// Comparison

How to Hack Like a Ghost vs Kubernetes Security and Observability: Which Should You Read?

Two cybersecurity books on Cloud, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52021
How to Hack Like a Ghost

Breaching the Cloud

Sparc Flow

A narrated, real-time breach of a fictional data-driven political consulting firm's AWS and Kubernetes environment, written by a working penetration tester who presents at Black Hat and DEF CON.

Advanced
3/52021
Kubernetes Security and Observability

A Holistic Approach to Securing Containers and Cloud-Native Applications

Brendan Creane, Amit Gupta

Brendan Creane and Amit Gupta's combined treatment of Kubernetes security and observability — RBAC, network policy, runtime detection, and the telemetry needed to make any of it operationally real.

Read this if

Pentesters and red teamers who want cloud-specific tradecraft (AWS, Kubernetes, anonymous attacker infrastructure, OPSEC) delivered as a readable narrative rather than a reference manual. The target is fictional; the vulnerabilities it exploits are patterns seen in real cloud environments.
Platform engineers and SRE-security hybrids running production Kubernetes who want a single reference for the security-and-observability boundary. Strongest on the network-policy and runtime-detection sections, where most teams are weakest in practice.

Skip this if

Readers wanting a structured, chapter-by-chapter reference they can jump around in; the book is a continuous narrative from recon to full compromise, better read start to finish than dipped into. Beginners with no cloud or Linux fundamentals will struggle to keep pace.
Readers wanting depth on Kubernetes architecture itself, multi-tenancy patterns, or supply-chain (SLSA, signed images) detail. Also somewhat Calico-flavored — the authors are from Tigera — which is fine if you know to read past the marketing.

Key takeaways

  • Treats attacker OPSEC and anonymous infrastructure as seriously as the exploitation itself, which most cloud-pentest material skips.
  • Walks a complete, realistic AWS and Kubernetes attack chain end to end rather than isolated techniques.
  • The narrative format keeps the tradecraft memorable in a way a reference manual rarely does — closer to Mr. Robot than to a lab manual.
  • Security without observability is unfalsifiable; the book's central argument is that they are one workstream, not two.
  • Network policy is operationally hard, not conceptually hard — the chapters on rolling out default-deny in production are the most useful.
  • Runtime detection is necessary because admission controllers cannot catch everything; the book treats the trade-off honestly.

How they compare

We rate How to Hack Like a Ghost higher (4/5 against 3/5 for Kubernetes Security and Observability). For most readers, that means How to Hack Like a Ghost is the primary pick and Kubernetes Security and Observability is a useful follow-up.

How to Hack Like a Ghost is pitched at intermediate level. Kubernetes Security and Observability is pitched at advanced level. Read the easier one first if you're not yet comfortable with the topic.

How to Hack Like a Ghost and Kubernetes Security and Observability both cover Cloud, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics