// Comparison
Container Security vs How to Hack Like a Ghost: Which Should You Read?
Two cybersecurity books on Cloud, compared honestly: who each is for, what each does best, and which to read first.
Liz Rice's first-principles introduction to how Linux containers actually work — namespaces, cgroups, capabilities, seccomp, image layering — and the security implications that fall out of those mechanics.
A narrated, real-time breach of a fictional data-driven political consulting firm's AWS and Kubernetes environment, written by a working penetration tester who presents at Black Hat and DEF CON.
Read this if
Skip this if
Key takeaways
- A container is not a box; it is a process with curated views of namespaces and resources, and most container vulnerabilities live in the gap between that mental model and the box mental model.
- Capability dropping, read-only root filesystems, and seccomp profiles are not optional — Rice makes the case persuasively with concrete examples.
- Image-supply-chain hygiene is half the security story; the book pre-dates SLSA but motivates it cleanly.
- Treats attacker OPSEC and anonymous infrastructure as seriously as the exploitation itself, which most cloud-pentest material skips.
- Walks a complete, realistic AWS and Kubernetes attack chain end to end rather than isolated techniques.
- The narrative format keeps the tradecraft memorable in a way a reference manual rarely does — closer to Mr. Robot than to a lab manual.
How they compare
Container Security and How to Hack Like a Ghost are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.
Both books target intermediate-level readers, so the choice is about topic, not difficulty.
Container Security and How to Hack Like a Ghost both cover Cloud, so reading them in sequence reinforces the same material from different angles.
Keep reading
How to Hack Like a Ghost
→ Alternatives to How to Hack Like a Ghost→ What to read after How to Hack Like a Ghost