or general traffic obfuscation. VPNs do not make you anonymous — they just change who can see your traffic.
- Mullvad — anonymous signup, accepts cash, no email required. The most privacy-focused option.
- ProtonVPN — solid free tier, Switzerland-based, well-audited.
- NordVPN — fast, large server network, good for streaming.
Password Managers
- Bitwarden — open source, free tier covers most needs. My main recommendation.
- 1Password — polished, family plan is good value.
- KeePassXC — fully offline, open source. If you don't want anything cloud-synced.
Email Privacy
- ProtonMail — end-to-end encrypted email. Free tier works for most.
- SimpleLogin — email alias service. Use a different alias for every signup.
- Apple Hide My Email — included with iCloud+. Generates unique aliases.
Software
Virtualization
- VirtualBox — free, cross-platform. What I use for most VM work.
- VMware Workstation Player — free for personal use, generally better performance than VirtualBox.
- UTM — for Apple Silicon Macs. QEMU-based, free.
Terminal & Editors
- iTerm2 (macOS) — what I use daily.
- Windows Terminal (Windows) — much better than the default cmd.exe.
- VS Code — my main code editor. Free.
- Neovim — for terminal-only editing. Worth learning if you're on remote systems often.
Practice Targets
Intentionally vulnerable VMs for legal practice. Set these up in your lab and have at it.
- Metasploitable 2 — vulnerable Linux, perfect for Metasploit and nmap practice.
- DVWA — Damn Vulnerable Web Application. Great for Burp Suite and sqlmap.
- OWASP Juice Shop — modern web app vulnerabilities. Free.
- VulnHub — collection of free vulnerable VMs.