A complete, self-contained field manual for breaking into cybersecurity — every fundamental term, 150+ essential tools, free labs, a home-lab blueprint, certification path and a week-by-week 90-day battle plan. No experience required.
tip: open this file in a full browser for clickable links — school it offline, it needs no internet.
Read sections 01–06 to master the fundamentals: the CIA Triad, how networks work, 80+ core terms, how attacks happen and how defenders think. Infographics make it stick.
Set up your own attack/defense home lab (section 09) and drill daily on free platforms like TryHackMe, picoCTF and PortSwigger Academy. Hands-on beats textbooks, always.
Follow the certification ladder (section 12), publish your write-ups on GitHub, join your local community, and apply for SOC/junior analyst roles with a portfolio recruiters can verify.
Cybersecurity is the practice of protecting systems, networks, programs and data from digital attacks, damage and unauthorized access. Every company with a computer needs it — banks, hospitals, mines, governments, your favourite app. That is why the field is enormous, understaffed, and open to curious people who put in the reps.
You can't "buy" security. It's an ongoing cycle: identify assets → protect them → detect failures → respond → recover → improve. Professionals call frameworks for this NIST CSF and ISO 27001.
No system is 100% secure. The job is reducing risk (likelihood × impact) to a level a business accepts — while keeping systems usable. Perfect security that blocks work gets ignored and bypassed.
Defenders think about what could go wrong; attackers prove what does. Learning both sides makes you dangerous (in the good way). Curiosity + persistence + ethics = the profile of every great practitioner.
Data is readable only by authorized people. Tools: encryption, access control, MFA, least privilege.
❌ Broken when: passwords leak, databases are exposed, attackers read your files.
Data and systems stay accurate and unmodified. Tools: hashing, checksums, digital signatures, file integrity monitoring.
❌ Broken when: attackers alter transactions, backdoor code, tamper with logs.
Systems and data remain accessible on demand. Tools: backups, redundancy, DDoS protection, incident response.
❌ Broken when: ransomware locks servers, DDoS floods knock sites offline.
ISC2 estimates a global workforce gap of ~4.8 million unfilled cyber roles. Demand outstrips supply in every region — especially outside pure IT: healthcare, finance, industrial/OT and government.
Entry-level SOC roles commonly start around US$45k–70k+, with experienced engineers/architects well past US$120k. (See the careers table in Section 02.)
Attackers innovate daily; you will learn forever. New clouds, AI attacks, zero-days — the field rewards people who love continuous learning.
Cyber famously hires on demonstrated skill: labs done, CTFs played, write-ups published. Certifications + a home lab portfolio regularly beat formal degrees.
Breaches like Optus and Medibank (2022, ~10M records each), MOVEit, Change Healthcare and Snowflake-related incidents put cybersecurity on front pages globally — and made baseline frameworks (CIS Critical Security Controls, NIST CSF, your national CERT's guidance) must-know vocabulary everywhere. You are entering the field at exactly the right time.
Cybersecurity isn't one job — it's a family of specialisations. The classic split: offensive security (think like an attacker to find weaknesses first) and defensive security (detect, respond, harden). Beginners should explore both for a few months before specialising.
core skills: networking · linux · scripting · web tech · persistence
core skills: logs & SIEM · Windows/AD · networking · calm under pressure
Purple team = red and blue working together in real time: red attacks, blue watches, both compare notes to measurably improve detection. Many modern roles blend both sides — and knowing attack techniques makes you a dramatically better defender (and vice versa).
| Role | What you actually do | Entry route | Indicative salary (USD, varies by region) |
|---|---|---|---|
| SOC Analyst (L1) | Watch SIEM dashboards, triage alerts, investigate phishing, escalate incidents. The classic first job. | Security+ / Google Cert / ISC2 CC + home SIEM lab | US$45k–70k |
| Cyber Security Analyst | Generalist: vuln scans, hardening, awareness training, policy, incident support. | Security+ → CySA+ | US$55k–80k |
| Penetration Tester | Simulate attacks on apps, networks, AD; write reports clients act on. | eJPT / HTB CPTS → OSCP | US$60k–90k (junior–mid) |
| GRC Analyst | Risk assessments, compliance (ISO 27001, Essential Eight, SOCI), audits, vendor reviews. Less coding, more frameworks. | Security+ / ISO 27001 Foundation | US$60k–95k |
| DFIR Specialist | Forensic imaging, memory analysis, malware triage, breach investigation. | SOC experience + BTL1 / GCFA later | US$70k–110k |
| Security Engineer | Design & operate security tooling (EDR, firewalls, IAM, cloud security), automate defenses. | sysadmin/cloud background + certs | US$85k–130k |
| Cloud / AppSec Security | Secure AWS/Azure/K8s, CI/CD pipelines, code review, threat modelling. | dev/cloud skills + security certs | US$95k–150k |
| OT / ICS Security ⭐ | Factories, energy, water, transport — every industry everywhere needs OT protection; people are scarce. | eng/networking + GICSP later | US$85k–140k |
| Security Architect / CISO track | Enterprise-wide security design, strategy, leadership, board-level risk. | years of experience + CISSP/CISM | US$130k–200k+ |
Ranges are indicative global ballparks — they vary hugely by country and sector; check job boards in your region. Universal tip: OT/ICS (industrial) security skills are a genuine niche cheat-code anywhere.
Most openings, clearest entry path, teaches you how attacks really look in logs. 12–24 months here opens every other door.
Helpdesk/sysadmin is a proven on-ramp: you learn AD, networking and users, then pivot internally. Many CISOs started at helpdesk.
Love organisation, writing and frameworks more than terminals? GRC is critical, well-paid, and less technical to enter — Technical skills still help.
Before "hacking tools", you need bedrock. Every senior professional stands on these four: computers & operating systems, networking, the command line (Linux!), and basic scripting. Two focused months here saves you a year of confusion later.
What a CPU, RAM, disk and process actually are; what an OS does; users & permissions; services; the Windows registry; virtualization. Free course: CompTIA A+ material via Professor Messer (YouTube).
IP addresses, MAC addresses, DNS, TCP vs UDP, ports, the OSI model, NAT, DHCP. Networking is to cyber what anatomy is to medicine. Free course: Professor Messer Network+ & Jeremy's IT Lab (CCNA).
~70% of servers and 95% of hacking tools run Linux. Master the terminal: files, permissions, processes, pipes, logs, SSH. Game: OverTheWire: Bandit teaches you by playing.
Python first (automation, tooling, exploit scripts), plus Bash (Linux) and enough PowerShell to recognize attacks on Windows. You don't need to be a software dev — reading code matters most early.
Mnemonic (7→1): "All People Seem To Need Data Processing"
Attacks live at every layer — phishing (7), ARP spoofing (2), SYN floods (4)…
| Port | Service | Why it matters to security |
|---|---|---|
| 20/21 | FTP | Cleartext file transfer — ancient, often misconfigured, gold for attackers |
| 22 | SSH | Secure remote admin — brute-forced constantly; use keys + fail2ban |
| 23 | Telnet | Cleartext remote login — if you see this open, it's a finding |
| 25 / 587 | SMTP | Email sending — abused for spoofing/phishing; check SPF/DKIM/DMARC |
| 53 | DNS | The phonebook of the internet — tunneling & exfiltration hide here |
| 67/68 | DHCP | Hands out IP addresses — rogue DHCP = easy MITM |
| 80 / 443 | HTTP / HTTPS | Web traffic. Where most attacks and most of your career will live |
| 110 / 143 | POP3 / IMAP | Email retrieval — legacy cleartext versions still haunt networks |
| 139 / 445 | NetBIOS / SMB | Windows file sharing — WannaCry/NotPetya spread via SMB. Critical. |
| 161/162 | SNMP | Device monitoring — default community string "public" leaks everything |
| 389 / 636 | LDAP / LDAPS | Directory lookups — the map of Active Directory for attackers |
| 88 | Kerberos | AD authentication — Kerberoasting, golden tickets live here |
| 1433 / 3306 / 5432 | MSSQL / MySQL / Postgres | Databases — should never face the internet; SQL injection's target |
| 3389 | RDP | Remote Desktop — #1 ransomware entry point. Always MFA / VPN first |
| 5985/5986 | WinRM | Windows remote management — lateral movement highway |
| 6379 / 27017 | Redis / MongoDB | NoSQL stores — historically wide-open, mass-exploited |
| 5900 | VNC | Remote screen sharing — weak/no passwords in the wild |
| 8080 / 8443 | HTTP-alt proxies | Dev servers, admin panels forget they're exposed here |
pwd · ls -la · cd
find / -name flag.txt
grep -R "password" .
locate · which · cat · less
Everything in Linux is a file — including devices and config. Learn to explore it.
chmod 755 script.sh
chown user:group file
sudo · su · id · whoami
/etc/passwd · /etc/shadow
Privilege escalation = abusing misconfigured permissions. Learn them deeply.
ip a · ip r · ss -tulpn
ps aux · top · kill
curl · wget · ssh · scp
systemctl status sshd
See what's listening, what's talking, what's running — attacker's AND defender's view.
Play OverTheWire: Bandit levels 0–30 (free, in your browser/terminal via SSH). You'll learn every command above by capturing flags, and you'll finish genuinely comfortable in a Linux shell. It's the single best Linux primer for future hackers.
80+ terms you will hear on day one of any job, course or CTF. Filter by theme, or search anything. Read these slowly — they're the vocabulary everything else is built from.
A weakness that can be exploited — a bug, misconfiguration or missing control. e.g. unpatched software, default passwords.
Code or technique that takes advantage of a vulnerability to cause unintended behaviour.
Anything that can cause harm: a hacker, malware, a disgruntled employee, even a flood in the server room.
Risk = Likelihood × Impact. The chance a threat exploits a vulnerability, and how bad it would be.
Every point where an attacker could try to enter: open ports, web apps, APIs, employees, suppliers.
The part of an attack that does the damage/action — e.g. the ransomware binary, or a reverse shell.
A vulnerability exploited before the vendor knows or has a patch. The most valuable kind of bug.
Common Vulnerabilities & Exposures — the public ID system for known flaws, e.g. CVE-2021-44228 (Log4Shell).
Severity score (0–10) for CVEs. 9.0+ = "drop everything and patch".
Vendor's fix for a vulnerability. "Patch Tuesday" (Microsoft, monthly) shapes the industry's rhythm.
The "who": script kiddies, cybercriminals, hacktivists, insiders, nation-state groups.
Advanced Persistent Threat — well-resourced groups (often state-backed) that stay hidden for months/years.
Indicator of Compromise — a forensic breadcrumb: malicious IP, file hash, domain, registry key.
Tactics, Techniques & Procedures — how an adversary operates, catalogued in the MITRE ATT&CK framework.
Anything worth protecting: data, servers, laptops, credentials, reputation.
Reducing attack surface: remove unneeded services, apply secure configs (see CIS Benchmarks).
The path/method used to get in: phishing email, exposed RDP, poisoned update, USB drop.
An incident where data/security controls are actually compromised. Reportable under privacy laws (in AU: Notifiable Data Breaches scheme).
Fraudulent messages tricking people into clicking links, opening malware or giving up credentials. #1 initial access method worldwide.
Targeted phishing at a specific person; whaling targets executives.
Any malicious software: viruses, worms, trojans, ransomware, spyware… (full taxonomy in Section 05).
Encrypts victim files and demands payment. Modern crews add "double extortion": leak the data too.
(Distributed) Denial of Service — flood a service until it falls over. Attacks Availability.
Man-in-the-Middle — secretly relaying/altering traffic between two parties (evil Wi-Fi AP, ARP spoofing).
Putting database commands into an app's input fields. Can dump entire databases. Classic, deadly, preventable.
Cross-Site Scripting — injecting JavaScript into pages other users view; steals sessions, defaces, phishes.
Cross-Site Request Forgery — riding a victim's logged-in session to perform unwanted actions.
Trying every password combination. Slow but sure against weak passwords; throttled by lockouts/MFA.
Replaying breached email:password combos on other sites, betting users reuse passwords. They do.
Going from low-privilege user to admin/root (vertical) or another user's account (horizontal).
Hopping between machines inside a network after the first foothold.
Target machine connects back to the attacker, giving remote command control. The classic payload.
The attacker's infrastructure used to control compromised machines and receive stolen data.
Getting stolen data out of the network — over DNS, HTTPS, cloud storage…
Techniques to survive reboots and password resets: services, scheduled tasks, registry run keys, webshells.
Writing past a memory buffer's boundary to hijack execution. The grandfather of exploitation; learn the theory even if modern mitigations exist.
"Hacking humans" — manipulating people instead of systems: pretext calls, tailgating into buildings, urgency scams.
Active Directory attacks reusing stolen password hashes / cracking service-account tickets. Bread and butter of AD pentesting.
Filters traffic by rules (IP/port/protocol). Network (perimeter) and host-based flavours.
Intrusion Detection watches & alerts; Intrusion Prevention sits inline and blocks. Tools: Snort, Suricata, Zeek.
Security Information & Event Management — collects and correlates logs from everything; the SOC's cockpit. Tools: Splunk, Elastic, Wazuh, Sentinel.
Security Operations Center — the team (and room) that monitors and responds 24/7. Where most careers start.
Endpoint (eXtended) Detection & Response — agents on devices that detect and stop malicious behaviour. CrowdStrike, Defender for Endpoint.
Signature/behaviour-based malware blocking. Necessary but alone insufficient.
Multi-Factor Authentication — password + something you have/are. Blocks the vast majority of account takeovers.
Identity & Access Management / Privileged Access Management — who can access what, and controlling admin accounts.
Give every user/process only the access it needs — nothing more. Kills lateral movement.
"Never trust, always verify" — no automatic trust even inside the network; authenticate & authorise everything, continuously.
Splitting networks into zones so a breach in one can't spread — like ship bulkheads.
Buffer network between internet and internal LAN where public-facing servers live.
A decoy system with no legitimate users — anyone touching it is malicious by definition. Great early-warning + research tool. Try: Cowrie, T-Pot.
Isolated environment to safely detonate/observe suspicious files. Tools: Cuckoo, Any.Run, Hybrid Analysis.
Data Loss Prevention — tooling that detects/blocks sensitive data leaving the org.
The structured reaction to a breach. Lifecycle: Prepare → Detect → Contain → Eradicate → Recover → Learn.
Digital Forensics & Incident Response — the discipline of investigating what happened from artifacts (disk, memory, logs).
Proactively searching for attackers who evaded alerts, using hypotheses + data. "Assume breach."
Tracking, testing and deploying updates. Unglamorous, massively effective.
The globally-used prioritized set of 18 defensive actions. Also know your national CERT's baseline guidance — interview gold anywhere.
Step-by-step response guides ("phishing email playbook") so juniors respond like veterans at 3am.
Open-Source Intelligence — collecting info from public sources. Used by attackers to target you and defenders to investigate.
Logical network address (IPv4 203.0.113.5 / IPv6). Public vs private ranges (10.x, 172.16–31.x, 192.168.x).
Hardware address of a network card, used on the local link (Layer 2). Spoofable.
Domain Name System — translates names (google.com) to IPs. DNS poisoning/tunneling are attack staples.
TCP = reliable, connection-oriented (3-way handshake SYN/ACK). UDP = fast, connectionless (DNS, streaming, games).
A numbered door (0–65535) identifying a service on a host. Well-known: 0–1023. See the table in Section 03.
Automatically assigns IP addresses when you join a network.
Network Address Translation — many private devices sharing one public IP. Your home router does this.
Dividing networks: 192.168.1.0/24 = 256 addresses (/24 = first 24 bits fixed).
Encrypted tunnel over untrusted networks — for remote workers and privacy.
Intermediary for requests; forward proxy hides clients, reverse proxy fronts servers (also a security control point).
Maps IP→MAC on a LAN. ARP spoofing = classic local MITM technique.
Encryption for traffic in transit — the padlock in HTTPS. SSL is dead; TLS 1.2/1.3 is correct.
Reversible scrambling with a key. Symmetric (one shared key — AES) vs Asymmetric (public/private key pair — RSA, ECC).
One-way fingerprint (SHA-256, bcrypt). Used for integrity checks and password storage. Not encryption — can't be "decrypted".
Random data added before hashing passwords so identical passwords get different hashes — defeats rainbow tables.
Asymmetric crypto proving a message/software came from you and wasn't altered (authenticity + integrity).
Public Key Infrastructure — the certificate authority system that makes HTTPS trust possible.
Precomputed hash→password lookup tables. Why unsalted fast hashes (MD5!) are terrible for passwords.
Hiding data inside other data (messages in image pixels). Favourite of CTF forensics challenges — tools: steghide, zsteg.
The "you are logged in" artifact (cookie/JWT). Stealing one = session hijacking. Guard with HttpOnly + short expiry + MFA.
Authorized, scoped, time-boxed simulated attack delivering a fix-it report. "Pentest". Requires written permission — always.
Automated scanning for known weaknesses (Nessus/OpenVAS). Breadth-first cousin of pentesting.
Offense / defense / collaboration exercises. (Section 02 covers the roles.)
Companies pay researchers for valid vulnerability reports via HackerOne/Bugcrowd. Legal hacking for money — but only in defined scope.
Capture The Flag — gamified security challenges where you find "flag{...}" strings. The sport of the industry (Section 11).
Lawful-ethical hackers / criminal hackers / somewhere in between. Aim to be unambiguously white hat.
Reporting a found vulnerability privately to the vendor so they can fix it before going public (typically ~90 days).
The legal contract defining what a pentester may and may not touch. Breaking scope = breaking the law.
The global knowledge base of adversary TTPs (Recon, Initial Access, Execution… Exfiltration). Learn to read it — the industry's shared map.
The secret string proving you solved a challenge: flag{y0u_f0und_m3}. Addictive — you've been warned.
To defend (or ethically attack) systems you must understand the adversary's playbook. Here's the complete beginner taxonomy: malware species, human hacking, and the famous Cyber Kill Chain — the model that breaks every attack into 7 defendable stages.
Attaches to a host file/program, needs user action to spread (open the file → infect). The original malware.
Replicates across networks by itself — no user needed. WannaCry (2017) wormed via SMB and hit 200,000+ machines in days.
Poses as legitimate software ("free photoshop crack") carrying a hidden payload. Doesn't self-replicate.
Encrypts your files, demands crypto payment. Modern gangs also steal data first ("double extortion"). Defence: offline backups + segmentation + MFA.
Silently monitors: keystrokes, screens, messages. Stalkerware is the consumer cousin.
Buries deep into the OS (drivers/kernel) to hide itself and maintain access. Extremely hard to detect/remove.
Records every keystroke — passwords, messages, everything. Hardware and software varieties exist.
Thousands of infected "zombie" devices controlled from one C2, used for DDoS, spam, mining. Mirai enslaved IoT cameras.
Remote Access Trojan — full remote control: files, webcam, mic. Delivered via phishing macros & cracked software.
Dormant code triggered by a condition — a date, an employee being removed from payroll. Favoured by malicious insiders.
Pure destruction — erases disks. NotPetya (2017) cost $10B globally; used heavily in the Ukraine conflict.
Forced ads & tracking, often bundled with "free" software. Usually grey-area legally, always a privacy problem.
Secretly mines cryptocurrency with your CPU/cloud bill. Signs: fans screaming, sluggish servers.
Lives in memory and legitimate tools (PowerShell, WMI) — nothing on disk for AV to scan. Detections focus on behaviour.
Stage 1 malware whose only job is to download/install the real payload — often bought as a service. Initial access → bigger infection.
"YOUR PC IS INFECTED — PAY $99!" manipulates fear. Social engineering dressed as software.
Mass emails with malicious links/attachments, fake login pages. Defend: verify sender, hover links, report button, MFA.
SMS phishing ("AusPost: fee required") & voice phishing ("IT helpdesk here, read me your MFA code"). Defend: never act via the contact they gave you — call back on official numbers.
Invented scenario to extract info: "auditor", "new colleague", "vendor survey". Defend: verify identity through known channels.
Curiosity trap: "FREE MUSIC" download, USB labelled "SALARIES 2026" left in the car park. Defend: never plug in found USBs.
Following an employee through a secure door ("hands full, mate?"). Defend: badge everyone, politely challenge strangers.
"CEO needs this gift card NOW", "your account closes in 1 hour". Defend: urgency + secrecy = red flags, always.
AI-cloned executives approving wire transfers — a growing 2020s threat. Defend: out-of-band verification for money/secret requests.
Spamming push notifications until the victim taps "Approve". Defend: number-matching MFA; deny + report unexpected prompts.
Morris Worm (1988, first internet worm) → ILOVEYOU (2000, email worm) → Stuxnet (2010, destroyed centrifuges via USB) → WannaCry / NotPetya (2017, global chaos in hours) → SolarWinds (2020, supply-chain espionage) → Log4Shell (2021, one Java logging bug shook the world) → Optus & Medibank (2022, a national wake-up call). Watch Darknet Diaries episodes on each — best free history class there is.
Animated walkthroughs of the four attacks you must understand fluently as a beginner. Replay them mentally until you could explain each on a whiteboard — interviewers love exactly this.
Untrusted input reaches an interpreter as commands. SQLi dumps databases; OS command injection runs shell commands. Fix: parameterization, allowlists.
Inject JavaScript into pages others view (reflected/stored/DOM). Steal sessions, deface, keylog. Fix: output encoding, CSP headers.
Change /invoice?id=1042 → 1043 and see someone else's invoice. The most exploited class today. Fix: server-side authorization on every object.
Trick a logged-in browser into making requests. Fix: anti-CSRF tokens, SameSite cookies.
Make the server fetch attacker-chosen URLs — reach internal cloud metadata (169.254.169.254) and steal AWS keys. Fix: egress allowlists.
../../etc/passwd — escaping the web root to read (or include) server files. Fix: canonicalization, chroot jails.
Upload shell.php as an "avatar", visit it, get a web shell. Fix: type checks, rename, store outside webroot, no exec.
Weak session IDs, no lockouts, password reset flaws, missing MFA. Fix: standard libraries, MFA, secure cookie flags.
One outdated library = whole app owned (see Log4Shell). Fix: SBOMs, dependency scanning (npm audit, Dependabot), patching.
No single tool stops a determined attacker. Professionals stack layers so that when one fails (one always eventually does), another catches the attack. This is the mindset that separates security thinking from "install antivirus and pray".
Every device ships logs to a SIEM (Splunk, Elastic, Wazuh). Detection rules (Sigma, KQL) match patterns: "impossible travel login", "known C2 domain", "mimikatz-like process" → an alert fires and an analyst (you!) investigates.
Triage mantra: WHAT happened → IS it real (true positive?) → HOW bad → CONTAIN → ESCALATE.
Traffic cop at the network edge & inside. "Next-gen" adds app-awareness & TLS inspection.
Sniffs traffic for attack signatures & anomalies (IPS blocks inline).
Central log brain: collects, correlates, alerts, dashboards, compliance reports.
Agent on every laptop/server watching processes & behaviour; can isolate a host with one click.
Filters phishing/malware before inboxes; URL rewriting & attachment detonation.
Identity is the new perimeter: SSO, MFA, just-in-time admin, vaulted credentials.
Continuous scanning + prioritised patching of the whole fleet.
Automates response: isolate host, block sender, reset creds — in seconds, not hours.
MITRE ATT&CK — catalogue of real adversary techniques · NIST CSF — identify/protect/detect/respond/recover (+govern) · CIS Critical Security Controls — the globally-used prioritized defensive baseline (also know your national CERT's guidance, e.g. ACSC's Essential Eight) · ISO 27001 — the international security management standard. Cite these confidently and you sound like a pro, fast.
The working professional's toolbox, organised by job function. Every tool includes a one-line purpose and example usage. Start with the ⭐ beginner picks; grow into the rest. (Almost everything here is free and open source.)
One download = hundreds of preinstalled tools. Install in a VM (Section 09), never as your daily driver OS holding personal files.
Start here. Prebuilt with Nmap, Metasploit, Burp, Wireshark & 600 more. Free from kali.org — run it as a VM.
Beautiful, lighter on RAM (good for older laptops), includes anon tools like Tor/AnonSurf.
Enormous arsenal on Arch Linux. Fantastic once you're comfortable with Linux — not day-one material.
Turns a Windows VM into an attack box — perfect for Active Directory practice on the platform attackers actually target.
Preloaded with malware-dissection tools (Ghidra, PE tools, fake network services). Pair with Flare VM.
Mandiant's Windows box of debuggers/decompilers for safe malware study in an isolated VM.
DFIR toolkit matching SANS courses: timeline analysis, memory forensics, registry tools.
Bundles Suricata, Zeek, Elastic, Kibana, CyberChef. Build this in your home lab = real blue-team experience on your resume.
"Amateurs hack systems; professionals hack information first." Enumeration is 80% of every engagement and CTF.
The network scanner: discover hosts, open ports, service versions, OS, run scripted checks (-sC). Learn it until flags are muscle memory.
Point-and-click Nmap with topology maps. Great while you memorise CLI flags.
Blazing-fast port scanner that pipes results into Nmap. CTF favourite: full port sweep in seconds.
Scans absurdly fast (the whole internet in minutes). Careless use = knocking on every door in town.
Read/write raw network connections: banner grab, chat, transfer files, catch reverse shells. Tiny tool, infinite uses.
Simple friendly GUI ping/port sweeper — handy for surveying your home lab.
The search engine of internet-connected devices: open cams, exposed databases, ICS gear. Recon without sending a single packet.
Shodan's scholarly sibling: internet-scan data + TLS certificate history to map any org's footprint.
Harvests emails, subdomains, employee names from public sources — builds a phishing-target list (defenders: audit yourself!).
OWASP's deep subdomain enumerator — discovers an org's forgotten dev/staging servers where bugs breed.
Fast passive subdomain discovery. Pipe into httpx → live web targets in two commands.
Modular web-recon framework with marketplace modules — automates the "who are they?" phase.
Rips users, shares, and policy info out of Windows/Samba hosts. First stop on any box with SMB open.
Reading packets is a superpower for both teams: attackers sniff secrets; defenders see evil hiding in plain sight.
The world's most-used protocol analyser. Capture traffic, follow TCP streams, carve files. Do the Wireshark TryHackMe room early.
Terminal packet capture for servers and CTF boxes. The flags look scary; learn five and you're set.
Scriptable Wireshark — extract fields from huge pcaps, perfect for CTF automation.
Turns raw traffic into structured logs (conn.log, dns.log, http.log). Core of network security monitoring & Security Onion.
Passive sniffer that rebuilds files, images, credentials from pcaps. Blue-team CTF darling.
Beautiful desktop app for hunting through pcaps with Zed queries. Great intro to network forensics.
Classic ARP-poisoning/MITM suite for your lab only. Seeing cleartext creds fly by teaches why TLS matters.
Modern MITM framework: ARP/DNS spoofing, wifi attacks, credential capture. The attacker's Wireshark.
Web is the most beginner-friendly (and most employed) attack surface. Master these and PortSwigger Academy and you can do real bug bounties.
The web-tester's weapon #1: intercept, replay (Repeater), fuzz (Intruder), scan (Pro). Community Edition is free — learn it deeply.
100% free/open from OWASP. Great for automated scans and CI pipelines. Teams often run both ZAP and Burp.
Already installed! Inspect requests, cookies, localStorage, JavaScript. Solve XSS labs with nothing else.
Brute-forces hidden directories/files (/admin, /backup.zip), virtual hosts and subdomains.
"Fuzz Faster U Fool": fuzz parameters, dirs, vhosts at high speed with fine filters. CTF essential.
Veteran web server scanner: outdated software, dangerous files, misconfigs. Noisy — which is a lesson itself.
Detects & exploits SQL injection automatically — even dumps databases. Learn manual SQLi first, then let sqlmap flex.
WordPress = 40%+ of the web. WPScan finds vulnerable plugins/themes and enumerates users.
Community template–driven scanner: thousands of one-click CVE/misconfig checks. Bug-bounty hunters live in it.
Identifies CMS, frameworks, server tech on any site — shapes your attack plan instantly.
Probes huge host lists: which are live, what tech, what status. Glue tool of recon pipelines.
APIs leak data constantly (see OWASP API Top 10). Postman is how you poke them methodically.
Fast, pretty newcomer for HTTP interception — nice alternative when Burp CE rate-limits Intruder.
Where vulnerabilities become shells. Practice these ONLY in your lab and on legal platforms — see the ethics banner, always.
The legendary exploit framework: 2,000+ modules, payloads and post-ex modules. The free "Metasploit Unleashed" course is a rite of passage.
Metasploit's payload factory: generate shells for any platform/format. Learn payloads by building them.
Metasploit's in-memory super-shell: file system control, keylogging, pivoting, privilege escalation — all living in RAM.
Offline copy of the Exploit Database. Found a service version? Searchsploit finds the public exploit. CTF daily driver.
Browser Exploitation Framework — demonstrates why XSS is terrifying: control the victim's browser in real time.
TrustedSec's framework for authorized social-engineering simulations. Why "think before you click" training exists.
Python classes for attacking Windows protocols — the toolbox behind most AD exploitation and Kerberos attacks.
CrackMapExec's successor: validate creds, spray, dump, execute across whole subnets. AD pentest essential.
Poisons LLMNR/NBT-NS on Windows networks and catches password hashes from thin air. Lab-only; shows why those protocols die in secure orgs.
The comfortable way to land on Windows via WinRM with creds or a hash. HTB players' best friend.
Relay traffic through compromised hosts to reach hidden networks — pivoting made simple.
Humans pick terrible passwords; these tools prove it — in your lab, for system owners, or on leaked-hash CTF challenges.
The fastest hash cracker on earth, powered by your GPU. Combine wordlists + rules to crack NTLM/SHA/etc. Benchmark it once — it's fun.
The classic cracker, superb on Linux/Unix hashes (/etc/shadow). Pairs with ssh2john/zip2john to crack archives & keys.
Parallel online login attacks against SSH/FTP/web forms/RDP. Use in labs; in the real world it locks accounts and trips alarms.
Hydra's stable, speedy cousin. Know both; they complement oddly-specific services.
Ships with Kali (gzip'd at /usr/share/wordlists). The definitive wordlist — together with SecLists it forms 90% of password challenges.
Daniel Miessler's curated collection for every wordlist need — especially web dirs and parameter names.
Spiders a website to build a company-flavoured wordlist ("AcmeCorp2026!"). Passwords come from culture — exploit it (with permission).
Online rainbow-table lookup for quick checks; Name-That-Hash identifies unknown hash formats instantly.
Getting in is half the story. These find the misconfigurations that turn "limited shell" into "Domain Admin".
PEASS-ng scripts auto-enumerate Linux/Windows privilege-escalation vectors in screaming colour. Run them on every CTF box.
Bible of Unix binaries that can be abused (sudo, SUID, capabilities) to escalate. Bookmark it forever.
Windows equivalent: legit Microsoft binaries attackers abuse (certutil download, mshta execution). Defenders monitor for these too.
Extracts plaintext creds, hashes and tickets from Windows memory. The tool that made "credential hygiene" a boardroom topic.
Maps Active Directory attack paths as a graph — reveals "Helpdesk→3 hops→Domain Admin" chains instantly. Red and blue both swear by it.
PowerSploit's Windows enumeration checks: unquoted service paths, weak service ACLs, AlwaysInstallElevated…
C# host enum swiss-army: who am I, what's here, what's defensible. Part of the standard C2 toolkit experience.
The go-to for Kerberos attacks: kerberoasting, AS-REP roasting, ticket manipulation.
Watches every process spawning (even other users') without privileges — exposes cron scripts and mistyped passwords.
Compares kernel/distro versions against known local-exploit lists (DirtyCow era classic). LES + LinPEAS = the standard workflow.
You'll need a USB Wi-Fi adapter that supports monitor mode (Alfa AWUS036-series are the community favourites).
The complete Wi-Fi audit suite: monitor, capture handshakes, deauth, crack WPA keys. The official tutorial is a legendary first lab.
Automates Aircrack attacks end-to-end: WEP/WPA/WPS. Great for understanding the attack chain hands-on.
Passive wireless sniffer/IDS — maps networks, detects rogue access points. The defender's wireless eyes.
Modern clientless WPA attacks — grab a crackable hash without any client connected. Then feed hashcat.
Attacks WPS PIN weakness on older routers. Mostly dead on modern gear — but knowing why = interview points.
Create lookalike networks and harvest hand-ins from unsuspecting devices — the evil-twin demo every awareness training uses.
The science of answering "what happened?" from artifacts. Quietly one of the most employable and satisfying specialties.
Free, friendly forensic platform for disk images. Recover deleted files, browser history, USB artifacts. The CyberDefenders labs pair perfectly.
Analyse RAM captures: running processes, injected code, connections, credentials in memory. Memory never lies.
Industry-standard imaging tool (free!). First rule of forensics: work on images, never originals.
Eric Zimmerman's Kroll Artifact Parser & Extractor — grabs registry hives, event logs, browser data fast for offline analysis.
The definitive Windows artifact parsers. Real IR shops run on these. Free with training videos.
Case captures constantly hide exfil in DNS/HTTP — carve it out and prove it.
Reads/writes metadata in hundreds of formats. CTF stego staple; real-world leak detector (phones embed GPS!).
Finds & extracts files hidden inside other files/firmware. First command in CTF forensics.
Recover lost partitions and deleted files by signature — also handy when ransomware nukes a test VM.
Builds a unified timeline from disks, logs, browsers. Timelines answer "when, then what?" — the heart of IR storytelling.
Open-source DFIR platform: hunt VQL queries across thousands of endpoints in seconds. Enterpise-grade and free.
The friendly front-ends that make Windows forensics approachable while you learn the artifacts.
Open malicious files safely in REMnux/FLARE VMs with the network shut off — see the lab safety rules before you ever detonate anything.
NSA's released RE suite — professional-grade and free. Disassemble, decompile, patch. Start with crackmes.
The famous Interactive Disassembler. Most tutorials/books use IDA — worth learning the UI early.
Open-source Windows debugger for dynamic analysis and crackmes. Friendlier than WinDbg for beginners.
Free RE framework beloved by CTF players for binaries on any architecture.
Instant suspicious-file triage: what it imports, what it pretends to be, MITRE mappings.
Interactive online sandbox: click like a user, watch processes/network in real time. Free tier + great public reports to learn from.
Free CrowdStrike sandbox — excellent static+dynamic reports when studying samples safely from your browser.
Lookup hashes/URLs across dozens of AV engines + sandbox telemetry. Daily reference for analysts. (Don't upload real secret files!)
Write pattern rules to classify/hunt malware. Every SOC, sandbox and CTF uses YARA — learn the syntax day one.
Windows dynamic-analysis eyes: see exactly what a program does. Sysinternals Suite is mandatory Windows study anyway.
Simulate DNS/HTTP services in an isolated VM so malware reveals its C2 behaviour safely.
Identifies packers (UPX!), compilers, protections — step 1 before unpacking.
Install these in your home lab and you can honestly list SIEM/EDR/IDS experience on your resume.
The enterprise SIEM leader — free 500MB/day tier is plenty for a lab. Splunk skills = directly employable; free Fundamentals course + Boss of the SOC dataset.
Free open-source SIEM/XDR: file integrity, vulnerability detection, MITRE-mapped alerts. The best first blue-lab install.
Elasticsearch + Kibana + Beats/Agents power countless SOCs. Learn KQL-style querying once, use it everywhere.
Fast IDS/IPS using ET Open rules. Feed it homelab traffic, watch it bark at your own Nmap scans.
The original open-source IDS (1998!) — still everywhere, still taught in certs. Learn rule syntax once: alert tcp any any → any 445.
Security Onion ships Zeek+Suricata+Elastic pre-integrated: a real SOC console in one VM (see Section 09).
FreeBSD firewall/router distro — learn NAT, rules, VLANs, VPNs by actually building them. Core of serious home labs.
Turns Windows Event Logs from "meh" into a goldmine: process creation, network connections, loading of suspicious DLLs. Pair with Wazuh/Splunk.
The open standard for detections ("detect mimikatz-like process names"). Write one rule, run it in Splunk/Elastic anywhere.
FREE friendly log platform with streams, pipelines, alerts — a gentler first SIEM than the giants.
Tiny daemon that bans brute-forcers by tailing logs. Install on any internet-facing Linux box — and on day one of any VPS.
Drag-and-drop playbooks: alert → enrich (VT, AbuseIPDB) → block. Learn SOAR concepts free.
Automated adversary emulation platform. Purple-team your lab: fire techniques, confirm your SIEM catches them.
Find out what the internet already knows. Used by pentesters for recon, SOCs for investigations — and by you to check your own footprint.
Visual intelligence graphs connecting people, domains, IPs, breaches. Free Community edition in Kali.
Advanced search operators expose forgotten files, admin panels, cameras. Free, powerful, underrated — master the syntax.
Interactive tree of hundreds of OSINT resources by category (usernames, emails, images, leaks…).
(See Recon section.) OSINT and recon are cousins — these tools sit at the border.
Finds where a username exists across hundreds of platforms. Prolific for investigations (and self-auditing).
Automates massive OSINT sweeps: DNS, breaches, emails, darknet mentions. Great for footprinting an org.
Troy Hunt's legendary service. Check your own accounts, enable the free notify-list. A household name in security.
Historical snapshots of any site: find removed admin pages, old emails, "deleted" evidence.
Trace images across the web: sock accounts fall apart fast with these.
Custom search consoles for social, breaches, maps & more from the author of "OSINT Techniques".
Investigate phone numbers: Truecaller hits, disposable-number flags. Great for vishing investigations.
Profiles a company's web tech → targets for both attacks and job interviews ("I see you use Splunk…").
Crowdsourced IP abuse reports — the SOC's reflex check on every alert IP.
Find weaknesses before attackers do, and prove it with reports. An everyday corporate task — great to have on your resume.
Open-source enterprise-grade vulnerability scanner. Runs in your lab VM and produces pro-looking reports.
Tenable's famous scanner, free for home labs. Learn the interface — you'll meet it at work, guaranteed.
Belongs here too — continuous, scriptable vuln checks with community templates.
Audits a Linux host against best practices and tells you exactly what to fix. Run it on your own VPS for instant wins.
Automated compliance scoring against the famous CIS hardening benchmarks — GRC meets engineering.
The small tools you'll use daily, whichever team you join.
GCHQ's "Cyber Swiss Army Knife": 300+ operations — encoding, crypto, compression, extraction. CTF oxygen.
Caesar to Vigenère to mystery hashes — classic-crypto challenges solved in seconds.
The pentester's encyclopedia: every service, misconfig and technique with commands. The community's brain, free.
GitHub repo of curated payloads/methodologies (SQLi, XSS, SSRF…). CTF clipboard.
Every language's reverse/bind shell, plus URL/Base64 encoding. Saves real time in labs.
Interactive cheat-sheet for Windows/AD: filters by what you have (creds? shell?) and shows commands.
Split screens for scan + listener + notes, and never lose a session. A pro's terminal looks like tmux.
Document every machine, command and lesson. Your notes become your portfolio and future self's gift.
One-stop online steganography triage for CTFs.
Classic hidden-data tools (zsteg shines on PNG/BMP LSB data).
Spin up vulnerable apps (Juice Shop!), tools and malware sandboxes without polluting your VM. Learn basic Docker — it's how labs are shipped now.
Free hypervisors hosting your Kali + targets + SIEM. Section 09 builds on them. (VirtualBox is free; VMware Workstation Pro is now free for personal use.)
Credibility rule #1: secure yourself. Set this up in week one; it also doubles as your first mini-project.
Open source, free, everywhere. Non-negotiable modern hygiene — password reuse is how people get owned.
Fully offline alternative beloved by the paranoid (healthy paranoia). Kali users' default.
App-based MFA with encrypted backup. Turn MFA on for email first, then everything else.
Free TrueCrypt successor — encrypt research, notes and VM drives on shared machines.
Reputable no-log VPNs for untrusted Wi-Fi. (A VPN is privacy hygiene, not magic invisibility.)
Malvertising is a real attack vector. Harden your daily browser, too — you are a target now.
End-to-end encrypted messaging with sealed-sender design. Community standard.
Run offensive tools only inside your isolated lab VMs or on platforms that explicitly permit it (TryHackMe, HTB, CTFs, bug bounty scope). Scanning or attacking systems you don't own or lack written permission for is a crime nearly everywhere in the world (US CFAA, UK Computer Misuse Act, and national equivalents). Skill + ethics = employable. Skill without ethics = criminal record.
The proven sequence. Each phase builds on the last; each ends with something you can show. Realistic pace: 60–90 minutes daily, weekends for labs. (The detailed week-by-week version is the 90-Day Plan in Section 13.)
Install VirtualBox/VMware + Kali VM. Create TryHackMe, picoCTF, OverTheWire accounts. Set up Bitwarden + MFA on your own accounts. Start a notes system (Obsidian) — professionals document everything.
Professor Messer's free Network+ playlist (don't need the exam yet — the knowledge). Simultaneously grind OverTheWire Bandit to ~level 25 and TryHackMe's Pre-Security path. Basic Python: automate one boring task.
TryHackMe Introduction to Cyber Security + SOC Level 1 or Jr Penetration Tester path (pick per interest). Learn Nmap, Wireshark, Burp basics; read Section 04–06 of this guide until fluent. Start picoCTF general-skills challenges.
Pick a lane (SOC vs pentest vs GRC — you can switch later). Build the full home lab (Section 09): targets + Wazuh/Splunk watching them. Study with Professor Messer + practice exams and book CompTIA Security+ (or start with free ISC2 CC first). Add HackTheBox Starting Point or PortSwigger Academy tracks.
Weekly CTFs (CTFtime), one flagged machine write-up a week, polish LinkedIn (list labs & projects!), attend BSides cons, OWASP/ISACA chapters and local meetups. Apply for SOC L1, service-desk-with-security, internships, grad programs (banks, telcos, consultancies, government) while continuing labs. Interviews love people who never stopped building.
You now own the same machine professionals hack banks (legally) with.
Feel the hacker-loop: stuck → research → solve → flag → dopamine.
Guided, browser-based, zero install — this is your structured course for months.
Beginner hype is fuel — use it.
Security people secure themselves first — always.
Small daily sessions beat weekend binges. 45–90 focused minutes every day + one longer lab on the weekend. Take notes on everything (future you is forgetful). When stuck >30 min, look up a hint — time-boxed struggle is learning; endless struggle is quitting fuel.
Don't choose yet. Do two months of TryHackMe's both-track content, a picoCTF (offense flavour) and a couple of CyberDefenders blue labs (defense flavour). Your energy levels while doing them will tell you the answer better than any quiz.
A home lab is the single best career accelerator: a safe, legal network where you attack VMs, then watch your own SIEM catch yourself doing it. Both red and blue skills from one laptop. Here's the exact blueprint.
① Lab VMs use host-only/internal networks — never bridged, especially when malware is involved. ② Only connect NAT briefly for updates, then disconnect. ③ Never use real personal files/passwords inside lab VMs. ④ Malware samples only inside fully-isolated VMs with snapshots — and never let them reach the internet. ⑤ Snapshot before everything; nuke-and-restore when in doubt. ⑥ Attack only lab IPs/platforms — no "testing" school/work/neighbour networks.
Nmap/Metasploit Metasploitable2 from Kali → review what Wazuh/Splunk captured → write it up: attack steps, IOCs, detection rule.
Craft a lab phishing simulation (SET) → land on Windows VM with Sysmon → trace the chain in Splunk → write a Sigma rule that catches it.
Windows Server as Domain Controller + Win10 client. Create users/GPOs → run BloodHound → attack path with NetExec → map every step to MITRE ATT&CK.
Isolated REMnux/FLARE pair detonating a known sample: PEStudio + Procmon + FakeNet → YARA rule from observed strings/behaviour.
Full OWASP Top-10 sweep of Juice Shop with Burp → professional-style report: findings, evidence, risk ratings, fixes.
Add pfSense: VLANs for "users/servers/guest", firewall rules between them → prove with scans that lateral movement is now blocked.
Organised from "day one friendly" to "seasoned". Nearly all have generous free tiers. These are 100% legal environments designed to be hacked — so break everything with joy.
Browser-based guided "rooms" with built-in attack VMs. Paths: Pre-Security → Intro to Cyber → SOC L1 / Jr Pentester. The smoothest on-ramp in existence; free tier is genuinely usable, premium (~US$14/mo) unlocks all rooms.
SSH wargame teaching Linux command-line through 34 puzzle levels. Free, legendary, frustrating in the best way.
Carnegie Mellon's free beginner CTF. picoGym practice challenges cover all categories year-round and are gentle enough for week one.
From the makers of Burp Suite: the best free web-security course in the world — bite theory + interactive labs for every vulnerability class.
ISC2's initiative offers the entry CC training + exam free (check current One Million pledge). A real certification on your resume quickly.
Free "Introduction to Cybersecurity" & networking courses with virtual network simulator. Solid, accredited fundamentals.
The internet's beloved free A+/Network+/Security+ video courses. Structured like the exams, cost like the air you breathe.
Free video classes + CTF from the biggest bug-bounty platform. Great bridge to real bounty hunting.
Arizona State's free curriculum: Linux, program exploitation, reverse engineering — from fundamentals to serious depth. For when you want to really understand computers.
The famous pentest platform. Starting Point machines are beginner-guided; HTB Academy teaches structured modules; retired machines have IppSec video walkthroughs for every step.
Hundreds of free downloadable vulnerable VMs for your own lab — no subscription, runs offline, write-ups exist for most.
Carefully crafted web & system exploitation exercises — excellent for understanding vulnerabilities at a technical depth interviews love.
SOC simulator: real-ish alert queue, phishing triage, SIEM investigations with guided lessons. The closest thing to a SOC job you can do at home; generous free tier.
Free blue-team CTF labs: pcaps, disk images, memory dumps, phishing kits — investigate with the exact tools from Section 07.
Purpose-built defensive scenarios: incident response, malware, log analysis. Premium but beloved in blue-team circles.
Learn cryptography by breaking it — from XOR to attacking real constructions. Free; extremely fun for puzzle brains.
Free courses on MITRE ATT&CK, detection engineering, adversary emulation (with Caldera) — resume-friendly, corporate-grade material.
Free real-world security dataset for Splunk practice. Recruiters recognise "BOTS" instantly.
Untouched (no walkthrough) boxes, Active Directory ranges like Dante/Offshore, and the ranked leaderboard. Where OSCP-level skills are forged.
Blue Team Level 1: 6-week practical course + 24-hr incident-response exam. The premier entry blue-team credential.
Cloud security hands-on: AWS misconfig hunting (free), Rhino's CloudGoat vulnerable-by-design environments. Cloud is where the jobs are.
Build entire multi-VM Active Directory forests with deliberate weaknesses + full logging. The upgrade your home lab deserves by month 6.
Vulnerable Android apps from OWASP for mobile-security fundamentals.
Long-running free challenge archives covering everything from web to reversing — great for steady daily practice.
Every completed room/box/lab → a short write-up on GitHub (markdown) or a blog. Within months you'll own a public, verifiable portfolio: "I don't just say I can do it — here are 40 documented machines I've owned/investigated." That portfolio outperforms degrees with recruiters.
CTFs are competitive puzzle events where you solve security challenges to recover secret strings — flags — and score points. They're the industry's favourite sport, training system, and hiring filter all in one.
Formats vary: flag{...}, CTF{...}, picoCTF{...} — you know it when you find it.
A board of challenges across categories & difficulties (100–500 pts). Solve any, in any order. This is 90% of events and all beginner events.
Each team defends its own vulnerable servers while attacking others'. Intense, team-oriented, advanced.
Root a whole machine (HTB style), or hold a box against rivals replacing your persistence with theirs. Chaos, wonderful chaos.
Exploit web apps: SQLi, XSS, IDOR, source-code leaks. First solve: view-source, /robots.txt, cookie tampering.
Break weak/ classic ciphers. First solve: CyberChef base64/ROT13, frequency-analysis a Caesar; dCode.fr is your sidekick.
Find things the internet already knows. First solve: reverse-image a landmark; Wayback Machine a "deleted" page.
Analyze provided files (images, pcaps, memory). First solve: strings a file, check EXIF metadata, carve with binwalk.
Data hidden inside images/audio. First solve: steghide/zsteg, view colour channels, check LSBs.
Analyze a binary to find the flag it checks. First solve: run strings; then Ghidra the main() function.
Overflow buffers, defeat mitigations, pop shells. The hardest category — pwn.college eases you in properly.
Everything else: esoteric languages, pyjails, weird protocols. First solve + best teachers' notes live here.
CTFtime.org — the global calendar & ratings. Join weekend events (even alone) and read winning write-ups afterwards. Regulars: picoCTF (Mar–Apr, beginner heaven), HTB University/Business CTFs, Google CTF, DEF CON qualifiers, DownUnderCTF (huge and beginner-friendly).
Timebox: 30 min stuck → read a hint. Take notes for the write-up as you go. After every event read others' write-ups — that's where the compounding growth is. Team up: a 3-person beginner squad covers 3x the categories. Never share flags mid-event.
Certs don't prove mastery — they get you past HR filters and structure your learning. Strategy: free starter cert → Security+ (the golden key) → one hands-on track cert. Prices are approximate in USD and change — always check current rates.
Free self-paced training + exam under ISC2's "1 Million Certified" pledge (verify it's still active). Covers security principles, network security, IR basics. ✦✧✧✧✧
Free course + digital badge from Cisco's academy. Great very-first credential. ✦✧✧✧✧
Coursera program: SIEM, Python, Linux, detection — aimed squarely at job-switchers. Frequently used to pass HR screens in the US/AU. ✦✦✧✧✧
Security/Compliance/Identity fundamentals — easy, cheap, and Microsoft shops recognise it instantly. Watch for free exam vouchers via MS events. ✦✧✧✧✧
Free official Splunk e-learning — the skill that shows up in most SOC job ads (exam/cert optional ~US$130). ✦✧✧✧✧
Vendor training, free, and decent for vocabulary/interviews. ✦✧✧✧✧
The world's default first security certification — appears in a huge share of junior job ads and satisfies US DoD 8570 requirements. Study free with Professor Messer + practice exams (Dion/Gibson). ✦✦✦✧✧
Skip the exam if you're networking-fluent from Phase 1 — but the syllabus/Professor Messer playlist remains the best networking study guide in existence. ✦✦✧✧✧
If you've never opened a PC or used the command line, A+ material builds IT bedrock. Self-study the knowledge; the two-exam cert is optional for a security path. ✦✧✧✧✧
Entry pentest cert — fully hands-on lab exam, not multiple choice. Beloved first-offense credential before the OSCP mountain. ✦✦✦✧✧
HackTheBox Certified Penetration Testing Specialist — brutally practical multi-day exam, insanely good price. Respect among practitioners >> price tag. ✦✦✦✦✧
24-hour practical IR exam using Splunk, Wireshark, Volatility… arguably the best junior blue-team credential available. ✦✦✦✧✧
Analyst-focused (SIEM, detecting, responding). Recognised in job ads; written + performance questions. ✦✦✦✧✧
PenTest+: respectable mid cert. CEH: famous (HR loves it) but theory-heavy — practitioners side-eye it; choose CEH only if a specific job demands it. ✦✦✦✧✧
Directly relevant for GRC roles worldwide; pairs beautifully with CIS Controls/NIST knowledge. ✦✦✧✧✧
The 24-hour exam that made hacking certifications famous. "Try Harder." Not an entry cert — do it with 12+ months of solid labbing. ✦✦✦✦✦
SANS courses: deep, respected, expensive (employers often pay). The blue-team gold standard. ✦✦✦✦✧
Leadership/management pillars. CISSP requires 5 years' experience (you can pass early and become an "Associate"). ✦✦✦✦✧
Active Directory and advanced red-team specialisations for when AD is your playground. ✦✦✦✦✧
Cloud-native security certifications — pair with PwnedLabs/CloudGoat practice for the cloud-security lane. ✦✦✦✧✧
Public-sector security work often values clearances and frameworks — e.g. US DoD 8570, UK SC/DV, country-specific assessor schemes. A long-game option after years in-industry.
Twelve structured weeks taking you from zero to "interview-ready fundamentals with receipts". Budget 60–90 min weekdays + one 3–4 hr weekend session. Tick boxes as you go (progress saves in your browser when possible).
Keep the flywheel: 1 machine/week, 1 write-up/week, 1 CTF/month, next certification within 6 months, and community presence weekly. The compounding is absurd — most people quit in week 3, so simply continuing makes you remarkable by month 6.
Handpicked, beginner-proven. You don't need everything — pick 2–3 from each category and go deep. (Links work when you open this file in your browser.)
High-energy networking, Linux & hacking-for-beginners series. The channel that makes thousands start. watch
Insanely prolific CTF/malware walkthroughs. Watch how a pro thinks, enumerates, gets stuck, un-stucks. watch
Legendary HackTheBox box-by-box videos. Watch AFTER attempting — closest thing to a mentor on demand. watch
Massive free full courses (Wireshark, Kali, networking) & career interviews with industry leaders. watch
Heath Adams' practical pentest teaching + "how I got into cyber" content founded an academy — starter videos are gold. watch
Mind-expanding videos on how exploitation really works. Save for months 2–3, revisit forever. watch
The free A+/Network+/Security+ training library. Your certification study backbone. watch
Real bug-bounty hunters showing methodology & mindset for web hunting. watch
Actual university-grade free courses (assembly, architecture, forensics) for later depth. visit
Linux Basics for Hackers — OccupyTheWeb · gentle on-ramp to Kali skills
Hacking: The Art of Exploitation (2e) — Jon Erickson · how exploitation really works, with code
The Web Application Hacker's Handbook · the deep web bible (with PortSwigger labs as modern companion)
Practical Malware Analysis — Sikorski & Honig · the malware-analysis standard
Blue Team Handbook: Incident Response — Don Murdoch · pocket field manual for analysts
The Practice of Network Security Monitoring — Richard Bejtlich · NSM philosophy done right
Stories: The Cuckoo's Egg · Sandworm · Countdown to Zero Day — motivation & mindset fuel
Darknet Diaries — gripping true hacking stories; the gateway podcast. Start ep. 1.
Risky Business — weekly global industry news. Listen to every episode → instant fluency.
Smashing Security — funny, educational weekly chat.
News sites: The Hacker News · BleepingComputer · Krebs on Security · The Record.
CISA / national CERT alerts — your national cyber centre's advisories (US: CISA). Bookmark them early.
Rapid7 / CISA feeds — vulnerability disclosure streams you'll learn to skim weekly.
Reddit: r/cybersecurity · r/netsecstudents · r/homelab · r/oscp. Discord: TryHackMe, HackTheBox, John Hammond's, NahamSec (bug bounty). X/Mastodon infosec communities for the latest research.
BSides community cons run in hundreds of cities worldwide, OWASP has chapters almost everywhere, plus ISACA/ISSA chapters, university CTF clubs and local/security meetups. One friend in the industry is worth 100 applications.
DEF CON & Black Hat (villages + trainings), SANS Summits (many free), BruCON, Hack.lu, FIRST.org member CERTs, and the global communities of ISC2 / ISACA / CompTIA.
1. Only test systems you own or have explicit written permission to test. "I'm learning" is not a legal defence — in most of the world — unauthorised access or modification of data is a serious crime (US CFAA, UK Computer Misuse Act, and national equivalents). 2. Stay inside documented scope (bug bounties & engagements define it — honour it). 3. Found something by accident on the public internet? Follow responsible disclosure; never extort, never "sample" the data. 4. Protect what you find: client data, credentials, secrets — treat them like biohazards. 5. Uplift others: share knowledge, credit sources, be kind in write-ups. 6. Your reputation is your career: the community is small and memory is long. Wear the white hat proudly — skill with integrity is rare, sought-after, and unstoppable.