// Comparison
How to Hack Like a Ghost vs Kubernetes Security: Which Should You Read?
Two cybersecurity books on Cloud, compared honestly: who each is for, what each does best, and which to read first.
A narrated, real-time breach of a fictional data-driven political consulting firm's AWS and Kubernetes environment, written by a working penetration tester who presents at Black Hat and DEF CON.
Liz Rice and Michael Hausenblas's freely-available O'Reilly short on the Kubernetes-specific security model: API server, RBAC, network policy, secrets, and the typical hardening steps that move a cluster from default to defensible.
Read this if
Skip this if
Key takeaways
- Treats attacker OPSEC and anonymous infrastructure as seriously as the exploitation itself, which most cloud-pentest material skips.
- Walks a complete, realistic AWS and Kubernetes attack chain end to end rather than isolated techniques.
- The narrative format keeps the tradecraft memorable in a way a reference manual rarely does — closer to Mr. Robot than to a lab manual.
- The Kubernetes security model is API-server-centric — most attacks are RBAC and network-policy failures, and the book makes this its spine.
- Default-deny network policy is the highest-leverage hardening step in any cluster, and the book's framing of why is the most quotable in print.
- Treat it as the on-ramp — once you have the basics, graduate to Kubernetes Security and Observability (Creane / Gupta) and current CNCF guidance.
How they compare
How to Hack Like a Ghost and Kubernetes Security are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.
Both books target intermediate-level readers, so the choice is about topic, not difficulty.
How to Hack Like a Ghost and Kubernetes Security both cover Cloud, so reading them in sequence reinforces the same material from different angles.
Keep reading
How to Hack Like a Ghost
→ Alternatives to How to Hack Like a Ghost→ What to read after How to Hack Like a Ghost