⌁ CYBER//START ▮
The beginner's program // v1.0

Enter Cyber Security
From Absolute Zero.

A complete, self-contained field manual for breaking into cybersecurity — every fundamental term, 150+ essential tools, free labs, a home-lab blueprint, certification path and a week-by-week 90-day battle plan. No experience required.

tip: open this file in a full browser for clickable links — school it offline, it needs no internet.

future_you@cyber:~
future_you@cyber:~$ _
0
Unfilled cyber jobs worldwide (ISC2)
0
Chapters in this guide
0
Essential tools catalogued
0
Days: your structured start

1 · Learn the Language

Read sections 01–06 to master the fundamentals: the CIA Triad, how networks work, 80+ core terms, how attacks happen and how defenders think. Infographics make it stick.

2 · Build & Practice

Set up your own attack/defense home lab (section 09) and drill daily on free platforms like TryHackMe, picoCTF and PortSwigger Academy. Hands-on beats textbooks, always.

3 · Certify & Apply

Follow the certification ladder (section 12), publish your write-ups on GitHub, join your local community, and apply for SOC/junior analyst roles with a portfolio recruiters can verify.

SECTION 01 / ORIENTATION

What Cybersecurity Actually Is

Cybersecurity is the practice of protecting systems, networks, programs and data from digital attacks, damage and unauthorized access. Every company with a computer needs it — banks, hospitals, mines, governments, your favourite app. That is why the field is enormous, understaffed, and open to curious people who put in the reps.

🎯

It's a mission, not a product

You can't "buy" security. It's an ongoing cycle: identify assets → protect them → detect failures → respond → recover → improve. Professionals call frameworks for this NIST CSF and ISO 27001.

⚖️

It's risk management

No system is 100% secure. The job is reducing risk (likelihood × impact) to a level a business accepts — while keeping systems usable. Perfect security that blocks work gets ignored and bypassed.

🧠

It's an adversarial mindset

Defenders think about what could go wrong; attackers prove what does. Learning both sides makes you dangerous (in the good way). Curiosity + persistence + ethics = the profile of every great practitioner.

INFOGRAPHIC 01 — THE CIA TRIAD · THE HEART OF ALL SECURITY
DATA 🔒 CONFIDENTIALITY ✅ INTEGRITY ⚡ AVAILABILITY

Confidentiality — "Only the right eyes"

Data is readable only by authorized people. Tools: encryption, access control, MFA, least privilege.
❌ Broken when: passwords leak, databases are exposed, attackers read your files.

Integrity — "Nothing secretly altered"

Data and systems stay accurate and unmodified. Tools: hashing, checksums, digital signatures, file integrity monitoring.
❌ Broken when: attackers alter transactions, backdoor code, tamper with logs.

Availability — "It's there when needed"

Systems and data remain accessible on demand. Tools: backups, redundancy, DDoS protection, incident response.
❌ Broken when: ransomware locks servers, DDoS floods knock sites offline.

Every attack you'll ever study breaks one (or more) of these three properties. Every defense you'll deploy protects one. Memorize this triangle — interviews start here.

Why it's a great career bet right now

the demand

🌏 Massive talent gap

ISC2 estimates a global workforce gap of ~4.8 million unfilled cyber roles. Demand outstrips supply in every region — especially outside pure IT: healthcare, finance, industrial/OT and government.

💰 Strong pay

Entry-level SOC roles commonly start around US$45k–70k+, with experienced engineers/architects well past US$120k. (See the careers table in Section 02.)

♾️ Never boring

Attackers innovate daily; you will learn forever. New clouds, AI attacks, zero-days — the field rewards people who love continuous learning.

🚪 Open doors, no degree required

Cyber famously hires on demonstrated skill: labs done, CTFs played, write-ups published. Certifications + a home lab portfolio regularly beat formal degrees.

📰

This is real: the whole world is under attack

Breaches like Optus and Medibank (2022, ~10M records each), MOVEit, Change Healthcare and Snowflake-related incidents put cybersecurity on front pages globally — and made baseline frameworks (CIS Critical Security Controls, NIST CSF, your national CERT's guidance) must-know vocabulary everywhere. You are entering the field at exactly the right time.

SECTION 02 / THE LANDSCAPE

Red Team vs Blue Team — Pick Your Side (Later)

Cybersecurity isn't one job — it's a family of specialisations. The classic split: offensive security (think like an attacker to find weaknesses first) and defensive security (detect, respond, harden). Beginners should explore both for a few months before specialising.

🔴 OFFENSE · RED TEAM

Attack (legally) to strengthen

  • Penetration Tester — paid to hack companies with written permission
  • Red Team Operator — full-scope adversary simulation, stealth
  • Bug Bounty Hunter — freelance: find bugs, get paid per valid finding
  • Web/App Security Tester — OWASP Top 10, APIs, mobile
  • Exploit Developer — reverse engineering, vulnerability research
  • Social Engineer — phishing simulations, physical entry tests

core skills: networking · linux · scripting · web tech · persistence

VS
🔵 DEFENSE · BLUE TEAM

Detect, respond, harden

  • SOC Analyst (L1→L3) — monitor alerts, triage, escalate · the #1 entry job
  • Incident Responder (DFIR) — forensics, contain breaches, hunt artifacts
  • Threat Intelligence Analyst — track attacker groups, IOCs, TTPs
  • Malware Analyst — dissect malicious software safely
  • Security Engineer — build/maintain firewalls, SIEMs, EDR, hardening
  • GRC Analyst — governance, risk, compliance, policies, audits

core skills: logs & SIEM · Windows/AD · networking · calm under pressure

💜

…and Purple Team

Purple team = red and blue working together in real time: red attacks, blue watches, both compare notes to measurably improve detection. Many modern roles blend both sides — and knowing attack techniques makes you a dramatically better defender (and vice versa).

Common roles, what they do & indicative global pay

careers table
RoleWhat you actually doEntry routeIndicative salary (USD, varies by region)
SOC Analyst (L1)Watch SIEM dashboards, triage alerts, investigate phishing, escalate incidents. The classic first job.Security+ / Google Cert / ISC2 CC + home SIEM labUS$45k–70k
Cyber Security AnalystGeneralist: vuln scans, hardening, awareness training, policy, incident support.Security+ → CySA+US$55k–80k
Penetration TesterSimulate attacks on apps, networks, AD; write reports clients act on.eJPT / HTB CPTS → OSCPUS$60k–90k (junior–mid)
GRC AnalystRisk assessments, compliance (ISO 27001, Essential Eight, SOCI), audits, vendor reviews. Less coding, more frameworks.Security+ / ISO 27001 FoundationUS$60k–95k
DFIR SpecialistForensic imaging, memory analysis, malware triage, breach investigation.SOC experience + BTL1 / GCFA laterUS$70k–110k
Security EngineerDesign & operate security tooling (EDR, firewalls, IAM, cloud security), automate defenses.sysadmin/cloud background + certsUS$85k–130k
Cloud / AppSec SecuritySecure AWS/Azure/K8s, CI/CD pipelines, code review, threat modelling.dev/cloud skills + security certsUS$95k–150k
OT / ICS Security ⭐Factories, energy, water, transport — every industry everywhere needs OT protection; people are scarce.eng/networking + GICSP laterUS$85k–140k
Security Architect / CISO trackEnterprise-wide security design, strategy, leadership, board-level risk.years of experience + CISSP/CISMUS$130k–200k+

Ranges are indicative global ballparks — they vary hugely by country and sector; check job boards in your region. Universal tip: OT/ICS (industrial) security skills are a genuine niche cheat-code anywhere.

best first target

🖥️ SOC Analyst / Cyber Analyst

Most openings, clearest entry path, teaches you how attacks really look in logs. 12–24 months here opens every other door.

underrated entry

🔧 IT Support → Security

Helpdesk/sysadmin is a proven on-ramp: you learn AD, networking and users, then pivot internally. Many CISOs started at helpdesk.

no-code friendly

📋 GRC / Compliance

Love organisation, writing and frameworks more than terminals? GRC is critical, well-paid, and less technical to enter — Technical skills still help.

SECTION 03 / FOUNDATIONS

The Four Pillars You Must Build First

Before "hacking tools", you need bedrock. Every senior professional stands on these four: computers & operating systems, networking, the command line (Linux!), and basic scripting. Two focused months here saves you a year of confusion later.

💻

1 · Computer & OS Basics

What a CPU, RAM, disk and process actually are; what an OS does; users & permissions; services; the Windows registry; virtualization. Free course: CompTIA A+ material via Professor Messer (YouTube).

🌐

2 · Networking

IP addresses, MAC addresses, DNS, TCP vs UDP, ports, the OSI model, NAT, DHCP. Networking is to cyber what anatomy is to medicine. Free course: Professor Messer Network+ & Jeremy's IT Lab (CCNA).

🐧

3 · Linux

~70% of servers and 95% of hacking tools run Linux. Master the terminal: files, permissions, processes, pipes, logs, SSH. Game: OverTheWire: Bandit teaches you by playing.

🐍

4 · Scripting

Python first (automation, tooling, exploit scripts), plus Bash (Linux) and enough PowerShell to recognize attacks on Windows. You don't need to be a software dev — reading code matters most early.

INFOGRAPHIC 02 — THE OSI MODEL · HOW DATA TRAVELS
  1. 7ApplicationHTTP · DNS · SMB · SSH
  2. 6Presentationencryption · TLS · encoding
  3. 5Sessionconnections · sessions
  4. 4TransportTCP (reliable) · UDP (fast) · ports
  5. 3NetworkIP addresses · routing
  6. 2Data LinkMAC addresses · switches · ARP
  7. 1Physicalcables · wifi · bits

Mnemonic (7→1): "All People Seem To Need Data Processing"

Attacks live at every layer — phishing (7), ARP spoofing (2), SYN floods (4)…

Your message is wrapped (encapsulated) down the stack on the sender, then unwrapped up the stack on the receiver. Attackers abuse every single layer.

The 26 ports you'll be asked about forever

memorise these
PortServiceWhy it matters to security
20/21FTPCleartext file transfer — ancient, often misconfigured, gold for attackers
22SSHSecure remote admin — brute-forced constantly; use keys + fail2ban
23TelnetCleartext remote login — if you see this open, it's a finding
25 / 587SMTPEmail sending — abused for spoofing/phishing; check SPF/DKIM/DMARC
53DNSThe phonebook of the internet — tunneling & exfiltration hide here
67/68DHCPHands out IP addresses — rogue DHCP = easy MITM
80 / 443HTTP / HTTPSWeb traffic. Where most attacks and most of your career will live
110 / 143POP3 / IMAPEmail retrieval — legacy cleartext versions still haunt networks
139 / 445NetBIOS / SMBWindows file sharing — WannaCry/NotPetya spread via SMB. Critical.
161/162SNMPDevice monitoring — default community string "public" leaks everything
389 / 636LDAP / LDAPSDirectory lookups — the map of Active Directory for attackers
88KerberosAD authentication — Kerberoasting, golden tickets live here
1433 / 3306 / 5432MSSQL / MySQL / PostgresDatabases — should never face the internet; SQL injection's target
3389RDPRemote Desktop — #1 ransomware entry point. Always MFA / VPN first
5985/5986WinRMWindows remote management — lateral movement highway
6379 / 27017Redis / MongoDBNoSQL stores — historically wide-open, mass-exploited
5900VNCRemote screen sharing — weak/no passwords in the wild
8080 / 8443HTTP-alt proxiesDev servers, admin panels forget they're exposed here

Linux survival commands — your first vocabulary

terminal

🧭 Navigate & find

pwd · ls -la · cd
find / -name flag.txt
grep -R "password" .
locate · which · cat · less

Everything in Linux is a file — including devices and config. Learn to explore it.

🔐 Permissions

chmod 755 script.sh
chown user:group file
sudo · su · id · whoami
/etc/passwd · /etc/shadow

Privilege escalation = abusing misconfigured permissions. Learn them deeply.

🌐 Network & processes

ip a · ip r · ss -tulpn
ps aux · top · kill
curl · wget · ssh · scp
systemctl status sshd

See what's listening, what's talking, what's running — attacker's AND defender's view.

⚡

Drill: the 30-day Bandit challenge

Play OverTheWire: Bandit levels 0–30 (free, in your browser/terminal via SSH). You'll learn every command above by capturing flags, and you'll finish genuinely comfortable in a Linux shell. It's the single best Linux primer for future hackers.

SECTION 04 / SPEAK THE LANGUAGE

The Essential Cyber Terminology Vault

80+ terms you will hear on day one of any job, course or CTF. Filter by theme, or search anything. Read these slowly — they're the vocabulary everything else is built from.

🧩 Core concepts

18

Vulnerability

A weakness that can be exploited — a bug, misconfiguration or missing control. e.g. unpatched software, default passwords.

Exploit

Code or technique that takes advantage of a vulnerability to cause unintended behaviour.

Threat

Anything that can cause harm: a hacker, malware, a disgruntled employee, even a flood in the server room.

Risk

Risk = Likelihood × Impact. The chance a threat exploits a vulnerability, and how bad it would be.

Attack Surface

Every point where an attacker could try to enter: open ports, web apps, APIs, employees, suppliers.

Payload

The part of an attack that does the damage/action — e.g. the ransomware binary, or a reverse shell.

Zero-Day (0-day)

A vulnerability exploited before the vendor knows or has a patch. The most valuable kind of bug.

CVE

Common Vulnerabilities & Exposures — the public ID system for known flaws, e.g. CVE-2021-44228 (Log4Shell).

CVSS

Severity score (0–10) for CVEs. 9.0+ = "drop everything and patch".

Patch / Patching

Vendor's fix for a vulnerability. "Patch Tuesday" (Microsoft, monthly) shapes the industry's rhythm.

Threat Actor

The "who": script kiddies, cybercriminals, hacktivists, insiders, nation-state groups.

APT

Advanced Persistent Threat — well-resourced groups (often state-backed) that stay hidden for months/years.

IOC

Indicator of Compromise — a forensic breadcrumb: malicious IP, file hash, domain, registry key.

TTPs

Tactics, Techniques & Procedures — how an adversary operates, catalogued in the MITRE ATT&CK framework.

Asset

Anything worth protecting: data, servers, laptops, credentials, reputation.

Hardening

Reducing attack surface: remove unneeded services, apply secure configs (see CIS Benchmarks).

Attack Vector

The path/method used to get in: phishing email, exposed RDP, poisoned update, USB drop.

Breach

An incident where data/security controls are actually compromised. Reportable under privacy laws (in AU: Notifiable Data Breaches scheme).

⚔️ Attacks & offensive terms

20

Phishing

Fraudulent messages tricking people into clicking links, opening malware or giving up credentials. #1 initial access method worldwide.

Spear Phishing / Whaling

Targeted phishing at a specific person; whaling targets executives.

Malware

Any malicious software: viruses, worms, trojans, ransomware, spyware… (full taxonomy in Section 05).

Ransomware

Encrypts victim files and demands payment. Modern crews add "double extortion": leak the data too.

DoS / DDoS

(Distributed) Denial of Service — flood a service until it falls over. Attacks Availability.

MITM

Man-in-the-Middle — secretly relaying/altering traffic between two parties (evil Wi-Fi AP, ARP spoofing).

SQL Injection (SQLi)

Putting database commands into an app's input fields. Can dump entire databases. Classic, deadly, preventable.

XSS

Cross-Site Scripting — injecting JavaScript into pages other users view; steals sessions, defaces, phishes.

CSRF

Cross-Site Request Forgery — riding a victim's logged-in session to perform unwanted actions.

Brute Force

Trying every password combination. Slow but sure against weak passwords; throttled by lockouts/MFA.

Credential Stuffing

Replaying breached email:password combos on other sites, betting users reuse passwords. They do.

Privilege Escalation

Going from low-privilege user to admin/root (vertical) or another user's account (horizontal).

Lateral Movement

Hopping between machines inside a network after the first foothold.

Reverse Shell

Target machine connects back to the attacker, giving remote command control. The classic payload.

C2 (Command & Control)

The attacker's infrastructure used to control compromised machines and receive stolen data.

Exfiltration

Getting stolen data out of the network — over DNS, HTTPS, cloud storage…

Persistence

Techniques to survive reboots and password resets: services, scheduled tasks, registry run keys, webshells.

Buffer Overflow

Writing past a memory buffer's boundary to hijack execution. The grandfather of exploitation; learn the theory even if modern mitigations exist.

Social Engineering

"Hacking humans" — manipulating people instead of systems: pretext calls, tailgating into buildings, urgency scams.

Pass-the-Hash / Kerberoasting

Active Directory attacks reusing stolen password hashes / cracking service-account tickets. Bread and butter of AD pentesting.

🛡️ Defense & operations

22

Firewall

Filters traffic by rules (IP/port/protocol). Network (perimeter) and host-based flavours.

IDS / IPS

Intrusion Detection watches & alerts; Intrusion Prevention sits inline and blocks. Tools: Snort, Suricata, Zeek.

SIEM

Security Information & Event Management — collects and correlates logs from everything; the SOC's cockpit. Tools: Splunk, Elastic, Wazuh, Sentinel.

SOC

Security Operations Center — the team (and room) that monitors and responds 24/7. Where most careers start.

EDR / XDR

Endpoint (eXtended) Detection & Response — agents on devices that detect and stop malicious behaviour. CrowdStrike, Defender for Endpoint.

AV (Antivirus)

Signature/behaviour-based malware blocking. Necessary but alone insufficient.

MFA / 2FA

Multi-Factor Authentication — password + something you have/are. Blocks the vast majority of account takeovers.

IAM / PAM

Identity & Access Management / Privileged Access Management — who can access what, and controlling admin accounts.

Least Privilege

Give every user/process only the access it needs — nothing more. Kills lateral movement.

Zero Trust

"Never trust, always verify" — no automatic trust even inside the network; authenticate & authorise everything, continuously.

Segmentation / VLAN

Splitting networks into zones so a breach in one can't spread — like ship bulkheads.

DMZ

Buffer network between internet and internal LAN where public-facing servers live.

Honeypot / Honeynet

A decoy system with no legitimate users — anyone touching it is malicious by definition. Great early-warning + research tool. Try: Cowrie, T-Pot.

Sandbox

Isolated environment to safely detonate/observe suspicious files. Tools: Cuckoo, Any.Run, Hybrid Analysis.

DLP

Data Loss Prevention — tooling that detects/blocks sensitive data leaving the org.

Incident Response (IR)

The structured reaction to a breach. Lifecycle: Prepare → Detect → Contain → Eradicate → Recover → Learn.

DFIR

Digital Forensics & Incident Response — the discipline of investigating what happened from artifacts (disk, memory, logs).

Threat Hunting

Proactively searching for attackers who evaded alerts, using hypotheses + data. "Assume breach."

Patch Management

Tracking, testing and deploying updates. Unglamorous, massively effective.

CIS Controls (CIS 18)

The globally-used prioritized set of 18 defensive actions. Also know your national CERT's baseline guidance — interview gold anywhere.

Playbook / Runbook

Step-by-step response guides ("phishing email playbook") so juniors respond like veterans at 3am.

OSINT

Open-Source Intelligence — collecting info from public sources. Used by attackers to target you and defenders to investigate.

🌐 Networking essentials

12

IP Address

Logical network address (IPv4 203.0.113.5 / IPv6). Public vs private ranges (10.x, 172.16–31.x, 192.168.x).

MAC Address

Hardware address of a network card, used on the local link (Layer 2). Spoofable.

DNS

Domain Name System — translates names (google.com) to IPs. DNS poisoning/tunneling are attack staples.

TCP vs UDP

TCP = reliable, connection-oriented (3-way handshake SYN/ACK). UDP = fast, connectionless (DNS, streaming, games).

Port

A numbered door (0–65535) identifying a service on a host. Well-known: 0–1023. See the table in Section 03.

DHCP

Automatically assigns IP addresses when you join a network.

NAT

Network Address Translation — many private devices sharing one public IP. Your home router does this.

Subnet / CIDR

Dividing networks: 192.168.1.0/24 = 256 addresses (/24 = first 24 bits fixed).

VPN

Encrypted tunnel over untrusted networks — for remote workers and privacy.

Proxy / Reverse Proxy

Intermediary for requests; forward proxy hides clients, reverse proxy fronts servers (also a security control point).

ARP

Maps IP→MAC on a LAN. ARP spoofing = classic local MITM technique.

TLS / SSL

Encryption for traffic in transit — the padlock in HTTPS. SSL is dead; TLS 1.2/1.3 is correct.

🔐 Cryptography basics

8

Encryption

Reversible scrambling with a key. Symmetric (one shared key — AES) vs Asymmetric (public/private key pair — RSA, ECC).

Hashing

One-way fingerprint (SHA-256, bcrypt). Used for integrity checks and password storage. Not encryption — can't be "decrypted".

Salting

Random data added before hashing passwords so identical passwords get different hashes — defeats rainbow tables.

Digital Signature

Asymmetric crypto proving a message/software came from you and wasn't altered (authenticity + integrity).

PKI / Certificates

Public Key Infrastructure — the certificate authority system that makes HTTPS trust possible.

Rainbow Table

Precomputed hash→password lookup tables. Why unsalted fast hashes (MD5!) are terrible for passwords.

Steganography

Hiding data inside other data (messages in image pixels). Favourite of CTF forensics challenges — tools: steghide, zsteg.

Token / Session ID

The "you are logged in" artifact (cookie/JWT). Stealing one = session hijacking. Guard with HttpOnly + short expiry + MFA.

🎓 Careers & practice terms

10

Penetration Test

Authorized, scoped, time-boxed simulated attack delivering a fix-it report. "Pentest". Requires written permission — always.

Vulnerability Assessment

Automated scanning for known weaknesses (Nessus/OpenVAS). Breadth-first cousin of pentesting.

Red / Blue / Purple Team

Offense / defense / collaboration exercises. (Section 02 covers the roles.)

Bug Bounty

Companies pay researchers for valid vulnerability reports via HackerOne/Bugcrowd. Legal hacking for money — but only in defined scope.

CTF

Capture The Flag — gamified security challenges where you find "flag{...}" strings. The sport of the industry (Section 11).

White / Black / Grey Hat

Lawful-ethical hackers / criminal hackers / somewhere in between. Aim to be unambiguously white hat.

Responsible Disclosure

Reporting a found vulnerability privately to the vendor so they can fix it before going public (typically ~90 days).

Rules of Engagement

The legal contract defining what a pentester may and may not touch. Breaking scope = breaking the law.

MITRE ATT&CK

The global knowledge base of adversary TTPs (Recon, Initial Access, Execution… Exfiltration). Learn to read it — the industry's shared map.

CTF Flag

The secret string proving you solved a challenge: flag{y0u_f0und_m3}. Addictive — you've been warned.

SECTION 05 / KNOW YOUR ENEMY

Threats, Malware & How Attacks Actually Unfold

To defend (or ethically attack) systems you must understand the adversary's playbook. Here's the complete beginner taxonomy: malware species, human hacking, and the famous Cyber Kill Chain — the model that breaks every attack into 7 defendable stages.

🦠 The malware zoo — 16 species to know

infographic grid
classic

Virus

Attaches to a host file/program, needs user action to spread (open the file → infect). The original malware.

self-spreading

Worm

Replicates across networks by itself — no user needed. WannaCry (2017) wormed via SMB and hit 200,000+ machines in days.

deception

Trojan Horse

Poses as legitimate software ("free photoshop crack") carrying a hidden payload. Doesn't self-replicate.

most feared

Ransomware

Encrypts your files, demands crypto payment. Modern gangs also steal data first ("double extortion"). Defence: offline backups + segmentation + MFA.

stealth

Spyware

Silently monitors: keystrokes, screens, messages. Stalkerware is the consumer cousin.

stealth+

Rootkit

Buries deep into the OS (drivers/kernel) to hide itself and maintain access. Extremely hard to detect/remove.

credentials

Keylogger

Records every keystroke — passwords, messages, everything. Hardware and software varieties exist.

army

Botnet

Thousands of infected "zombie" devices controlled from one C2, used for DDoS, spam, mining. Mirai enslaved IoT cameras.

remote control

RAT

Remote Access Trojan — full remote control: files, webcam, mic. Delivered via phishing macros & cracked software.

sabotage

Logic Bomb

Dormant code triggered by a condition — a date, an employee being removed from payroll. Favoured by malicious insiders.

destruction

Wiper

Pure destruction — erases disks. NotPetya (2017) cost $10B globally; used heavily in the Ukraine conflict.

annoying

Adware

Forced ads & tracking, often bundled with "free" software. Usually grey-area legally, always a privacy problem.

parasite

Cryptominer

Secretly mines cryptocurrency with your CPU/cloud bill. Signs: fans screaming, sluggish servers.

ghost

Fileless Malware

Lives in memory and legitimate tools (PowerShell, WMI) — nothing on disk for AV to scan. Detections focus on behaviour.

delivery

Dropper / Loader

Stage 1 malware whose only job is to download/install the real payload — often bought as a service. Initial access → bigger infection.

fake AV

Scareware

"YOUR PC IS INFECTED — PAY $99!" manipulates fear. Social engineering dressed as software.

🎭 Social engineering — hacking the human OS

humans are the softest target

📧 Phishing

Mass emails with malicious links/attachments, fake login pages. Defend: verify sender, hover links, report button, MFA.

📱 Smishing / Vishing

SMS phishing ("AusPost: fee required") & voice phishing ("IT helpdesk here, read me your MFA code"). Defend: never act via the contact they gave you — call back on official numbers.

🎭 Pretexting

Invented scenario to extract info: "auditor", "new colleague", "vendor survey". Defend: verify identity through known channels.

🪤 Baiting

Curiosity trap: "FREE MUSIC" download, USB labelled "SALARIES 2026" left in the car park. Defend: never plug in found USBs.

🚪 Tailgating

Following an employee through a secure door ("hands full, mate?"). Defend: badge everyone, politely challenge strangers.

😰 Scare Tactics / Urgency

"CEO needs this gift card NOW", "your account closes in 1 hour". Defend: urgency + secrecy = red flags, always.

🤖 Deepfake Voice/Video

AI-cloned executives approving wire transfers — a growing 2020s threat. Defend: out-of-band verification for money/secret requests.

🔔 MFA Fatigue

Spamming push notifications until the victim taps "Approve". Defend: number-matching MFA; deny + report unexpected prompts.

INFOGRAPHIC 03 — THE CYBER KILL CHAIN · LOCKHEED MARTIN'S 7 STAGES
01
Reconnaissance
Researching the target: LinkedIn, Shodan, DNS records
🛡 detect: monitor web logs, threat intel
02
Weaponization
Building the payload: exploit + malware in a PDF/doc
🛡 disrupt: hard to see — focus elsewhere
03
Delivery
Sending it: phishing email, USB, watering hole, drive-by
🛡 deny: email filtering, sandboxing attachments
04
Exploitation
Triggering the vulnerability to run code
🛡 deny: patching, EDR, exploit prevention
05
Installation
Persistence: implants, services, run keys, webshells
🛡 detect: EDR, file integrity monitoring
06
Command & Control
Beaconing home for instructions over HTTPS/DNS
🛡 deny: egress filtering → block unknown outbound
07
Actions on Objectives
The goal: steal data, encrypt, destroy, spy
🛡 degrade: DLP, segmentation, fast IR
The defender's advantage: attackers must succeed at every stage — you only need to break one link. Study which controls map to which stage, and you'll architect real "defense in depth".
🕰️

Attacks everyone should know by name

Morris Worm (1988, first internet worm) → ILOVEYOU (2000, email worm) → Stuxnet (2010, destroyed centrifuges via USB) → WannaCry / NotPetya (2017, global chaos in hours) → SolarWinds (2020, supply-chain espionage) → Log4Shell (2021, one Java logging bug shook the world) → Optus & Medibank (2022, a national wake-up call). Watch Darknet Diaries episodes on each — best free history class there is.

SECTION 05B / ATTACK ANATOMIES

Watch Four Classic Attacks Play Out

Animated walkthroughs of the four attacks you must understand fluently as a beginner. Replay them mentally until you could explain each on a whiteboard — interviewers love exactly this.

INFOGRAPHIC 04 — ANATOMY OF A PHISHING ATTACK
😈 ATTACKER 📮 MAIL SERVER 🧑‍💼 VICTIM 🎣 FAKE LOGIN PAGE 1 · spear-phish sent: "urgent — payroll update" 2 · victim clicks → enters real credentials 3 · attacker captures password → logs in… DEFENSE: MFA stops the stolen password from being enough ✔
Phishing = delivery via deception. The whole attack rides on urgency + trust. Technical control of the year: MFA (ideally phishing-resistant, like passkeys/FIDO2).
INFOGRAPHIC 05 — MAN-IN-THE-MIDDLE
what Alice thinks: a private, direct connection intercepted relayed (readable!) 👩 ALICE 🏦 BANK 🕵️ MALLORY (rogue Wi-Fi AP) 🔑
Happens via rogue hotspots ("Free Airport WiFi"), ARP spoofing, or DNS poisoning. Your defense: TLS everywhere (that padlock), HSTS, VPN on untrusted networks, and certificate warnings are never to be clicked through.
INFOGRAPHIC 06 — BRUTE FORCE / PASSWORD ATTACK
attacker@kali:~$ hydra -l admin -P rockyou.txt ssh://10.0.0.5
trying… password123 ✗
[hydra] 18,204 attempts so far…
Attackers try huge password lists (like rockyou.txt: 14M real leaked passwords) against logins — with Hydra online or Hashcat/John on stolen hash databases.
Defend: long passphrases (16+ chars), rate limiting, lockouts, MFA. One long unique password per site via a manager.
INFOGRAPHIC 07 — SQL INJECTION IN ONE LOOK
# login form asks: username / password
evil input: ' OR '1'='1' --
# app builds query:
SELECT * FROM users WHERE name='' OR '1'='1' --'
→ '1'='1' is always true ⇒ LOGGED IN WITHOUT A PASSWORD
# worse: UNION SELECT can dump every table in the database.
Fix is boring and 100% effective: parameterized queries / prepared statements. Never concatenate user input into SQL. Practice legally on PortSwigger Academy & DVWA.

🕸️ Web attacks you must know (the OWASP Top 10 era)

study these on PortSwigger

💉 Injection (SQLi, Command)

Untrusted input reaches an interpreter as commands. SQLi dumps databases; OS command injection runs shell commands. Fix: parameterization, allowlists.

📜 XSS — Cross-Site Scripting

Inject JavaScript into pages others view (reflected/stored/DOM). Steal sessions, deface, keylog. Fix: output encoding, CSP headers.

🔑 Broken Access Control / IDOR

Change /invoice?id=1042 → 1043 and see someone else's invoice. The most exploited class today. Fix: server-side authorization on every object.

🎫 CSRF

Trick a logged-in browser into making requests. Fix: anti-CSRF tokens, SameSite cookies.

🌐 SSRF

Make the server fetch attacker-chosen URLs — reach internal cloud metadata (169.254.169.254) and steal AWS keys. Fix: egress allowlists.

📂 Path Traversal / LFI

../../etc/passwd — escaping the web root to read (or include) server files. Fix: canonicalization, chroot jails.

📤 Malicious File Upload

Upload shell.php as an "avatar", visit it, get a web shell. Fix: type checks, rename, store outside webroot, no exec.

🔓 Broken Authentication

Weak session IDs, no lockouts, password reset flaws, missing MFA. Fix: standard libraries, MFA, secure cookie flags.

📦 Vulnerable Components

One outdated library = whole app owned (see Log4Shell). Fix: SBOMs, dependency scanning (npm audit, Dependabot), patching.

SECTION 06 / DEFENSE IN DEPTH

How Real Defense Works — Layers Upon Layers

No single tool stops a determined attacker. Professionals stack layers so that when one fails (one always eventually does), another catches the attack. This is the mindset that separates security thinking from "install antivirus and pray".

INFOGRAPHIC 08 — DEFENSE IN DEPTH · CONCENTRIC LAYERS
Perimeter · firewall, DDoS protection, email/DNS filtering
Network · segmentation, IDS/IPS, NAC
Endpoint · EDR, patching, hardening, disk encryption
DATA access controls · encryption · DLP
backups · least privilege · MFA
An attacker who phishes a user (outer layer breached) still faces segmentation, EDR, and finally encrypted, access-controlled data — with every layer generating logs for the SOC. Also remember: people & policies wrap everything (training, MFA culture, incident plans).
INFOGRAPHIC 09 — A FIREWALL DOING ITS JOB
INTERNET (untrusted) INTERNAL LAN FIREWALL 🔒 telnet:23 rdp:3389 open ALLOW ✓ https:443 → fileserver DENY ✗ telnet:23 — blocked & logged ALLOW ✓ ssh:22 from admin VPN DENY ✗ rdp:3389 from internet — alert SOC
Default policy of professionals: deny everything, allow only what's needed. Every block is logged — those logs feed the SIEM (next), turning a wall into a sensor.
INFOGRAPHIC 10 — THE SOC'S VIEW · LOGS → SIEM → ALERTS

Every device ships logs to a SIEM (Splunk, Elastic, Wazuh). Detection rules (Sigma, KQL) match patterns: "impossible travel login", "known C2 domain", "mimikatz-like process" → an alert fires and an analyst (you!) investigates.

Triage mantra: WHAT happened → IS it real (true positive?) → HOW bad → CONTAIN → ESCALATE.

🧱 The defender's technology stack, explained simply

blue toolbox

Firewall / NGFW

Traffic cop at the network edge & inside. "Next-gen" adds app-awareness & TLS inspection.

eg: pfSense, Fortinet, Palo Alto

IDS / IPS

Sniffs traffic for attack signatures & anomalies (IPS blocks inline).

eg: Snort, Suricata, Zeek

SIEM

Central log brain: collects, correlates, alerts, dashboards, compliance reports.

eg: Splunk, Elastic SIEM, Wazuh, MS Sentinel

EDR / XDR

Agent on every laptop/server watching processes & behaviour; can isolate a host with one click.

eg: CrowdStrike, Defender for Endpoint, Velociraptor

Email Security Gateway

Filters phishing/malware before inboxes; URL rewriting & attachment detonation.

eg: Proofpoint, Mimecast, Defender for O365

IAM / PAM

Identity is the new perimeter: SSO, MFA, just-in-time admin, vaulted credentials.

eg: Entra ID, Okta, CyberArk

Vulnerability Management

Continuous scanning + prioritised patching of the whole fleet.

eg: Tenable/Nessus, Qualys, Greenbone

SOAR

Automates response: isolate host, block sender, reset creds — in seconds, not hours.

eg: Shuffle (free), Cortex XSOAR, Splunk SOAR
🧩

Frameworks to learn early (they structure everything)

MITRE ATT&CK — catalogue of real adversary techniques · NIST CSF — identify/protect/detect/respond/recover (+govern) · CIS Critical Security Controls — the globally-used prioritized defensive baseline (also know your national CERT's guidance, e.g. ACSC's Essential Eight) · ISO 27001 — the international security management standard. Cite these confidently and you sound like a pro, fast.

SECTION 07 / THE ARMORY

The Essential Tools — 151 With What They're For

The working professional's toolbox, organised by job function. Every tool includes a one-line purpose and example usage. Start with the ⭐ beginner picks; grow into the rest. (Almost everything here is free and open source.)

🐉 Security Operating Systems — your foundation

8

One download = hundreds of preinstalled tools. Install in a VM (Section 09), never as your daily driver OS holding personal files.

Kali Linux ⭐offense · debian
the industry-standard pentest distro

Start here. Prebuilt with Nmap, Metasploit, Burp, Wireshark & 600 more. Free from kali.org — run it as a VM.

Parrot Security OSoffense/privacy · debian
lighter Kali alternative with privacy tools

Beautiful, lighter on RAM (good for older laptops), includes anon tools like Tor/AnonSurf.

BlackArchoffense · arch
2,800+ tools for advanced users

Enormous arsenal on Arch Linux. Fantastic once you're comfortable with Linux — not day-one material.

Commando VMoffense · windows
Mandiant's Windows pentest VM

Turns a Windows VM into an attack box — perfect for Active Directory practice on the platform attackers actually target.

REMnux ⭐malware analysis
Linux toolkit for reverse-engineering malware

Preloaded with malware-dissection tools (Ghidra, PE tools, fake network services). Pair with Flare VM.

FLARE VMmalware analysis · windows
Windows malware-analysis distribution

Mandiant's Windows box of debuggers/decompilers for safe malware study in an isolated VM.

SIFT Workstationforensics
SANS forensics distro

DFIR toolkit matching SANS courses: timeline analysis, memory forensics, registry tools.

Security Onion ⭐defense · NSM
free enterprise SOC-in-a-box: IDS+SIEM+pcap

Bundles Suricata, Zeek, Elastic, Kibana, CyberChef. Build this in your home lab = real blue-team experience on your resume.

🔍 Reconnaissance & Network Scanning

13

"Amateurs hack systems; professionals hack information first." Enumeration is 80% of every engagement and CTF.

Nmap ⭐scanner · cli
nmap -sV -sC -O target.com

The network scanner: discover hosts, open ports, service versions, OS, run scripted checks (-sC). Learn it until flags are muscle memory.

Zenmapscanner · gui
official Nmap GUI

Point-and-click Nmap with topology maps. Great while you memorise CLI flags.

Rustscanscanner · fast
rustscan -a target -- -sV

Blazing-fast port scanner that pipes results into Nmap. CTF favourite: full port sweep in seconds.

Masscanscanner · internet-scale
masscan -p1-65535 10.10.10.0/24 --rate=1000

Scans absurdly fast (the whole internet in minutes). Careless use = knocking on every door in town.

Netcat (nc) ⭐swiss-army tcp/udp
nc -nvlp 4444 · nc target 80

Read/write raw network connections: banner grab, chat, transfer files, catch reverse shells. Tiny tool, infinite uses.

Angry IP Scannerscanner · gui
quick LAN discovery

Simple friendly GUI ping/port sweeper — handy for surveying your home lab.

Shodan ⭐search engine · web
shodan.io — "product:apache country:AU"

The search engine of internet-connected devices: open cams, exposed databases, ICS gear. Recon without sending a single packet.

Censyssearch engine · web
censys.io — certificates & hosts search

Shodan's scholarly sibling: internet-scan data + TLS certificate history to map any org's footprint.

theHarvesterrecon · osint
theHarvester -d target.com -b all

Harvests emails, subdomains, employee names from public sources — builds a phishing-target list (defenders: audit yourself!).

Amassrecon · subdomains
amass enum -d target.com

OWASP's deep subdomain enumerator — discovers an org's forgotten dev/staging servers where bugs breed.

subfinderrecon · subdomains
subfinder -d target.com -silent

Fast passive subdomain discovery. Pipe into httpx → live web targets in two commands.

Recon-ngrecon · framework
metasploit-style OSINT framework

Modular web-recon framework with marketplace modules — automates the "who are they?" phase.

enum4linux-ngenum · smb
enum4linux-ng -A 10.10.10.5

Rips users, shares, and policy info out of Windows/Samba hosts. First stop on any box with SMB open.

🦈 Traffic & Packet Analysis

8

Reading packets is a superpower for both teams: attackers sniff secrets; defenders see evil hiding in plain sight.

Wireshark ⭐packet analysis · gui
filter: http.request or dns

The world's most-used protocol analyser. Capture traffic, follow TCP streams, carve files. Do the Wireshark TryHackMe room early.

tcpdumppacket capture · cli
tcpdump -i eth0 -w capture.pcap

Terminal packet capture for servers and CTF boxes. The flags look scary; learn five and you're set.

tsharkwireshark · cli
tshark -r cap.pcap -Y "http" -T fields

Scriptable Wireshark — extract fields from huge pcaps, perfect for CTF automation.

Zeek (Bro) ⭐NSM · framework
zeek -r traffic.pcap → rich logs

Turns raw traffic into structured logs (conn.log, dns.log, http.log). Core of network security monitoring & Security Onion.

NetworkMinerpcap forensics · gui
drag-and-drop pcap analysis

Passive sniffer that rebuilds files, images, credentials from pcaps. Blue-team CTF darling.

Brim / Zuipcap analysis · gui
zeek logs + visual queries

Beautiful desktop app for hunting through pcaps with Zed queries. Great intro to network forensics.

Ettercaplan attacks · mitm
ettercap -G (graphical MITM suite)

Classic ARP-poisoning/MITM suite for your lab only. Seeing cleartext creds fly by teaches why TLS matters.

Bettercaplan attacks · modern
bettercap -iface eth0

Modern MITM framework: ARP/DNS spoofing, wifi attacks, credential capture. The attacker's Wireshark.

🕸️ Web Application Testing

13

Web is the most beginner-friendly (and most employed) attack surface. Master these and PortSwigger Academy and you can do real bug bounties.

Burp Suite ⭐intercept proxy
browser → Burp → site: inspect & modify everything

The web-tester's weapon #1: intercept, replay (Repeater), fuzz (Intruder), scan (Pro). Community Edition is free — learn it deeply.

OWASP ZAP ⭐intercept proxy · free
free Burp alternative + automated scanner

100% free/open from OWASP. Great for automated scans and CI pipelines. Teams often run both ZAP and Burp.

Browser DevTools ⭐built-in · f12
F12 → Network / Console / Sources

Already installed! Inspect requests, cookies, localStorage, JavaScript. Solve XSS labs with nothing else.

Gobustercontent discovery
gobuster dir -u http://site -w list.txt

Brute-forces hidden directories/files (/admin, /backup.zip), virtual hosts and subdomains.

ffuffuzzer · fast
ffuf -w words.txt -u http://site/FUZZ

"Fuzz Faster U Fool": fuzz parameters, dirs, vhosts at high speed with fine filters. CTF essential.

Niktoweb scanner
nikto -h http://target

Veteran web server scanner: outdated software, dangerous files, misconfigs. Noisy — which is a lesson itself.

sqlmap ⭐sqli automation
sqlmap -u "site/item?id=1" --dbs

Detects & exploits SQL injection automatically — even dumps databases. Learn manual SQLi first, then let sqlmap flex.

WPScanwordpress
wpscan --url http://site -e vp,u

WordPress = 40%+ of the web. WPScan finds vulnerable plugins/themes and enumerates users.

Nuclei ⭐vuln scanner · templates
nuclei -u https://target -t cves/

Community template–driven scanner: thousands of one-click CVE/misconfig checks. Bug-bounty hunters live in it.

Wappalyzerfingerprinting
browser extension: what is this site running?

Identifies CMS, frameworks, server tech on any site — shapes your attack plan instantly.

httpxprobing · cli
cat subs.txt | httpx -title -status-code

Probes huge host lists: which are live, what tech, what status. Glue tool of recon pipelines.

Postmanapi testing
craft & replay API calls

APIs leak data constantly (see OWASP API Top 10). Postman is how you poke them methodically.

Caidoproxy · modern
lightweight modern Burp-like proxy

Fast, pretty newcomer for HTTP interception — nice alternative when Burp CE rate-limits Intruder.

💥 Exploitation Frameworks & Post Exploitation Access

11

Where vulnerabilities become shells. Practice these ONLY in your lab and on legal platforms — see the ethics banner, always.

Metasploit Framework ⭐exploitation
msfconsole → use exploit/... → set RHOSTS → run

The legendary exploit framework: 2,000+ modules, payloads and post-ex modules. The free "Metasploit Unleashed" course is a rite of passage.

msfvenompayload builder
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=.. LPORT=.. -f exe -o shell.exe

Metasploit's payload factory: generate shells for any platform/format. Learn payloads by building them.

Meterpreterpost-ex shell
migrate · hashdump · screenshot · getsystem

Metasploit's in-memory super-shell: file system control, keylogging, pivoting, privilege escalation — all living in RAM.

Exploit-DB / Searchsploit ⭐exploit archive
searchsploit apache 2.4.49

Offline copy of the Exploit Database. Found a service version? Searchsploit finds the public exploit. CTF daily driver.

BeEFbrowser exploitation
hook a browser via XSS, own the session

Browser Exploitation Framework — demonstrates why XSS is terrifying: control the victim's browser in real time.

SET (Social-Engineer Toolkit)phishing sim
clone sites, craft spear-phish, USB attacks

TrustedSec's framework for authorized social-engineering simulations. Why "think before you click" training exists.

Impacket ⭐windows protocols · python
psexec.py · secretsdump.py · GetNPUsers.py

Python classes for attacking Windows protocols — the toolbox behind most AD exploitation and Kerberos attacks.

NetExec (nxc)network execution
nxc smb 10.0.0.0/24 -u user -p pass --shares

CrackMapExec's successor: validate creds, spray, dump, execute across whole subnets. AD pentest essential.

Responder ⭐poisoning · windows
responder -I eth0 → capture NTLMv2 hashes

Poisons LLMNR/NBT-NS on Windows networks and catches password hashes from thin air. Lab-only; shows why those protocols die in secure orgs.

Evil-WinRMwindows shell
evil-winrm -i 10.10.10.5 -u admin -p pass

The comfortable way to land on Windows via WinRM with creds or a hash. HTB players' best friend.

Chisel / Ligolo-ngtunneling · pivot
chisel server / client → socks through firewalls

Relay traffic through compromised hosts to reach hidden networks — pivoting made simple.

🔑 Password & Hash Attacks

8

Humans pick terrible passwords; these tools prove it — in your lab, for system owners, or on leaked-hash CTF challenges.

Hashcat ⭐gpu cracking
hashcat -m 1000 hashes.txt rockyou.txt -r rules

The fastest hash cracker on earth, powered by your GPU. Combine wordlists + rules to crack NTLM/SHA/etc. Benchmark it once — it's fun.

John the Ripper ⭐cpu cracking
john --wordlist=rockyou.txt hashes.txt

The classic cracker, superb on Linux/Unix hashes (/etc/shadow). Pairs with ssh2john/zip2john to crack archives & keys.

Hydra ⭐online bruteforce
hydra -L users.txt -P rockyou.txt ssh://target

Parallel online login attacks against SSH/FTP/web forms/RDP. Use in labs; in the real world it locks accounts and trips alarms.

Medusaonline bruteforce
medusa -h target -U users -P passes -M ssh

Hydra's stable, speedy cousin. Know both; they complement oddly-specific services.

rockyou.txt ⭐wordlist
14 million real leaked passwords

Ships with Kali (gzip'd at /usr/share/wordlists). The definitive wordlist — together with SecLists it forms 90% of password challenges.

SecLists ⭐wordlists
usernames, passwords, dirs, fuzzing payloads

Daniel Miessler's curated collection for every wordlist need — especially web dirs and parameter names.

CeWLcustom wordlists
cewl https://target.com -w list.txt

Spiders a website to build a company-flavoured wordlist ("AcmeCorp2026!"). Passwords come from culture — exploit it (with permission).

CrackStation / Name-That-Hashonline · hash id
paste a hash → instant type & crack

Online rainbow-table lookup for quick checks; Name-That-Hash identifies unknown hash formats instantly.

🪜 Privilege Escalation & Post-Exploitation

10

Getting in is half the story. These find the misconfigurations that turn "limited shell" into "Domain Admin".

LinPEAS / WinPEAS ⭐privesc enum
./linpeas.sh → highlights 95% of the attack path

PEASS-ng scripts auto-enumerate Linux/Windows privilege-escalation vectors in screaming colour. Run them on every CTF box.

GTFOBins ⭐living-off-land
gtfobins.github.io → "find" sudo → root

Bible of Unix binaries that can be abused (sudo, SUID, capabilities) to escalate. Bookmark it forever.

LOLBASliving-off-land · win
lolbas-project.github.io

Windows equivalent: legit Microsoft binaries attackers abuse (certutil download, mshta execution). Defenders monitor for these too.

Mimikatz ⭐windows creds
sekurlsa::logonpasswords

Extracts plaintext creds, hashes and tickets from Windows memory. The tool that made "credential hygiene" a boardroom topic.

BloodHound ⭐AD mapping
SharpHound collect → graph: shortest path to DA

Maps Active Directory attack paths as a graph — reveals "Helpdesk→3 hops→Domain Admin" chains instantly. Red and blue both swear by it.

PowerUp / SharpUpwin privesc enum
Invoke-AllChecks

PowerSploit's Windows enumeration checks: unquoted service paths, weak service ACLs, AlwaysInstallElevated…

Seatbeltwin situational awareness
Seatbelt.exe -group=all

C# host enum swiss-army: who am I, what's here, what's defensible. Part of the standard C2 toolkit experience.

Rubeuskerberos abuse
Rubeus.exe kerberoast

The go-to for Kerberos attacks: kerberoasting, AS-REP roasting, ticket manipulation.

pspylinux process watch
./pspy64 → see cron jobs & commands without root

Watches every process spawning (even other users') without privileges — exposes cron scripts and mistyped passwords.

linux-exploit-suggesterkernel audits
suggests local kernel exploits by version

Compares kernel/distro versions against known local-exploit lists (DirtyCow era classic). LES + LinPEAS = the standard workflow.

📡 Wireless Hacking

6

You'll need a USB Wi-Fi adapter that supports monitor mode (Alfa AWUS036-series are the community favourites).

Aircrack-ng suite ⭐wifi cracking
airmon-ng → airodump-ng → aireplay-ng → aircrack-ng

The complete Wi-Fi audit suite: monitor, capture handshakes, deauth, crack WPA keys. The official tutorial is a legendary first lab.

Wifiteautomated wifi
wifite --kill

Automates Aircrack attacks end-to-end: WEP/WPA/WPS. Great for understanding the attack chain hands-on.

Kismetwireless IDS
kismet → wardriving & rogue-AP detection

Passive wireless sniffer/IDS — maps networks, detects rogue access points. The defender's wireless eyes.

hcxdumptool + hcxtoolspmkid attacks
capture PMKID → hashcat 22000

Modern clientless WPA attacks — grab a crackable hash without any client connected. Then feed hashcat.

Reaver / Bullywps bruteforce
reaver -i wlan0mon -b BSSID

Attacks WPS PIN weakness on older routers. Mostly dead on modern gear — but knowing why = interview points.

Bettercap (wifi)rogue ap
wifi.recon / fake APs / evil twin

Create lookalike networks and harvest hand-ins from unsuspecting devices — the evil-twin demo every awareness training uses.

🔬 Digital Forensics (DFIR)

12

The science of answering "what happened?" from artifacts. Quietly one of the most employable and satisfying specialties.

Autopsy + Sleuth Kit ⭐disk forensics · gui
open a disk image → timeline, deleted files, artifacts

Free, friendly forensic platform for disk images. Recover deleted files, browser history, USB artifacts. The CyberDefenders labs pair perfectly.

Volatility 3 ⭐memory forensics
vol -f memdump.raw windows.pslist

Analyse RAM captures: running processes, injected code, connections, credentials in memory. Memory never lies.

FTK Imager ⭐acquisition
create forensic disk images + preview

Industry-standard imaging tool (free!). First rule of forensics: work on images, never originals.

KAPEtriage collection
collect key artifacts in minutes

Eric Zimmerman's Kroll Artifact Parser & Extractor — grabs registry hives, event logs, browser data fast for offline analysis.

Eric Zimmerman's Tools ⭐artifact parsers
MFTECmd · EvtxECmd · PECmd · RegistryExplorer

The definitive Windows artifact parsers. Real IR shops run on these. Free with training videos.

Wireshark (again)network forensics
pcap is evidence: follow streams, export objects

Case captures constantly hide exfil in DNS/HTTP — carve it out and prove it.

ExifTool ⭐metadata
exiftool secret.jpg → GPS, camera, timestamps

Reads/writes metadata in hundreds of formats. CTF stego staple; real-world leak detector (phones embed GPS!).

binwalk ⭐firmware/file carving
binwalk -e firmware.bin

Finds & extracts files hidden inside other files/firmware. First command in CTF forensics.

TestDisk + PhotoRecrecovery
undelete partitions & files (free)

Recover lost partitions and deleted files by signature — also handy when ransomware nukes a test VM.

Plaso / log2timelinesuper timeline
every timestamped artifact → one timeline

Builds a unified timeline from disks, logs, browsers. Timelines answer "when, then what?" — the heart of IR storytelling.

Velociraptor ⭐dfir at scale
query a whole fleet's artifacts live

Open-source DFIR platform: hunt VQL queries across thousands of endpoints in seconds. Enterpise-grade and free.

Registry Explorer / Timeline Explorergui analysis
browse registry & CSV timelines visually

The friendly front-ends that make Windows forensics approachable while you learn the artifacts.

🧪 Malware Analysis & Reverse Engineering

12

Open malicious files safely in REMnux/FLARE VMs with the network shut off — see the lab safety rules before you ever detonate anything.

Ghidra ⭐reverse engineering · free
decompile binaries → readable C-like code

NSA's released RE suite — professional-grade and free. Disassemble, decompile, patch. Start with crackmes.

IDA Freedisassembler
industry-standard disassembler (free edition)

The famous Interactive Disassembler. Most tutorials/books use IDA — worth learning the UI early.

x64dbg / x32dbgwindows debugger
step through malware live, break, watch memory

Open-source Windows debugger for dynamic analysis and crackmes. Friendlier than WinDbg for beginners.

Cutter + radare2re · cross-platform
r2 binary → GUI via Cutter

Free RE framework beloved by CTF players for binaries on any architecture.

PEStudio ⭐static triage
drop a .exe → flags imports, strings, entropy

Instant suspicious-file triage: what it imports, what it pretends to be, MITRE mappings.

Any.Run ⭐sandbox · interactive
upload sample → watch it live in a VM

Interactive online sandbox: click like a user, watch processes/network in real time. Free tier + great public reports to learn from.

Hybrid Analysissandbox · reports
deep automated behaviour reports

Free CrowdStrike sandbox — excellent static+dynamic reports when studying samples safely from your browser.

VirusTotal ⭐multi-scanner
search a hash → 70 engines' verdicts

Lookup hashes/URLs across dozens of AV engines + sandbox telemetry. Daily reference for analysts. (Don't upload real secret files!)

YARA ⭐malware patterns
rule: strings + conditions → match families

Write pattern rules to classify/hunt malware. Every SOC, sandbox and CTF uses YARA — learn the syntax day one.

Procmon + Process Hackersysinternals
watch every file/reg/network touch in real time

Windows dynamic-analysis eyes: see exactly what a program does. Sysinternals Suite is mandatory Windows study anyway.

FakeNet-NG / INetSimfake internet
malware thinks it's online — you watch

Simulate DNS/HTTP services in an isolated VM so malware reveals its C2 behaviour safely.

Detect It Easy (DIE)packer id
what packer/compiler made this binary?

Identifies packers (UPX!), compilers, protections — step 1 before unpacking.

🛰️ SOC, SIEM & Network Defense (Blue Toolbox)

13

Install these in your home lab and you can honestly list SIEM/EDR/IDS experience on your resume.

Splunk (Free) ⭐siem
index="*" error | stats count by src

The enterprise SIEM leader — free 500MB/day tier is plenty for a lab. Splunk skills = directly employable; free Fundamentals course + Boss of the SOC dataset.

Wazuh ⭐siem+xdr · free
agents + manager → FIM, vuln, MITRE alerts

Free open-source SIEM/XDR: file integrity, vulnerability detection, MITRE-mapped alerts. The best first blue-lab install.

Elastic Stack / Elastic SIEMsiem · free tier
ELK: search, dashboards, detection rules

Elasticsearch + Kibana + Beats/Agents power countless SOCs. Learn KQL-style querying once, use it everywhere.

Suricata ⭐ids/ips
suricata -c suricata.yaml -i eth0

Fast IDS/IPS using ET Open rules. Feed it homelab traffic, watch it bark at your own Nmap scans.

Snortids · classic
snort -A console -c snort.conf

The original open-source IDS (1998!) — still everywhere, still taught in certs. Learn rule syntax once: alert tcp any any → any 445.

Zeek + Security Onion ⭐nsm stack
full network security monitoring

Security Onion ships Zeek+Suricata+Elastic pre-integrated: a real SOC console in one VM (see Section 09).

pfSense ⭐firewall · free
virtual-ize your network with real firewall rules

FreeBSD firewall/router distro — learn NAT, rules, VLANs, VPNs by actually building them. Core of serious home labs.

Sysmon ⭐windows logging
sysmon -i with SwiftOnSecurity's config

Turns Windows Event Logs from "meh" into a goldmine: process creation, network connections, loading of suspicious DLLs. Pair with Wazuh/Splunk.

Sigma ⭐detection rules
generic rules → convert to any SIEM

The open standard for detections ("detect mimikatz-like process names"). Write one rule, run it in Splunk/Elastic anywhere.

Grayloglog management
open-source log centralisation

FREE friendly log platform with streams, pipelines, alerts — a gentler first SIEM than the giants.

Fail2Banips · hosts
5 failed SSH logins → IP banned

Tiny daemon that bans brute-forcers by tailing logs. Install on any internet-facing Linux box — and on day one of any VPS.

Shuffle SOARautomation
open-source SOC automation workflows

Drag-and-drop playbooks: alert → enrich (VT, AbuseIPDB) → block. Learn SOAR concepts free.

MITRE Calderaadversary emulation
run ATT&CK techniques → test detections

Automated adversary emulation platform. Purple-team your lab: fire techniques, confirm your SIEM catches them.

🕵️ OSINT — Open Source Intelligence

13

Find out what the internet already knows. Used by pentesters for recon, SOCs for investigations — and by you to check your own footprint.

Maltego CE ⭐link analysis · gui
graph: person → emails → domains → infra

Visual intelligence graphs connecting people, domains, IPs, breaches. Free Community edition in Kali.

Google Dorking ⭐search operators
site:target.com filetype:pdf "confidential"

Advanced search operators expose forgotten files, admin panels, cameras. Free, powerful, underrated — master the syntax.

OSINT Frameworkdirectory
osintframework.com — the curated map

Interactive tree of hundreds of OSINT resources by category (usernames, emails, images, leaks…).

theHarvester / Amassin recon too
emails + subdomains from public sources

(See Recon section.) OSINT and recon are cousins — these tools sit at the border.

Sherlock ⭐username hunt
sherlock johndoe → 300+ sites

Finds where a username exists across hundreds of platforms. Prolific for investigations (and self-auditing).

SpiderFootautomation
spiderfoot: 200+ modules, one scan

Automates massive OSINT sweeps: DNS, breaches, emails, darknet mentions. Great for footprinting an org.

Have I Been Pwned ⭐breach lookup
has this email leaked? which breach?

Troy Hunt's legendary service. Check your own accounts, enable the free notify-list. A household name in security.

Wayback Machine ⭐time travel
web.archive.org — deleted ≠ gone

Historical snapshots of any site: find removed admin pages, old emails, "deleted" evidence.

TinEye / Google Lensimage search
reverse-search that profile pic

Trace images across the web: sock accounts fall apart fast with these.

IntelTechniques Toolscollection
Michael Bazzell's free OSINT tool pages

Custom search consoles for social, breaches, maps & more from the author of "OSINT Techniques".

PhoneInfogaphone numbers
carrier, location, reputation of a number

Investigate phone numbers: Truecaller hits, disposable-number flags. Great for vishing investigations.

BuiltWith / Wappalyzertech profiling
what tech stack is that company built on?

Profiles a company's web tech → targets for both attacks and job interviews ("I see you use Splunk…").

AbuseIPDBreputation
is this IP known-bad? confidence %

Crowdsourced IP abuse reports — the SOC's reflex check on every alert IP.

🩹 Vulnerability Management

5

Find weaknesses before attackers do, and prove it with reports. An everyday corporate task — great to have on your resume.

Greenbone / OpenVAS ⭐scanner · free
full-network authenticated & unauthenticated scans

Open-source enterprise-grade vulnerability scanner. Runs in your lab VM and produces pro-looking reports.

Nessus Essentials ⭐scanner · free tier
free 16-asset licence of the industry leader

Tenable's famous scanner, free for home labs. Learn the interface — you'll meet it at work, guaranteed.

Nuclei (again)template scanning
fast CVE/misconfig checks at scale

Belongs here too — continuous, scriptable vuln checks with community templates.

Lynislinux hardening audit
lynis audit system → hardening suggestions

Audits a Linux host against best practices and tells you exactly what to fix. Run it on your own VPS for instant wins.

SCAP / OpenSCAP + CIS-CATcompliance benchmarks
measure hosts against CIS Benchmarks

Automated compliance scoring against the famous CIS hardening benchmarks — GRC meets engineering.

🧰 CTF & Everyday Utilities — the beloved helpers

12

The small tools you'll use daily, whichever team you join.

CyberChef ⭐swiss-army decoder
base64 → hex → zip → decode magic in your browser

GCHQ's "Cyber Swiss Army Knife": 300+ operations — encoding, crypto, compression, extraction. CTF oxygen.

dCode.frcipher solver
identify & decode hundreds of ciphers

Caesar to Vigenère to mystery hashes — classic-crypto challenges solved in seconds.

HackTricks ⭐knowledge base
book.hacktricks.xyz — "how to attack X"

The pentester's encyclopedia: every service, misconfig and technique with commands. The community's brain, free.

PayloadsAllTheThingscheat repo
ready-made payloads for every vuln class

GitHub repo of curated payloads/methodologies (SQLi, XSS, SSRF…). CTF clipboard.

RevShells.com ⭐shell generator
click options → copy your reverse shell one-liner

Every language's reverse/bind shell, plus URL/Base64 encoding. Saves real time in labs.

WADComswindows cheatsheet
"I have X, want Y" → exact command

Interactive cheat-sheet for Windows/AD: filters by what you have (creds? shell?) and shows commands.

tmux ⭐terminal multiplexer
panes + sessions that survive disconnects

Split screens for scan + listener + notes, and never lose a session. A pro's terminal looks like tmux.

Obsidian ⭐notes
markdown knowledge base for write-ups

Document every machine, command and lesson. Your notes become your portfolio and future self's gift.

Aperi'Solvestego analysis
upload image → strings, zsteg, exif, binwalk at once

One-stop online steganography triage for CTFs.

Steghide / zstegstego tools
steghide extract -sf pic.jpg

Classic hidden-data tools (zsteg shines on PNG/BMP LSB data).

Docker ⭐containers
docker run -it ... → any lab app instantly

Spin up vulnerable apps (Juice Shop!), tools and malware sandboxes without polluting your VM. Learn basic Docker — it's how labs are shipped now.

VirtualBox / VMware ⭐virtualization
your entire lab runs on this

Free hypervisors hosting your Kali + targets + SIEM. Section 09 builds on them. (VirtualBox is free; VMware Workstation Pro is now free for personal use.)

🔐 Personal Security Starter Pack — protect yourself first

7

Credibility rule #1: secure yourself. Set this up in week one; it also doubles as your first mini-project.

Bitwarden ⭐password manager · free
unique 20+ char passwords everywhere

Open source, free, everywhere. Non-negotiable modern hygiene — password reuse is how people get owned.

KeePassXCoffline manager
local encrypted database, no cloud

Fully offline alternative beloved by the paranoid (healthy paranoia). Kali users' default.

Aegis / 2FAS (authenticator)mfa app
TOTP codes > SMS codes

App-based MFA with encrypted backup. Turn MFA on for email first, then everything else.

VeraCryptdisk encryption
encrypted containers & full-disk encryption

Free TrueCrypt successor — encrypt research, notes and VM drives on shared machines.

Mullvad / ProtonVPNvpn
hide traffic from sketchy networks

Reputable no-log VPNs for untrusted Wi-Fi. (A VPN is privacy hygiene, not magic invisibility.)

uBlock Origin + Privacy Badgerbrowser
block trackers & malicious ad networks

Malvertising is a real attack vector. Harden your daily browser, too — you are a target now.

Signalencrypted messaging
private comms, disappearing messages

End-to-end encrypted messaging with sealed-sender design. Community standard.

⚠️

Golden safety rule for tools

Run offensive tools only inside your isolated lab VMs or on platforms that explicitly permit it (TryHackMe, HTB, CTFs, bug bounty scope). Scanning or attacking systems you don't own or lack written permission for is a crime nearly everywhere in the world (US CFAA, UK Computer Misuse Act, and national equivalents). Skill + ethics = employable. Skill without ethics = criminal record.

SECTION 08 / THE ROADMAP

Your Path From Zero to Hireable

The proven sequence. Each phase builds on the last; each ends with something you can show. Realistic pace: 60–90 minutes daily, weekends for labs. (The detailed week-by-week version is the 90-Day Plan in Section 13.)

PHASE 0 · THIS WEEK

Set up & set the rules

Install VirtualBox/VMware + Kali VM. Create TryHackMe, picoCTF, OverTheWire accounts. Set up Bitwarden + MFA on your own accounts. Start a notes system (Obsidian) — professionals document everything.

  • Deliverable: working Kali VM + organized notes vault.
PHASE 1 · MONTHS 1–2

Bedrock: IT, Networking, Linux

Professor Messer's free Network+ playlist (don't need the exam yet — the knowledge). Simultaneously grind OverTheWire Bandit to ~level 25 and TryHackMe's Pre-Security path. Basic Python: automate one boring task.

  • You can explain DNS, TCP vs UDP, and the OSI model at a whiteboard.
  • You are comfortable living in a Linux terminal.
PHASE 2 · MONTHS 2–4

Security core concepts + guided hacking

TryHackMe Introduction to Cyber Security + SOC Level 1 or Jr Penetration Tester path (pick per interest). Learn Nmap, Wireshark, Burp basics; read Section 04–06 of this guide until fluent. Start picoCTF general-skills challenges.

  • Deliverable: 100+ rooms/challenges completed, 10 published write-ups on GitHub/blog.
PHASE 3 · MONTHS 4–6

Specialize + home lab + first cert

Pick a lane (SOC vs pentest vs GRC — you can switch later). Build the full home lab (Section 09): targets + Wazuh/Splunk watching them. Study with Professor Messer + practice exams and book CompTIA Security+ (or start with free ISC2 CC first). Add HackTheBox Starting Point or PortSwigger Academy tracks.

  • Deliverable: first certification scheduled/passed + lab screenshots + detection write-ups.
PHASE 4 · MONTHS 6–12

Proof of skill → job hunting

Weekly CTFs (CTFtime), one flagged machine write-up a week, polish LinkedIn (list labs & projects!), attend BSides cons, OWASP/ISACA chapters and local meetups. Apply for SOC L1, service-desk-with-security, internships, grad programs (banks, telcos, consultancies, government) while continuing labs. Interviews love people who never stopped building.

  • Deliverable: portfolio (GitHub + blog), 50+ applications, community presence, first interviews.
QUICKSTART — YOUR FIRST 24 HOURS IN CYBER
  1. Hour 1: Download VirtualBox + Kali Linux VM image. Import, allocate 4GB RAM / 2 CPUs, boot, update (sudo apt update && sudo apt upgrade).

    You now own the same machine professionals hack banks (legally) with.

  2. Hour 2: Play OverTheWire: Bandit levels 0–5. Just SSH in and start — every level teaches one Linux skill.

    Feel the hacker-loop: stuck → research → solve → flag → dopamine.

  3. Hour 3: Register TryHackMe, finish the free "Tutorial" room + start Pre-Security path.

    Guided, browser-based, zero install — this is your structured course for months.

  4. Hour 4–6: Watch: "Hold on... how does the internet work?" (any good networking primer), then a NetworkChuck "So you want to be a hacker" style roadmap video for motivation.

    Beginner hype is fuel — use it.

  5. Day 1 wrap: Secure yourself: Bitwarden + MFA + unique passwords; start Obsidian notes vault with pages: "Networking", "Linux", "Tools".

    Security people secure themselves first — always.

🎯

The only strategy that works

Small daily sessions beat weekend binges. 45–90 focused minutes every day + one longer lab on the weekend. Take notes on everything (future you is forgetful). When stuck >30 min, look up a hint — time-boxed struggle is learning; endless struggle is quitting fuel.

🧭

"Which side should I choose?"

Don't choose yet. Do two months of TryHackMe's both-track content, a picoCTF (offense flavour) and a couple of CyberDefenders blue labs (defense flavour). Your energy levels while doing them will tell you the answer better than any quiz.

SECTION 09 / BUILD YOUR DOJO

The Home Lab Blueprint — Your Private Hacking & Defense Playground

A home lab is the single best career accelerator: a safe, legal network where you attack VMs, then watch your own SIEM catch yourself doing it. Both red and blue skills from one laptop. Here's the exact blueprint.

INFOGRAPHIC 11 — HOME LAB ARCHITECTURE · ISOLATED INTERNAL NETWORK
YOUR PC / LAPTOP — runs VirtualBox or VMware ⚠ ISOLATED "lab-net" (host-only / internal, no internet by default) 🐉 KALI LINUX attacker 🎯 METASPLOITABLE 2 victim (intentionally weak) 🪟 WIN 10 / SERVER EVAL victim (90-day free eval) 🛡️ WAZUH / SPLUNK defender (your SOC) 🧃 JUICE SHOP / DVWA vulnerable web apps (Docker) attack traffic agent logs & telemetry installation order: hypervisor → kali → victims → siem agents → dashboards → hack yourself → detect yourself 🌐 INTERNET temporary NAT only
updates & packages,
then disconnect again 🧱 pfSense (optional lvl-up) real firewall rules / VLANs / VPN
One physical computer, one invisible internal network, an entire attack-vs-defense ecosystem. Choose "host-only"/"internal" networking so nothing can escape — that rule is what keeps your lab legal and safe.

🛠️ Hardware & software checklist

RAM16 GB ideal · 8 GB works (run 2 VMs max)
Disk80–150 GB free (SSD strongly preferred)
CPUany modern 4-core+ with VT-x/AMD-V enabled in BIOS
HypervisorVirtualBox (free) or VMware Workstation Pro (now free personal)
Optional lvl-upold PC/Intel NUC + Proxmox = always-on lab server ($0–250 used)
Snapshot habitsnapshot every VM clean, before each risky exercise

📥 Exactly what to download (all free)

  1. Kali Linux VM — prebuilt VirtualBox/VMware image (kali.org) → your attacker.
  2. Metasploitable 2 — intentionally-vulnerable Linux (sourceforge) → first target.
  3. Windows 10/11 or Server 2019/2022 Evaluation — free 90–180 days (Microsoft Evaluation Center) → learn AD basics; later promote to a Domain Controller.
  4. Ubuntu Server + Docker → host OWASP Juice Shop & DVWA in one command each.
  5. Wazuh (OVA) or Splunk Free → your SIEM; add agents/Sysmon to the Windows VM.
  6. VulnHub VMs — infinite free vulnerable machines to import as you level up.
🚧

Lab safety rules (non-negotiable)

① Lab VMs use host-only/internal networks — never bridged, especially when malware is involved. ② Only connect NAT briefly for updates, then disconnect. ③ Never use real personal files/passwords inside lab VMs. ④ Malware samples only inside fully-isolated VMs with snapshots — and never let them reach the internet. ⑤ Snapshot before everything; nuke-and-restore when in doubt. ⑥ Attack only lab IPs/platforms — no "testing" school/work/neighbour networks.

🎓 Lab exercises that become resume lines

portfolio gold

1 · "I attacked, then detected myself"

Nmap/Metasploit Metasploitable2 from Kali → review what Wazuh/Splunk captured → write it up: attack steps, IOCs, detection rule.

skills: scanning, exploitation, SIEM, writing

2 · Phishing-to-alert pipeline

Craft a lab phishing simulation (SET) → land on Windows VM with Sysmon → trace the chain in Splunk → write a Sigma rule that catches it.

skills: social engineering, Sysmon, detection engineering

3 · Mini Active Directory

Windows Server as Domain Controller + Win10 client. Create users/GPOs → run BloodHound → attack path with NetExec → map every step to MITRE ATT&CK.

skills: AD, BloodHound, ATT&CK mapping

4 · Malware sandbox

Isolated REMnux/FLARE pair detonating a known sample: PEStudio + Procmon + FakeNet → YARA rule from observed strings/behaviour.

skills: malware analysis, YARA

5 · Web pentest report

Full OWASP Top-10 sweep of Juice Shop with Burp → professional-style report: findings, evidence, risk ratings, fixes.

skills: web testing, reporting (the job!)

6 · Network segmentation

Add pfSense: VLANs for "users/servers/guest", firewall rules between them → prove with scans that lateral movement is now blocked.

skills: firewalls, segmentation, verification
SECTION 10 / TRAINING GROUNDS

Labs & Practice Platforms — Where Beginners Become Practitioners

Organised from "day one friendly" to "seasoned". Nearly all have generous free tiers. These are 100% legal environments designed to be hacked — so break everything with joy.

🌱 Tier 1 — Start here (guided, beginner-first)

free or freemium
⭐ #1 pick

TryHackMe

Browser-based guided "rooms" with built-in attack VMs. Paths: Pre-Security → Intro to Cyber → SOC L1 / Jr Pentester. The smoothest on-ramp in existence; free tier is genuinely usable, premium (~US$14/mo) unlocks all rooms.

start: Pre-Security path
⭐ linux

OverTheWire: Bandit

SSH wargame teaching Linux command-line through 34 puzzle levels. Free, legendary, frustrating in the best way.

goal: levels 0–25 in month 1–2
⭐ ctf

picoCTF + picoGym

Carnegie Mellon's free beginner CTF. picoGym practice challenges cover all categories year-round and are gentle enough for week one.

start: general skills + web basics
⭐ web ⭐

PortSwigger Web Security Academy

From the makers of Burp Suite: the best free web-security course in the world — bite theory + interactive labs for every vulnerability class.

start: SQLi + XSS learning paths
free cert

ISC2 Certified in Cybersecurity (CC)

ISC2's initiative offers the entry CC training + exam free (check current One Million pledge). A real certification on your resume quickly.

video labs

Cisco Networking Academy + Packet Tracer

Free "Introduction to Cybersecurity" & networking courses with virtual network simulator. Solid, accredited fundamentals.

course

Professor Messer (YouTube)

The internet's beloved free A+/Network+/Security+ video courses. Structured like the exams, cost like the air you breathe.

with ctf

Hacker101 (HackerOne)

Free video classes + CTF from the biggest bug-bounty platform. Great bridge to real bounty hunting.

deep linux

pwn.college

Arizona State's free curriculum: Linux, program exploitation, reverse engineering — from fundamentals to serious depth. For when you want to really understand computers.

⚔️ Tier 2 — Core training (intermediate paths)

months 2–6
⭐ offensive

HackTheBox — Starting Point + Academy

The famous pentest platform. Starting Point machines are beginner-guided; HTB Academy teaches structured modules; retired machines have IppSec video walkthroughs for every step.

progression: Tier 0 → Tier 2 boxes
free vms

VulnHub

Hundreds of free downloadable vulnerable VMs for your own lab — no subscription, runs offline, write-ups exist for most.

web / paid-lite

PentesterLab

Carefully crafted web & system exploitation exercises — excellent for understanding vulnerabilities at a technical depth interviews love.

⭐ defensive

LetsDefend

SOC simulator: real-ish alert queue, phishing triage, SIEM investigations with guided lessons. The closest thing to a SOC job you can do at home; generous free tier.

⭐ forensics

CyberDefenders

Free blue-team CTF labs: pcaps, disk images, memory dumps, phishing kits — investigate with the exact tools from Section 07.

blue labs

Blue Team Labs Online (BTLO)

Purpose-built defensive scenarios: incident response, malware, log analysis. Premium but beloved in blue-team circles.

crypto

CryptoHack + Cryptopals

Learn cryptography by breaking it — from XOR to attacking real constructions. Free; extremely fun for puzzle brains.

free mitre

AttackIQ Academy

Free courses on MITRE ATT&CK, detection engineering, adversary emulation (with Caldera) — resume-friendly, corporate-grade material.

siem data

Splunk Boss of the SOC (BOTS) dataset

Free real-world security dataset for Splunk practice. Recruiters recognise "BOTS" instantly.

🏔️ Tier 3 — Level-up & specialty (months 6+)

bragging rights
hard mode

HackTheBox main labs + Pro Labs

Untouched (no walkthrough) boxes, Active Directory ranges like Dante/Offshore, and the ranked leaderboard. Where OSCP-level skills are forged.

cert course

Security Blue Team (BTL1)

Blue Team Level 1: 6-week practical course + 24-hr incident-response exam. The premier entry blue-team credential.

cloud ⭐

PwnedLabs, flaws.cloud, CloudGoat

Cloud security hands-on: AWS misconfig hunting (free), Rhino's CloudGoat vulnerable-by-design environments. Cloud is where the jobs are.

AD range

GOAD / DetectionLab

Build entire multi-VM Active Directory forests with deliberate weaknesses + full logging. The upgrade your home lab deserves by month 6.

mobile

InjuredAndroid / DIVA / MSTG playground

Vulnerable Android apps from OWASP for mobile-security fundamentals.

crypto+

Root-Me & CTFlearn

Long-running free challenge archives covering everything from web to reversing — great for steady daily practice.

🏆

The golden rule of platforms: write it up

Every completed room/box/lab → a short write-up on GitHub (markdown) or a blog. Within months you'll own a public, verifiable portfolio: "I don't just say I can do it — here are 40 documented machines I've owned/investigated." That portfolio outperforms degrees with recruiters.

SECTION 11 / THE SPORT OF HACKING

CTFs — Capture The Flag, Explained

CTFs are competitive puzzle events where you solve security challenges to recover secret strings — flags — and score points. They're the industry's favourite sport, training system, and hiring filter all in one.

flag{y0u_just_l34rn3d_wh4t_a_flag_l00ks_l1k3} 🚩

Formats vary: flag{...}, CTF{...}, picoCTF{...} — you know it when you find it.

format 1

Jeopardy-style

A board of challenges across categories & difficulties (100–500 pts). Solve any, in any order. This is 90% of events and all beginner events.

format 2

Attack–Defense

Each team defends its own vulnerable servers while attacking others'. Intense, team-oriented, advanced.

format 3

Boot2Root / King of the Hill

Root a whole machine (HTB style), or hold a box against rivals replacing your persistence with theirs. Chaos, wonderful chaos.

🧩 The standard categories (and your first solve in each)

jeopardy

🌐 Web

Exploit web apps: SQLi, XSS, IDOR, source-code leaks. First solve: view-source, /robots.txt, cookie tampering.

🔐 Crypto

Break weak/ classic ciphers. First solve: CyberChef base64/ROT13, frequency-analysis a Caesar; dCode.fr is your sidekick.

🕵️ OSINT

Find things the internet already knows. First solve: reverse-image a landmark; Wayback Machine a "deleted" page.

🧾 Forensics

Analyze provided files (images, pcaps, memory). First solve: strings a file, check EXIF metadata, carve with binwalk.

🎭 Stego

Data hidden inside images/audio. First solve: steghide/zsteg, view colour channels, check LSBs.

⚙️ Reversing (RE)

Analyze a binary to find the flag it checks. First solve: run strings; then Ghidra the main() function.

💥 Pwn / Binary Exploitation

Overflow buffers, defeat mitigations, pop shells. The hardest category — pwn.college eases you in properly.

🗂️ Misc

Everything else: esoteric languages, pyjails, weird protocols. First solve + best teachers' notes live here.

📅 Where CTFs happen

CTFtime.org — the global calendar & ratings. Join weekend events (even alone) and read winning write-ups afterwards. Regulars: picoCTF (Mar–Apr, beginner heaven), HTB University/Business CTFs, Google CTF, DEF CON qualifiers, DownUnderCTF (huge and beginner-friendly).

🧠 CTF survival etiquette & tips

Timebox: 30 min stuck → read a hint. Take notes for the write-up as you go. After every event read others' write-ups — that's where the compounding growth is. Team up: a 3-person beginner squad covers 3x the categories. Never share flags mid-event.

SECTION 12 / CERTIFICATIONS

The Certification Ladder — From Free to Elite

Certs don't prove mastery — they get you past HR filters and structure your learning. Strategy: free starter cert → Security+ (the golden key) → one hands-on track cert. Prices are approximate in USD and change — always check current rates.

INFOGRAPHIC 12 — THE CLIMB
Tier 0
Free starter
Tier 1
Foundation
Tier 2
Hands-on entry
Tier 3
Professional
Tier 4
Elite / Mgmt

Tier 0 — Free / almost free (months 0–2)

zero excuses

🆓 ISC2 CC — Certified in Cybersecurity

Free self-paced training + exam under ISC2's "1 Million Certified" pledge (verify it's still active). Covers security principles, network security, IR basics. ✦✧✧✧✧

cost: $0 · resume-ready in 4–8 weeks

🆓 Cisco NetAcad: Introduction to Cybersecurity

Free course + digital badge from Cisco's academy. Great very-first credential. ✦✧✧✧✧

cost: $0

💲 Google Cybersecurity Certificate

Coursera program: SIEM, Python, Linux, detection — aimed squarely at job-switchers. Frequently used to pass HR screens in the US/AU. ✦✦✧✧✧

cost: ~US$49/mo × 3–6 months (financial aid exists)

💲 Microsoft SC-900

Security/Compliance/Identity fundamentals — easy, cheap, and Microsoft shops recognise it instantly. Watch for free exam vouchers via MS events. ✦✧✧✧✧

cost: ~US$99

🆓 Splunk Fundamentals 1

Free official Splunk e-learning — the skill that shows up in most SOC job ads (exam/cert optional ~US$130). ✦✧✧✧✧

cost: $0 training

🆓 Fortinet NSE 1–3 (now FCF/FCA)

Vendor training, free, and decent for vocabulary/interviews. ✦✧✧✧✧

cost: $0

Tier 1 — The foundation crown jewel (months 3–6)

most job posts name it
⭐ THE entry cert

CompTIA Security+ (SY0-701)

The world's default first security certification — appears in a huge share of junior job ads and satisfies US DoD 8570 requirements. Study free with Professor Messer + practice exams (Dion/Gibson). ✦✦✦✧✧

cost: ~US$404 exam · study 6–10 weeks

CompTIA Network+ (optional)

Skip the exam if you're networking-fluent from Phase 1 — but the syllabus/Professor Messer playlist remains the best networking study guide in existence. ✦✦✧✧✧

cost: ~US$369 (knowledge recommended, cert optional)

CompTIA A+ (only if new to IT)

If you've never opened a PC or used the command line, A+ material builds IT bedrock. Self-study the knowledge; the two-exam cert is optional for a security path. ✦✧✧✧✧

cost: ~US$506 (2 exams)

Tier 2 — Hands-on, pick your track (months 6–12)

practicals beat multiple-choice
🔴 offense

eJPT (INE)

Entry pentest cert — fully hands-on lab exam, not multiple choice. Beloved first-offense credential before the OSCP mountain. ✦✦✦✧✧

cost: ~US$249 voucher
🔴 offense ⭐ value

HTB CPTS

HackTheBox Certified Penetration Testing Specialist — brutally practical multi-day exam, insanely good price. Respect among practitioners >> price tag. ✦✦✦✦✧

cost: ~US$210 exam (+ Academy study)
🔵 defense

BTL1 (Security Blue Team)

24-hour practical IR exam using Splunk, Wireshark, Volatility… arguably the best junior blue-team credential available. ✦✦✦✧✧

cost: ~US$550 incl. training
🔵 defense

CompTIA CySA+

Analyst-focused (SIEM, detecting, responding). Recognised in job ads; written + performance questions. ✦✦✦✧✧

cost: ~US$437
either / generalist

CompTIA PenTest+ / CEH

PenTest+: respectable mid cert. CEH: famous (HR loves it) but theory-heavy — practitioners side-eye it; choose CEH only if a specific job demands it. ✦✦✦✧✧

cost: ~US$560–1,200
GRC / IRL

ISO 27001 Foundation / Lead Implementer

Directly relevant for GRC roles worldwide; pairs beautifully with CIS Controls/NIST knowledge. ✦✦✧✧✧

cost: varies (~US$300–1,500)

Tiers 3–4 — Later, when you're working in the field

year 1–5
legendary

OSCP (OffSec)

The 24-hour exam that made hacking certifications famous. "Try Harder." Not an entry cert — do it with 12+ months of solid labbing. ✦✦✦✦✦

cost: ~US$1,649 course+exam
gold standard blue

GIAC (GSEC, GCIH, GCFA…)

SANS courses: deep, respected, expensive (employers often pay). The blue-team gold standard. ✦✦✦✦✧

cost: ~US$1,000+ exam (training ~US$8k)
manager path

CISSP / CISM

Leadership/management pillars. CISSP requires 5 years' experience (you can pass early and become an "Associate"). ✦✦✦✦✧

cost: US$749 / ~$760
ad/offense

CRTP / CRTE / OSEP

Active Directory and advanced red-team specialisations for when AD is your playground. ✦✦✦✦✧

cost: ~US$300–1,500
cloud

AWS/Azure Security Specialty

Cloud-native security certifications — pair with PwnedLabs/CloudGoat practice for the cloud-security lane. ✦✦✦✧✧

cost: ~US$150–300
gov note

Clearances & government paths

Public-sector security work often values clearances and frameworks — e.g. US DoD 8570, UK SC/DV, country-specific assessor schemes. A long-game option after years in-industry.

cost: career-stage dependent
SECTION 13 / THE BATTLE PLAN

The 90-Day Beginner Battle Plan

Twelve structured weeks taking you from zero to "interview-ready fundamentals with receipts". Budget 60–90 min weekdays + one 3–4 hr weekend session. Tick boxes as you go (progress saves in your browser when possible).

WEEK 1Boot & setup week~6 hrs
  • Install VirtualBox/VMware + Kali VM; snapshot it "clean"
  • Create accounts: TryHackMe, OverTheWire, picoCTF, GitHub
  • Secure yourself: Bitwarden + MFA on everything personal
  • Start notes vault (Obsidian) with Networking/Linux/Tools pages
  • Complete: TryHackMe "Tutorial" + first Pre-Security rooms
WEEK 2How computers & networks work~7 hrs
  • Watch: Professor Messer Network+ N10-008/009 (start; ~2 lessons/day)
  • Master: IP addressing, subnetting basics, DNS, DHCP
  • Learn the 26 ports table (Section 03) → self-quiz until 90%+
  • OverTheWire Bandit levels 0–8
  • Write notes: OSI model + TCP handshake in your own words
WEEK 3Linux confidence~7 hrs
  • Bandit levels 9–18 (permissions, files, SSH keys, cron)
  • Practice daily: navigate, grep, find, pipes inside Kali
  • Read: this guide's Section 04 glossary (all terms once)
  • TryHackMe: Linux Fundamentals rooms 1–3
WEEK 4Security fundamentals~7 hrs
  • Finish TryHackMe Pre-Security path 🎉
  • Study: CIA triad, kill chain, MITRE ATT&CK layout (Sections 01/05/06)
  • Bandit levels 19–25
  • Start ISC2 CC free training (aim: exam by week 8)
WEEK 5Core tools week 1~7 hrs
  • Nmap: THM Nmap room + scan your own VMs 10 different ways
  • Wireshark: THM rooms + capture & analyse home lab traffic
  • Finish Bandit (26–34) 🏁
  • picoCTF: first 10 general-skills challenges
WEEK 6Core tools week 2 + web~7 hrs
  • Burp Suite basics: intercept, repeater (THM Burp rooms)
  • Metasploit walkthrough room + exploit Metasploitable2 in lab
  • PortSwigger Academy: complete SQL injection path (all labs)
  • Privilege-escalation primer: LinPEAS/WinPEAS rooms
WEEK 7Defense foundations~7 hrs
  • Deploy Wazuh or Splunk Free in home lab + Sysmon on Windows VM
  • Complete 2 CyberDefenders free labs (pcap/first analysis)
  • TryHackMe: SOC L1 path begun (phishing & network modules)
  • Attack your lab from Kali → find your attack in the SIEM → write it up
WEEK 8First certification 🎓~8 hrs
  • Finish ISC2 CC training → pass the (free) exam 🏆
  • PortSwigger: XSS learning path
  • picoCTF: 20+ total solves across categories
  • Publish 3 GitHub write-ups (Bandit, a THM room, a CDefenders lab)
WEEK 9Choose your lane~7 hrs
  • Decide: 🔴 offense (Jr Pentester path / HTB Academy) vs 🔵 defense (SOC L1 / LetsDefend)
  • Offense picks: HTB Starting Point Tier 0 complete
  • Defense picks: LetsDefend free SOC courses + 2 simulated alerts
  • Begin Security+ study plan (Professor Messer playlist, 1 video/day)
WEEK 10Deep-lane grinding~7 hrs
  • Lane path progress: complete 1 full module/track
  • Security+ domains 1–2 done (General + Threats) with practice quizzes
  • Weekend: join a live or practice CTF on CTFtime (score ≥1 flag)
  • Full-lab exercise: attack→detect→document (your 2nd portfolio piece)
WEEK 11Security+ push + portfolio~8 hrs
  • Security+ domains 3–5 complete; 2 full timed practice exams ≥80%
  • Portfolio polish: 8+ write-ups public; make a clean GitHub README
  • CV draft: skills, certs (ISC2 CC ✓), labs, projects — not just "courses"
  • LinkedIn: headline "Aspiring SOC/Pentester | THM Top X% | ISC2 CC", post weekly progress
WEEK 12Certify & launch 🚀~8 hrs
  • Sit CompTIA Security+ 🏆 (or lock the date within 2 weeks)
  • Book/pick next target: eJPT·CPTS (red) or BTL1·CySA+ (blue)
  • Attend/join: a BSides con, OWASP/ISACA chapter or infosec meetup near you — or a cyber Discord
  • Apply: 10 SOC/junior/support roles or internships (portfolio attached)
  • Reflection post: "90 days from zero" — public progress attracts recruiters
📌

After day 90

Keep the flywheel: 1 machine/week, 1 write-up/week, 1 CTF/month, next certification within 6 months, and community presence weekly. The compounding is absurd — most people quit in week 3, so simply continuing makes you remarkable by month 6.

SECTION 14 / FUEL & COMMUNITY

Resources — Channels, Books, News & Your Community

Handpicked, beginner-proven. You don't need everything — pick 2–3 from each category and go deep. (Links work when you open this file in your browser.)

📺 YouTube — free world-class teachers

10
fundamentals

NetworkChuck

High-energy networking, Linux & hacking-for-beginners series. The channel that makes thousands start. watch

hands-on ctf

John Hammond

Insanely prolific CTF/malware walkthroughs. Watch how a pro thinks, enumerates, gets stuck, un-stucks. watch

htb walkthroughs

IppSec

Legendary HackTheBox box-by-box videos. Watch AFTER attempting — closest thing to a mentor on demand. watch

courses

David Bombal

Massive free full courses (Wireshark, Kali, networking) & career interviews with industry leaders. watch

careers + pentest

TCM Security (The Cyber Mentor)

Heath Adams' practical pentest teaching + "how I got into cyber" content founded an academy — starter videos are gold. watch

deep technical

LiveOverflow

Mind-expanding videos on how exploitation really works. Save for months 2–3, revisit forever. watch

dfir

13Cubed

Memory forensics & incident-response craftsman's channel — the blue-team IppSec. watch

free exam prep

Professor Messer

The free A+/Network+/Security+ training library. Your certification study backbone. watch

web/bug bounty

STÖK & InsiderPhD

Real bug-bounty hunters showing methodology & mindset for web hunting. watch

deep free uni

OpenSecurityTraining2

Actual university-grade free courses (assembly, architecture, forensics) for later depth. visit

📚 Books that aged well (read after week 4)

Linux Basics for Hackers — OccupyTheWeb · gentle on-ramp to Kali skills

Hacking: The Art of Exploitation (2e) — Jon Erickson · how exploitation really works, with code

The Web Application Hacker's Handbook · the deep web bible (with PortSwigger labs as modern companion)

Practical Malware Analysis — Sikorski & Honig · the malware-analysis standard

Blue Team Handbook: Incident Response — Don Murdoch · pocket field manual for analysts

The Practice of Network Security Monitoring — Richard Bejtlich · NSM philosophy done right

Stories: The Cuckoo's Egg · Sandworm · Countdown to Zero Day — motivation & mindset fuel

🎧 Podcasts & news — build the daily habit

Darknet Diaries — gripping true hacking stories; the gateway podcast. Start ep. 1.

Risky Business — weekly global industry news. Listen to every episode → instant fluency.

Smashing Security — funny, educational weekly chat.

News sites: The Hacker News · BleepingComputer · Krebs on Security · The Record.

CISA / national CERT alerts — your national cyber centre's advisories (US: CISA). Bookmark them early.

Rapid7 / CISA feeds — vulnerability disclosure streams you'll learn to skim weekly.

🤝 Community — where careers actually happen

network = net worth

💬 Online

Reddit: r/cybersecurity · r/netsecstudents · r/homelab · r/oscp. Discord: TryHackMe, HackTheBox, John Hammond's, NahamSec (bug bounty). X/Mastodon infosec communities for the latest research.

🌍 anywhere

Local (use this!)

BSides community cons run in hundreds of cities worldwide, OWASP has chapters almost everywhere, plus ISACA/ISSA chapters, university CTF clubs and local/security meetups. One friend in the industry is worth 100 applications.

🌐 Global & big-name

DEF CON & Black Hat (villages + trainings), SANS Summits (many free), BruCON, Hack.lu, FIRST.org member CERTs, and the global communities of ISC2 / ISACA / CompTIA.

⚖️

The Hacker's Code — read this before your first scan

1. Only test systems you own or have explicit written permission to test. "I'm learning" is not a legal defence — in most of the world — unauthorised access or modification of data is a serious crime (US CFAA, UK Computer Misuse Act, and national equivalents). 2. Stay inside documented scope (bug bounties & engagements define it — honour it). 3. Found something by accident on the public internet? Follow responsible disclosure; never extort, never "sample" the data. 4. Protect what you find: client data, credentials, secrets — treat them like biohazards. 5. Uplift others: share knowledge, credit sources, be kind in write-ups. 6. Your reputation is your career: the community is small and memory is long. Wear the white hat proudly — skill with integrity is rare, sought-after, and unstoppable.