No degree. No gatekeepers. Just a laptop, curiosity and this guide — 90 terms, 151 tools, free labs, a home-lab blueprint, certifications and a 90-day battle plan. Scroll to begin the descent.
Systems, networks, programs, data. Every bank, hospital, mine and startup needs defenders — and there aren't nearly enough of us. Here's the mindset and the one diagram the entire industry is built on: the CIA Triad.
You can't "buy" security. It's a loop: identify → protect → detect → respond → recover → improve. Frameworks like NIST CSF and ISO 27001 formalise it.
Risk = likelihood × impact. No system is 100% secure — the job is reducing risk to an acceptable level without blocking people from working.
Defenders think about what could go wrong; attackers prove what does. Learn both sides and you become genuinely dangerous (in the good way).
Data readable only by authorised people. Tools: encryption, access control, MFA, least privilege.
❌ Broken by: leaks, exposed databases, stolen files.
Data and systems stay accurate and unmodified. Tools: hashing, checksums, digital signatures, file integrity monitoring.
❌ Broken by: tampered transactions, backdoored code.
Systems stay up and data stays accessible. Tools: backups, redundancy, DDoS protection, incident response.
❌ Broken by: ransomware, DDoS floods, destructive wipers.
Global workforce gap: ~4.8 million unfilled roles (ISC2). Mega-breaches — Optus & Medibank (~10M records each, 2022), MOVEit, Change Healthcare — made cyber a front-page priority everywhere, and baseline frameworks (CIS Controls, NIST CSF, your national CERT's guidance) must-know vocabulary. Bonus niche: OT/ICS security (protecting industrial systems) is a genuine career cheat-code in any industrial economy.
Red team thinks like the attacker to find weaknesses first. Blue team detects, responds and hardens. Purple team makes them train together. Beginners should sample both before choosing a lane.
Watch SIEM dashboards, triage alerts, investigate phishing. Most openings, clearest path in.
Vuln scans, hardening, awareness, incident support — the all-rounder bridging to anywhere.
Simulate attacks, deliver reports clients act on. Competitive but deeply learnable via labs.
Risk, compliance (ISO 27001, Essential Eight), audits. Organisation & writing over terminals.
Forensic images, memory analysis, breach investigations. Quiet, deep, highly employable.
Factories, energy, water, transport — scarce people who know both IT security and industry.
Do two months of offense-side rooms (TryHackMe) plus a couple of defense labs (CyberDefenders). Watch your own energy — the side you lose track of time on is your side. You can always cross-train later; the best defenders understand attacks, and vice versa.
Before "hacking tools", every professional builds the same bedrock. Two focused months here will save you a year of confusion later. Keep scrolling — the page moves sideways for you.
What the CPU, RAM, disk and processes actually do. Users, permissions, services, the Windows registry, virtualization. You can't secure what you don't understand — and everything else stacks on this layer.
IP addresses, MAC, subnetting, DNS, DHCP, NAT, TCP vs UDP, ports, the OSI model. Networking is to cyber what anatomy is to medicine — attackers abuse protocols, defenders read them like X-rays.
~70% of servers and nearly all hacking tools run Linux. Files, permissions, pipes, processes, logs, SSH — until the shell feels like home. The terminal stops being scary fast when you learn by playing.
Python first (tools, automation, exploit scripts), plus Bash on Linux and enough PowerShell to recognise attacks on Windows. Early on, reading code matters more than writing it.
Play OverTheWire: Bandit levels 0–25 in your first month — you learn every core Linux command by capturing flags. Then finish to 34 by month two. It's free and genuinely the best Linux primer for future hackers.
| Port | Service | Why it matters to security |
|---|---|---|
| 20/21 | FTP | Cleartext file transfer — ancient, often misconfigured, gold for attackers |
| 22 | SSH | Secure remote admin — brute-forced constantly; use keys + fail2ban |
| 23 | Telnet | Cleartext remote login — if you see this open, it's a finding |
| 25 / 587 | SMTP | Email sending — abused for spoofing/phishing; check SPF/DKIM/DMARC |
| 53 | DNS | The phonebook of the internet — tunneling & exfiltration hide here |
| 67/68 | DHCP | Hands out IP addresses — rogue DHCP = easy MITM |
| 80 / 443 | HTTP / HTTPS | Web traffic. Where most attacks and most of your career will live |
| 110 / 143 | POP3 / IMAP | Email retrieval — legacy cleartext versions still haunt networks |
| 139 / 445 | NetBIOS / SMB | Windows file sharing — WannaCry/NotPetya spread via SMB. Critical. |
| 161/162 | SNMP | Device monitoring — default community string "public" leaks everything |
| 389 / 636 | LDAP / LDAPS | Directory lookups — the map of Active Directory for attackers |
| 88 | Kerberos | AD authentication — Kerberoasting, golden tickets live here |
| 1433 / 3306 / 5432 | MSSQL / MySQL / Postgres | Databases — should never face the internet; SQL injection's target |
| 3389 | RDP | Remote Desktop — #1 ransomware entry point. Always MFA / VPN first |
| 5985/5986 | WinRM | Windows remote management — lateral movement highway |
| 6379 / 27017 | Redis / MongoDB | NoSQL stores — historically wide-open, mass-exploited |
| 5900 | VNC | Remote screen sharing — weak/no passwords in the wild |
| 8080 / 8443 | HTTP-alt proxies | Dev servers, admin panels forget they're exposed here |
90 terms you'll hear on day one of any job, course or CTF — filterable, searchable, and ordered as a learning path. Fluent vocabulary is half of sounding (and being) competent.
A weakness that can be exploited — a bug, misconfiguration or missing control. e.g. unpatched software, default passwords.
Code or technique that takes advantage of a vulnerability to cause unintended behaviour.
Anything that can cause harm: a hacker, malware, a disgruntled employee, even a flood in the server room.
Risk = Likelihood × Impact. The chance a threat exploits a vulnerability, and how bad it would be.
Every point where an attacker could try to enter: open ports, web apps, APIs, employees, suppliers.
The part of an attack that does the damage/action — e.g. the ransomware binary, or a reverse shell.
A vulnerability exploited before the vendor knows or has a patch. The most valuable kind of bug.
Common Vulnerabilities & Exposures — the public ID system for known flaws, e.g. CVE-2021-44228 (Log4Shell).
Severity score (0–10) for CVEs. 9.0+ = "drop everything and patch".
Vendor's fix for a vulnerability. "Patch Tuesday" (Microsoft, monthly) shapes the industry's rhythm.
The "who": script kiddies, cybercriminals, hacktivists, insiders, nation-state groups.
Advanced Persistent Threat — well-resourced groups (often state-backed) that stay hidden for months/years.
Indicator of Compromise — a forensic breadcrumb: malicious IP, file hash, domain, registry key.
Tactics, Techniques & Procedures — how an adversary operates, catalogued in the MITRE ATT&CK framework.
Anything worth protecting: data, servers, laptops, credentials, reputation.
Reducing attack surface: remove unneeded services, apply secure configs (see CIS Benchmarks).
The path/method used to get in: phishing email, exposed RDP, poisoned update, USB drop.
An incident where data/security controls are actually compromised. Reportable under privacy laws (in AU: Notifiable Data Breaches scheme).
Fraudulent messages tricking people into clicking links, opening malware or giving up credentials. #1 initial access method worldwide.
Targeted phishing at a specific person; whaling targets executives.
Any malicious software: viruses, worms, trojans, ransomware, spyware… (full taxonomy in Section 05).
Encrypts victim files and demands payment. Modern crews add "double extortion": leak the data too.
(Distributed) Denial of Service — flood a service until it falls over. Attacks Availability.
Man-in-the-Middle — secretly relaying/altering traffic between two parties (evil Wi-Fi AP, ARP spoofing).
Putting database commands into an app's input fields. Can dump entire databases. Classic, deadly, preventable.
Cross-Site Scripting — injecting JavaScript into pages other users view; steals sessions, defaces, phishes.
Cross-Site Request Forgery — riding a victim's logged-in session to perform unwanted actions.
Trying every password combination. Slow but sure against weak passwords; throttled by lockouts/MFA.
Replaying breached email:password combos on other sites, betting users reuse passwords. They do.
Going from low-privilege user to admin/root (vertical) or another user's account (horizontal).
Hopping between machines inside a network after the first foothold.
Target machine connects back to the attacker, giving remote command control. The classic payload.
The attacker's infrastructure used to control compromised machines and receive stolen data.
Getting stolen data out of the network — over DNS, HTTPS, cloud storage…
Techniques to survive reboots and password resets: services, scheduled tasks, registry run keys, webshells.
Writing past a memory buffer's boundary to hijack execution. The grandfather of exploitation; learn the theory even if modern mitigations exist.
"Hacking humans" — manipulating people instead of systems: pretext calls, tailgating into buildings, urgency scams.
Active Directory attacks reusing stolen password hashes / cracking service-account tickets. Bread and butter of AD pentesting.
Filters traffic by rules (IP/port/protocol). Network (perimeter) and host-based flavours.
Intrusion Detection watches & alerts; Intrusion Prevention sits inline and blocks. Tools: Snort, Suricata, Zeek.
Security Information & Event Management — collects and correlates logs from everything; the SOC's cockpit. Tools: Splunk, Elastic, Wazuh, Sentinel.
Security Operations Center — the team (and room) that monitors and responds 24/7. Where most careers start.
Endpoint (eXtended) Detection & Response — agents on devices that detect and stop malicious behaviour. CrowdStrike, Defender for Endpoint.
Signature/behaviour-based malware blocking. Necessary but alone insufficient.
Multi-Factor Authentication — password + something you have/are. Blocks the vast majority of account takeovers.
Identity & Access Management / Privileged Access Management — who can access what, and controlling admin accounts.
Give every user/process only the access it needs — nothing more. Kills lateral movement.
"Never trust, always verify" — no automatic trust even inside the network; authenticate & authorise everything, continuously.
Splitting networks into zones so a breach in one can't spread — like ship bulkheads.
Buffer network between internet and internal LAN where public-facing servers live.
A decoy system with no legitimate users — anyone touching it is malicious by definition. Great early-warning + research tool. Try: Cowrie, T-Pot.
Isolated environment to safely detonate/observe suspicious files. Tools: Cuckoo, Any.Run, Hybrid Analysis.
Data Loss Prevention — tooling that detects/blocks sensitive data leaving the org.
The structured reaction to a breach. Lifecycle: Prepare → Detect → Contain → Eradicate → Recover → Learn.
Digital Forensics & Incident Response — the discipline of investigating what happened from artifacts (disk, memory, logs).
Proactively searching for attackers who evaded alerts, using hypotheses + data. "Assume breach."
Tracking, testing and deploying updates. Unglamorous, massively effective.
The globally-used prioritized set of 18 defensive actions. Also know your national CERT's baseline — interview gold anywhere.
Step-by-step response guides ("phishing email playbook") so juniors respond like veterans at 3am.
Open-Source Intelligence — collecting info from public sources. Used by attackers to target you and defenders to investigate.
Logical network address (IPv4 203.0.113.5 / IPv6). Public vs private ranges (10.x, 172.16–31.x, 192.168.x).
Hardware address of a network card, used on the local link (Layer 2). Spoofable.
Domain Name System — translates names (google.com) to IPs. DNS poisoning/tunneling are attack staples.
TCP = reliable, connection-oriented (3-way handshake SYN/ACK). UDP = fast, connectionless (DNS, streaming, games).
A numbered door (0–65535) identifying a service on a host. Well-known: 0–1023. See the table in Section 03.
Automatically assigns IP addresses when you join a network.
Network Address Translation — many private devices sharing one public IP. Your home router does this.
Dividing networks: 192.168.1.0/24 = 256 addresses (/24 = first 24 bits fixed).
Encrypted tunnel over untrusted networks — for remote workers and privacy.
Intermediary for requests; forward proxy hides clients, reverse proxy fronts servers (also a security control point).
Maps IP→MAC on a LAN. ARP spoofing = classic local MITM technique.
Encryption for traffic in transit — the padlock in HTTPS. SSL is dead; TLS 1.2/1.3 is correct.
Reversible scrambling with a key. Symmetric (one shared key — AES) vs Asymmetric (public/private key pair — RSA, ECC).
One-way fingerprint (SHA-256, bcrypt). Used for integrity checks and password storage. Not encryption — can't be "decrypted".
Random data added before hashing passwords so identical passwords get different hashes — defeats rainbow tables.
Asymmetric crypto proving a message/software came from you and wasn't altered (authenticity + integrity).
Public Key Infrastructure — the certificate authority system that makes HTTPS trust possible.
Precomputed hash→password lookup tables. Why unsalted fast hashes (MD5!) are terrible for passwords.
Hiding data inside other data (messages in image pixels). Favourite of CTF forensics challenges — tools: steghide, zsteg.
The "you are logged in" artifact (cookie/JWT). Stealing one = session hijacking. Guard with HttpOnly + short expiry + MFA.
Authorized, scoped, time-boxed simulated attack delivering a fix-it report. "Pentest". Requires written permission — always.
Automated scanning for known weaknesses (Nessus/OpenVAS). Breadth-first cousin of pentesting.
Offense / defense / collaboration exercises. (Section 02 covers the roles.)
Companies pay researchers for valid vulnerability reports via HackerOne/Bugcrowd. Legal hacking for money — but only in defined scope.
Capture The Flag — gamified security challenges where you find "flag{...}" strings. The sport of the industry (Section 11).
Lawful-ethical hackers / criminal hackers / somewhere in between. Aim to be unambiguously white hat.
Reporting a found vulnerability privately to the vendor so they can fix it before going public (typically ~90 days).
The legal contract defining what a pentester may and may not touch. Breaking scope = breaking the law.
The global knowledge base of adversary TTPs (Recon, Initial Access, Execution… Exfiltration). Learn to read it — the industry's shared map.
The secret string proving you solved a challenge: flag{y0u_f0und_m3}. Addictive — you've been warned.
Lockheed Martin's Cyber Kill Chain breaks any intrusion into stages. The defender's advantage: attackers must win every stage — you only need to break one link. Scroll through the chain; the left panel tracks where you are.
Researching the target: employees on LinkedIn, exposed services on Shodan, DNS records, job ads that leak the tech stack.
defender's creed: break one link → the whole chain fails.
Attackers profile you quietly from public sources: emails, subdomains, tech stack, staff names for phishing.
🛡 DETECT — monitor web logs, threat intel, limit what's publicThe exploit + payload are assembled into a deliverable package. Happens entirely on the attacker's side — nearly invisible.
🛡 DISRUPT — hard to observe directly; invest in the other 6 stagesTransmission: spear-phish, infected USB, compromised site. This is where email gateways earn their keep.
🛡 DENY — email filtering, attachment sandboxing, user trainingThe vulnerability triggers and malicious code executes. Unpatched software is what makes this easy.
🛡 DENY — patch management, EDR, exploit prevention, hardeningPersistence is planted: implants, autostarts, webshells — so the attacker survives reboots and password changes.
🛡 DETECT — EDR, file integrity monitoring, autoruns auditingThe implant beacons to attacker servers for instructions. Outbound traffic is now the tell — most orgs watch inbound only.
🛡 DENY — egress filtering, DNS sinkholes, beacon detection, proxy logsThe mission: exfiltration, ransomware, espionage, destruction. Fast incident response here decides whether it's a bad day or a headline.
🛡 DEGRADE — DLP, segmentation, tested backups, rapid IRAttaches to a host file, needs user action to spread. The original malware.
Replicates across networks by itself — WannaCry hit 200k+ machines in days (2017).
Legit-looking software ("free photoshop!") with a hidden payload. No self-replication.
Encrypts files, demands payment — modern gangs leak data too ("double extortion").
Silent monitoring: keystrokes, screens, messages, location.
Buries into the OS kernel/drivers to hide and persist. Brutal to detect.
Records every keystroke — passwords, messages, everything.
Thousands of zombied devices under one C2 — DDoS, spam, mining (Mirai).
Remote Access Trojan: full control — files, webcam, mic. Delivered by phishing.
Sleeps until triggered — a date, a deletion. The insider-threat classic.
Pure annihilation — NotPetya cost $10B (2017); used in modern conflicts.
Silently mines crypto on your CPU/cloud bill. Symptom: screaming fans.
Lives in memory & legit tools (PowerShell, WMI). Nothing on disk for AV.
Stage-1 malware whose only job is installing the real payload.
Forced ads & tracking, bundled with "free" software. A privacy problem.
"YOUR PC IS INFECTED — PAY $99!" Fear as the exploit.
Mass fake emails/sites stealing creds. Defend: verify sender, hover links, MFA.
Targeted phishing at you / your CEO. Defend: out-of-band verification.
SMS & voice scams ("AusPost fee", "IT here, read me your code"). Defend: call back on official numbers only.
Invented scenarios to extract info. Defend: verify identity through known channels.
Curiosity traps: "free music", the USB labelled "SALARIES" in the car park. Defend: never plug in found media.
Following staff through secure doors. Defend: badge everyone, politely challenge.
AI-cloned voices approving transfers. Defend: call-back rules for money/secrets.
Spamming push prompts until you tap Approve. Defend: number-matching MFA, deny unexpected prompts.
Memorise this roster: Broken Access Control / IDOR (change /invoice?id=1042→1043), Injection (SQLi, command), Crypto failures, Insecure design, Security misconfiguration, Vulnerable components (Log4Shell!), Auth failures, Data integrity failures, Logging gaps, SSRF (make the server fetch internal URLs — steal cloud keys). Practice every one legally on PortSwigger Web Security Academy — free and world-class.
No single control survives a determined attacker. Professionals stack them — when one layer fails (one always eventually does), the next is already watching.
Every device ships logs to a SIEM. Detection rules (Sigma, KQL) match patterns — "impossible travel login", "known C2 domain" — and an alert fires. Analyst triage mantra: what happened → is it real → how bad → contain → escalate.
Traffic cop: deny-all default, allow only what's needed.
Sniffs for attack patterns; IPS blocks inline.
Central log brain: correlate, alert, dashboard.
Behaviour agents on every host; one-click isolate.
Identity is the new perimeter: SSO, MFA, vaulted admin.
Automated response: isolate, block, reset — in seconds.
MITRE ATT&CK — the shared map of adversary techniques · NIST CSF — identify/protect/detect/respond/recover/govern · CIS Critical Security Controls — the globally-prioritized baseline (know your national CERT's guidance too) · ISO 27001 — the international security-management standard · CIS Benchmarks — concrete hardening configs. Drop these names correctly and you instantly sound like a peer, not a tourist.
The working professional's toolbox organised by job function — every entry has the one-liner purpose and an example. ⭐ marks the beginner picks. Filter by discipline or search anything. Almost everything here is free and open source.
One download = hundreds of preinstalled tools. Install in a VM (Section 09), never as your daily driver OS holding personal files.
Start here. Prebuilt with Nmap, Metasploit, Burp, Wireshark & 600 more. Free from kali.org — run it as a VM.
Beautiful, lighter on RAM (good for older laptops), includes anon tools like Tor/AnonSurf.
Enormous arsenal on Arch Linux. Fantastic once you're comfortable with Linux — not day-one material.
Turns a Windows VM into an attack box — perfect for Active Directory practice on the platform attackers actually target.
Preloaded with malware-dissection tools (Ghidra, PE tools, fake network services). Pair with Flare VM.
Mandiant's Windows box of debuggers/decompilers for safe malware study in an isolated VM.
DFIR toolkit matching SANS courses: timeline analysis, memory forensics, registry tools.
Bundles Suricata, Zeek, Elastic, Kibana, CyberChef. Build this in your home lab = real blue-team experience on your resume.
"Amateurs hack systems; professionals hack information first." Enumeration is 80% of every engagement and CTF.
The network scanner: discover hosts, open ports, service versions, OS, run scripted checks (-sC). Learn it until flags are muscle memory.
Point-and-click Nmap with topology maps. Great while you memorise CLI flags.
Blazing-fast port scanner that pipes results into Nmap. CTF favourite: full port sweep in seconds.
Scans absurdly fast (the whole internet in minutes). Careless use = knocking on every door in town.
Read/write raw network connections: banner grab, chat, transfer files, catch reverse shells. Tiny tool, infinite uses.
Simple friendly GUI ping/port sweeper — handy for surveying your home lab.
The search engine of internet-connected devices: open cams, exposed databases, ICS gear. Recon without sending a single packet.
Shodan's scholarly sibling: internet-scan data + TLS certificate history to map any org's footprint.
Harvests emails, subdomains, employee names from public sources — builds a phishing-target list (defenders: audit yourself!).
OWASP's deep subdomain enumerator — discovers an org's forgotten dev/staging servers where bugs breed.
Fast passive subdomain discovery. Pipe into httpx → live web targets in two commands.
Modular web-recon framework with marketplace modules — automates the "who are they?" phase.
Rips users, shares, and policy info out of Windows/Samba hosts. First stop on any box with SMB open.
Reading packets is a superpower for both teams: attackers sniff secrets; defenders see evil hiding in plain sight.
The world's most-used protocol analyser. Capture traffic, follow TCP streams, carve files. Do the Wireshark TryHackMe room early.
Terminal packet capture for servers and CTF boxes. The flags look scary; learn five and you're set.
Scriptable Wireshark — extract fields from huge pcaps, perfect for CTF automation.
Turns raw traffic into structured logs (conn.log, dns.log, http.log). Core of network security monitoring & Security Onion.
Passive sniffer that rebuilds files, images, credentials from pcaps. Blue-team CTF darling.
Beautiful desktop app for hunting through pcaps with Zed queries. Great intro to network forensics.
Classic ARP-poisoning/MITM suite for your lab only. Seeing cleartext creds fly by teaches why TLS matters.
Modern MITM framework: ARP/DNS spoofing, wifi attacks, credential capture. The attacker's Wireshark.
Web is the most beginner-friendly (and most employed) attack surface. Master these and PortSwigger Academy and you can do real bug bounties.
The web-tester's weapon #1: intercept, replay (Repeater), fuzz (Intruder), scan (Pro). Community Edition is free — learn it deeply.
100% free/open from OWASP. Great for automated scans and CI pipelines. Teams often run both ZAP and Burp.
Already installed! Inspect requests, cookies, localStorage, JavaScript. Solve XSS labs with nothing else.
Brute-forces hidden directories/files (/admin, /backup.zip), virtual hosts and subdomains.
"Fuzz Faster U Fool": fuzz parameters, dirs, vhosts at high speed with fine filters. CTF essential.
Veteran web server scanner: outdated software, dangerous files, misconfigs. Noisy — which is a lesson itself.
Detects & exploits SQL injection automatically — even dumps databases. Learn manual SQLi first, then let sqlmap flex.
WordPress = 40%+ of the web. WPScan finds vulnerable plugins/themes and enumerates users.
Community template–driven scanner: thousands of one-click CVE/misconfig checks. Bug-bounty hunters live in it.
Identifies CMS, frameworks, server tech on any site — shapes your attack plan instantly.
Probes huge host lists: which are live, what tech, what status. Glue tool of recon pipelines.
APIs leak data constantly (see OWASP API Top 10). Postman is how you poke them methodically.
Fast, pretty newcomer for HTTP interception — nice alternative when Burp CE rate-limits Intruder.
Where vulnerabilities become shells. Practice these ONLY in your lab and on legal platforms — see the ethics banner, always.
The legendary exploit framework: 2,000+ modules, payloads and post-ex modules. The free "Metasploit Unleashed" course is a rite of passage.
Metasploit's payload factory: generate shells for any platform/format. Learn payloads by building them.
Metasploit's in-memory super-shell: file system control, keylogging, pivoting, privilege escalation — all living in RAM.
Offline copy of the Exploit Database. Found a service version? Searchsploit finds the public exploit. CTF daily driver.
Browser Exploitation Framework — demonstrates why XSS is terrifying: control the victim's browser in real time.
TrustedSec's framework for authorized social-engineering simulations. Why "think before you click" training exists.
Python classes for attacking Windows protocols — the toolbox behind most AD exploitation and Kerberos attacks.
CrackMapExec's successor: validate creds, spray, dump, execute across whole subnets. AD pentest essential.
Poisons LLMNR/NBT-NS on Windows networks and catches password hashes from thin air. Lab-only; shows why those protocols die in secure orgs.
The comfortable way to land on Windows via WinRM with creds or a hash. HTB players' best friend.
Relay traffic through compromised hosts to reach hidden networks — pivoting made simple.
Humans pick terrible passwords; these tools prove it — in your lab, for system owners, or on leaked-hash CTF challenges.
The fastest hash cracker on earth, powered by your GPU. Combine wordlists + rules to crack NTLM/SHA/etc. Benchmark it once — it's fun.
The classic cracker, superb on Linux/Unix hashes (/etc/shadow). Pairs with ssh2john/zip2john to crack archives & keys.
Parallel online login attacks against SSH/FTP/web forms/RDP. Use in labs; in the real world it locks accounts and trips alarms.
Hydra's stable, speedy cousin. Know both; they complement oddly-specific services.
Ships with Kali (gzip'd at /usr/share/wordlists). The definitive wordlist — together with SecLists it forms 90% of password challenges.
Daniel Miessler's curated collection for every wordlist need — especially web dirs and parameter names.
Spiders a website to build a company-flavoured wordlist ("AcmeCorp2026!"). Passwords come from culture — exploit it (with permission).
Online rainbow-table lookup for quick checks; Name-That-Hash identifies unknown hash formats instantly.
Getting in is half the story. These find the misconfigurations that turn "limited shell" into "Domain Admin".
PEASS-ng scripts auto-enumerate Linux/Windows privilege-escalation vectors in screaming colour. Run them on every CTF box.
Bible of Unix binaries that can be abused (sudo, SUID, capabilities) to escalate. Bookmark it forever.
Windows equivalent: legit Microsoft binaries attackers abuse (certutil download, mshta execution). Defenders monitor for these too.
Extracts plaintext creds, hashes and tickets from Windows memory. The tool that made "credential hygiene" a boardroom topic.
Maps Active Directory attack paths as a graph — reveals "Helpdesk→3 hops→Domain Admin" chains instantly. Red and blue both swear by it.
PowerSploit's Windows enumeration checks: unquoted service paths, weak service ACLs, AlwaysInstallElevated…
C# host enum swiss-army: who am I, what's here, what's defensible. Part of the standard C2 toolkit experience.
The go-to for Kerberos attacks: kerberoasting, AS-REP roasting, ticket manipulation.
Watches every process spawning (even other users') without privileges — exposes cron scripts and mistyped passwords.
Compares kernel/distro versions against known local-exploit lists (DirtyCow era classic). LES + LinPEAS = the standard workflow.
You'll need a USB Wi-Fi adapter that supports monitor mode (Alfa AWUS036-series are the community favourites).
The complete Wi-Fi audit suite: monitor, capture handshakes, deauth, crack WPA keys. The official tutorial is a legendary first lab.
Automates Aircrack attacks end-to-end: WEP/WPA/WPS. Great for understanding the attack chain hands-on.
Passive wireless sniffer/IDS — maps networks, detects rogue access points. The defender's wireless eyes.
Modern clientless WPA attacks — grab a crackable hash without any client connected. Then feed hashcat.
Attacks WPS PIN weakness on older routers. Mostly dead on modern gear — but knowing why = interview points.
Create lookalike networks and harvest hand-ins from unsuspecting devices — the evil-twin demo every awareness training uses.
The science of answering "what happened?" from artifacts. Quietly one of the most employable and satisfying specialties.
Free, friendly forensic platform for disk images. Recover deleted files, browser history, USB artifacts. The CyberDefenders labs pair perfectly.
Analyse RAM captures: running processes, injected code, connections, credentials in memory. Memory never lies.
Industry-standard imaging tool (free!). First rule of forensics: work on images, never originals.
Eric Zimmerman's Kroll Artifact Parser & Extractor — grabs registry hives, event logs, browser data fast for offline analysis.
The definitive Windows artifact parsers. Real IR shops run on these. Free with training videos.
Case captures constantly hide exfil in DNS/HTTP — carve it out and prove it.
Reads/writes metadata in hundreds of formats. CTF stego staple; real-world leak detector (phones embed GPS!).
Finds & extracts files hidden inside other files/firmware. First command in CTF forensics.
Recover lost partitions and deleted files by signature — also handy when ransomware nukes a test VM.
Builds a unified timeline from disks, logs, browsers. Timelines answer "when, then what?" — the heart of IR storytelling.
Open-source DFIR platform: hunt VQL queries across thousands of endpoints in seconds. Enterpise-grade and free.
The friendly front-ends that make Windows forensics approachable while you learn the artifacts.
Open malicious files safely in REMnux/FLARE VMs with the network shut off — see the lab safety rules before you ever detonate anything.
NSA's released RE suite — professional-grade and free. Disassemble, decompile, patch. Start with crackmes.
The famous Interactive Disassembler. Most tutorials/books use IDA — worth learning the UI early.
Open-source Windows debugger for dynamic analysis and crackmes. Friendlier than WinDbg for beginners.
Free RE framework beloved by CTF players for binaries on any architecture.
Instant suspicious-file triage: what it imports, what it pretends to be, MITRE mappings.
Interactive online sandbox: click like a user, watch processes/network in real time. Free tier + great public reports to learn from.
Free CrowdStrike sandbox — excellent static+dynamic reports when studying samples safely from your browser.
Lookup hashes/URLs across dozens of AV engines + sandbox telemetry. Daily reference for analysts. (Don't upload real secret files!)
Write pattern rules to classify/hunt malware. Every SOC, sandbox and CTF uses YARA — learn the syntax day one.
Windows dynamic-analysis eyes: see exactly what a program does. Sysinternals Suite is mandatory Windows study anyway.
Simulate DNS/HTTP services in an isolated VM so malware reveals its C2 behaviour safely.
Identifies packers (UPX!), compilers, protections — step 1 before unpacking.
Install these in your home lab and you can honestly list SIEM/EDR/IDS experience on your resume.
The enterprise SIEM leader — free 500MB/day tier is plenty for a lab. Splunk skills = directly employable; free Fundamentals course + Boss of the SOC dataset.
Free open-source SIEM/XDR: file integrity, vulnerability detection, MITRE-mapped alerts. The best first blue-lab install.
Elasticsearch + Kibana + Beats/Agents power countless SOCs. Learn KQL-style querying once, use it everywhere.
Fast IDS/IPS using ET Open rules. Feed it homelab traffic, watch it bark at your own Nmap scans.
The original open-source IDS (1998!) — still everywhere, still taught in certs. Learn rule syntax once: alert tcp any any → any 445.
Security Onion ships Zeek+Suricata+Elastic pre-integrated: a real SOC console in one VM (see Section 09).
FreeBSD firewall/router distro — learn NAT, rules, VLANs, VPNs by actually building them. Core of serious home labs.
Turns Windows Event Logs from "meh" into a goldmine: process creation, network connections, loading of suspicious DLLs. Pair with Wazuh/Splunk.
The open standard for detections ("detect mimikatz-like process names"). Write one rule, run it in Splunk/Elastic anywhere.
FREE friendly log platform with streams, pipelines, alerts — a gentler first SIEM than the giants.
Tiny daemon that bans brute-forcers by tailing logs. Install on any internet-facing Linux box — and on day one of any VPS.
Drag-and-drop playbooks: alert → enrich (VT, AbuseIPDB) → block. Learn SOAR concepts free.
Automated adversary emulation platform. Purple-team your lab: fire techniques, confirm your SIEM catches them.
Find out what the internet already knows. Used by pentesters for recon, SOCs for investigations — and by you to check your own footprint.
Visual intelligence graphs connecting people, domains, IPs, breaches. Free Community edition in Kali.
Advanced search operators expose forgotten files, admin panels, cameras. Free, powerful, underrated — master the syntax.
Interactive tree of hundreds of OSINT resources by category (usernames, emails, images, leaks…).
(See Recon section.) OSINT and recon are cousins — these tools sit at the border.
Finds where a username exists across hundreds of platforms. Prolific for investigations (and self-auditing).
Automates massive OSINT sweeps: DNS, breaches, emails, darknet mentions. Great for footprinting an org.
Troy Hunt's legendary service. Check your own accounts, enable the free notify-list. A household name in security.
Historical snapshots of any site: find removed admin pages, old emails, "deleted" evidence.
Trace images across the web: sock accounts fall apart fast with these.
Custom search consoles for social, breaches, maps & more from the author of "OSINT Techniques".
Investigate phone numbers: Truecaller hits, disposable-number flags. Great for vishing investigations.
Profiles a company's web tech → targets for both attacks and job interviews ("I see you use Splunk…").
Crowdsourced IP abuse reports — the SOC's reflex check on every alert IP.
Find weaknesses before attackers do, and prove it with reports. An everyday corporate task — great to have on your resume.
Open-source enterprise-grade vulnerability scanner. Runs in your lab VM and produces pro-looking reports.
Tenable's famous scanner, free for home labs. Learn the interface — you'll meet it at work, guaranteed.
Belongs here too — continuous, scriptable vuln checks with community templates.
Audits a Linux host against best practices and tells you exactly what to fix. Run it on your own VPS for instant wins.
Automated compliance scoring against the famous CIS hardening benchmarks — GRC meets engineering.
The small tools you'll use daily, whichever team you join.
GCHQ's "Cyber Swiss Army Knife": 300+ operations — encoding, crypto, compression, extraction. CTF oxygen.
Caesar to Vigenère to mystery hashes — classic-crypto challenges solved in seconds.
The pentester's encyclopedia: every service, misconfig and technique with commands. The community's brain, free.
GitHub repo of curated payloads/methodologies (SQLi, XSS, SSRF…). CTF clipboard.
Every language's reverse/bind shell, plus URL/Base64 encoding. Saves real time in labs.
Interactive cheat-sheet for Windows/AD: filters by what you have (creds? shell?) and shows commands.
Split screens for scan + listener + notes, and never lose a session. A pro's terminal looks like tmux.
Document every machine, command and lesson. Your notes become your portfolio and future self's gift.
One-stop online steganography triage for CTFs.
Classic hidden-data tools (zsteg shines on PNG/BMP LSB data).
Spin up vulnerable apps (Juice Shop!), tools and malware sandboxes without polluting your VM. Learn basic Docker — it's how labs are shipped now.
Free hypervisors hosting your Kali + targets + SIEM. Section 09 builds on them. (VirtualBox is free; VMware Workstation Pro is now free for personal use.)
Credibility rule #1: secure yourself. Set this up in week one; it also doubles as your first mini-project.
Open source, free, everywhere. Non-negotiable modern hygiene — password reuse is how people get owned.
Fully offline alternative beloved by the paranoid (healthy paranoia). Kali users' default.
App-based MFA with encrypted backup. Turn MFA on for email first, then everything else.
Free TrueCrypt successor — encrypt research, notes and VM drives on shared machines.
Reputable no-log VPNs for untrusted Wi-Fi. (A VPN is privacy hygiene, not magic invisibility.)
Malvertising is a real attack vector. Harden your daily browser, too — you are a target now.
End-to-end encrypted messaging with sealed-sender design. Community standard.
Run offensive tools only inside your isolated lab VMs or on platforms that explicitly permit it (TryHackMe, HTB, CTFs, in-scope bug bounties). Scanning or attacking systems you don't own or lack written permission for is a crime nearly everywhere on earth (US CFAA, UK Computer Misuse Act, national equivalents). Skill + ethics = employable. Skill without ethics = criminal record.
Each phase builds on the last and ends with something you can show. Pace: 60–90 focused minutes daily plus one longer weekend session.
Install VirtualBox/VMware + a Kali VM. Create TryHackMe, picoCTF, OverTheWire accounts. Secure yourself first: Bitwarden + MFA. Start an Obsidian notes vault — pros document everything.
Professor Messer's free Network+ playlist. Grind OverTheWire Bandit to ~25 and TryHackMe's Pre-Security path. Automate one boring thing in Python.
THM SOC L1 or Jr Pentester path (per your lane). Learn Nmap, Wireshark, Burp. Start picoCTF. Memorise Section 04 until fluent.
Build the full lab (next section). Study with Messer + practice exams: pass ISC2 CC (free), then book Security+. Add HTB Starting Point or PortSwigger tracks.
Weekly CTFs, one write-up a week, polish LinkedIn with projects, hit BSides cons, OWASP/ISACA chapters and meetups near you. Apply broadly: SOC L1, support-with-security, internships, grad programs.
Daily small sessions beat weekend binges. Time-box struggle at ~30 minutes, then read a hint. Take notes on everything — future-you is forgetful, and your notes become your blog becomes your portfolio becomes your job.
Most beginners quit around week 3. Simply continuing to month 6 already puts you ahead of most applicants. 1 machine/week, 1 write-up/week, 1 CTF/month — that's the whole secret.
A private attack-vs-defense playground on one computer: hack your own VMs from Kali, then watch your own SIEM catch you doing it. Red and blue skills from a single laptop — and the best portfolio material there is.
① Lab VMs on host-only/internal networks — never bridged, especially with malware. ② Temporary NAT for updates only, then disconnect. ③ No real personal files or passwords in lab VMs. ④ Malware detonates only in isolated VMs with snapshots, never internet-connected. ⑤ Snapshot before everything; nuke-and-restore when in doubt. ⑥ Attack only lab IPs — never school, work, or the neighbours.
Exploit Metasploitable2 from Kali → review what Wazuh/Splunk captured → write-up: steps, IOCs, detection rule.
Lab phishing sim → lands on Windows VM with Sysmon → trace the chain in Splunk → write a Sigma rule that catches it.
Server as DC + Win10 client; users, GPOs → BloodHound attack paths with NetExec → map every step to MITRE ATT&CK.
Isolated REMnux/FLARE pair + known sample: PEStudio, Procmon, FakeNet → write your first YARA rule.
Full OWASP sweep of Juice Shop via Burp → professional report: findings, evidence, risk ratings, fixes.
VLANs for users/servers/guest + rules between them → prove with scans that lateral movement is now dead.
Ordered day-one-friendly → hard mode. Nearly all have generous free tiers, and all of them exist for you to break things on purpose.
Guided browser "rooms" with built-in VMs. Paths: Pre-Security → Intro → SOC L1 / Jr Pentester. Smoothest on-ramp in existence; free tier is genuinely usable.
SSH wargame: 34 Linux-teaching puzzles. Free, legendary, occasionally evil.
CMU's free beginner CTF + year-round practice gym. Gentle enough for week one.
From Burp's creators — the best free web-security course on earth: theory + labs for every vuln class.
Entry certification with free training + exam (One Million pledge — verify current status). Resume-ready in weeks.
Free A+/Net+/Sec+ videos; Cisco's intro course + Packet Tracer; HackerOne's free classes + CTF.
Famous pentest platform; guided starter machines, structured Academy modules, IppSec walkthroughs for retired boxes.
Hundreds of free vulnerable VMs for your lab. No subscription, works offline, write-ups abound.
Crafted web/system exploitation exercises; and ASU's free deep curriculum (Linux → exploitation → reversing).
SOC simulator: real alert queue, phishing triage, SIEM investigations. Closest thing to a SOC job at home; free tier.
Free blue-team CTF labs (pcaps, disk images, memory dumps); Blue Team Labs Online for deeper scenarios.
Learn cryptography by breaking it — XOR to attacking real constructions. Free, brilliant.
Free MITRE ATT&CK, detection-engineering and adversary-emulation courses. Resume candy.
Boss of the SOC: free real-world dataset for Splunk practice. Recruiters know the name.
Long-running free challenge archives for steady daily reps across every category.
Unwalkthroughed boxes, AD ranges (Dante, Offshore), ranked leaderboard. Where OSCP-level skill is forged.
6-week course + 24-hr practical IR exam. The premier junior blue-team credential.
Cloud-security hands-on: AWS misconfig hunting and vulnerable-by-design environments. Cloud skills = job multiplier.
Entire multi-VM Active Directory forests with deliberate weaknesses + full logging. The home-lab endgame.
OWASP's vulnerable Android apps; and free ICS/SCADA learning resources from CISA for the industrial-security niche.
The global CTF calendar & ratings. Join weekend events; read winning write-ups after — that's where growth compounds.
Every finished room/box/lab → a short GitHub write-up. Within months you own proof: "40+ documented machines breached/investigated." A public portfolio outperforms a degree with recruiters, every time.
Competitive events where solving security challenges reveals secret strings — flags — worth points. It's training, community and hiring signal in one package.
SQLi, XSS, IDOR, source leaks. First solve: view-source + /robots.txt.
Break weak ciphers. First solve: CyberChef base64/ROT13, Caesar freq-analysis.
Find what the internet already knows. First solve: reverse image search, Wayback Machine.
Images, pcaps, memory dumps. First solve: strings, EXIF, binwalk.
Data hidden in images/audio. First solve: steghide, zsteg, colour channels.
Analyze binaries for the flag check. First solve: strings → Ghidra main().
Buffer overflows, mitigations, shells. Hardest category — pwn.college eases you in.
Everything else: pyjails, esolangs, weird protocols. Great teachers here.
CTFtime.org — the global calendar. Regulars: picoCTF (beginner heaven, Mar–Apr), HTB Uni CTF, Google CTF, DEF CON qualifiers, and DownUnderCTF — famously beginner-friendly, one of the biggest worldwide. Team up: three beginners cover 3× the categories.
Timebox: 30 min stuck → read a hint. Notes as you go = instant write-up. After events, read others' solutions — the compounding lives there. Never share flags mid-event. Jeopardy boards are 90% of events: solve in any order, harvest the easy points first.
Certs get you past HR filters and structure your study. Strategy: free starter → Security+ (the golden key) → one hands-on track cert. Prices approximate USD — always check current rates.
Certified in Cybersecurity — free training + exam via the One Million pledge. The fastest real cert on a resume. ✦✧✧✧✧
Cisco's free intro cert; Microsoft's identity/security fundamentals (~US$99, watch for free vouchers); Splunk's free SIEM course. ✦✧✧✧✧
Coursera job-switcher program: SIEM, Linux, Python, IR. Frequently recognised by HR. ✦✦✧✧✧
The default first security cert, named in a huge share of junior ads + DoD 8570-compliant. Free study via Professor Messer; 6–10 weeks. ✦✦✦✧✧
Knowledge recommended, exams optional if you're fluent from Phase 1; A+ only if brand-new to IT. ✦✦✧✧✧
BTL1: 24-hr hands-on IR exam (~US$550 w/ training) — blue-team favourite. CySA+: SIEM/detection analyst cert (~US$437). ✦✦✦✧✧
Fully hands-on pentest practicals — CPTS (~US$210) is the best value in infosec; eJPT (~US$249) the gentle first practical. ✦✦✦✧✧
HR-recognised middles. CEH is theory-heavy — take it only when a listing demands it. ✦✦✦✧✧
Directly relevant for compliance roles worldwide; pairs beautifully with CIS Controls fluency. ✦✦✧✧✧
The legendary 24-hr OSCP (~US$1,649), SANS/GIAC gold standards (employer often pays), AD specialisations. Year 1–5 goals. ✦✦✦✦✦
Management pillars (CISSP needs 5 yrs experience; pass early, be an "Associate"). Plus cloud security specialties & government clearance paths as long games. ✦✦✦✦✧
Certs open the door; portfolio + home lab + community win the interview. One practical cert > three multiple-choice ones for technical roles.
60–90 min weekdays + one deep weekend session. Click a week to expand; tick items off — progress saves in your browser. Extend timelines to your life: consistent > fast.
Keep the flywheel spinning: 1 machine/week · 1 write-up/week · 1 CTF/month · next cert within 6 months · community weekly. Most people quit in week 3 — continuing alone makes you remarkable by month 6.
Handpicked, beginner-proven resources. Pick two or three per category and go deep — links open when you view this file in a browser.
NetworkChuck (energy + fundamentals) · John Hammond (CTF/malware) · IppSec (HTB walkthroughs) · David Bombal (full courses) · TCM Security (pentest + careers) · LiveOverflow (deep theory) · 13Cubed (DFIR) · Professor Messer (cert prep) · STÖK (bug bounty) · OpenSecurityTraining2 (free uni-grade)
Linux Basics for Hackers (gentle start) · Hacking: The Art of Exploitation (how it really works) · Web App Hacker's Handbook · Practical Malware Analysis · Blue Team Handbook · The Practice of NSM · stories: The Cuckoo's Egg, Sandworm, Countdown to Zero Day
Darknet Diaries (start here) · Risky Business · Smashing Security · news: The Hacker News, BleepingComputer, Krebs, The Record · CISA alerts
Reddit: r/cybersecurity · r/netsecstudents · r/homelab · r/oscp — Discords: TryHackMe, HackTheBox, John Hammond, NahamSec — CTFtime teams
BSides cons run in hundreds of cities · OWASP chapters are nearly everywhere · ISACA/ISSA chapters · university CTF clubs · local infosec meetups & Discords. One industry friend > 100 cold applications.
DEF CON & Black Hat villages · free SANS Summits · BruCON / Hack.lu · FIRST.org CERTs · ISC2 / ISACA / CompTIA global communities
1. Only test what you own or have explicit written permission to test (AU: Criminal Code Act 1995, Part 10.7 — "learning" is no defence). 2. Stay inside documented scope. 3. Found something on the open internet? Responsible disclosure — never extort, never sample the data. 4. Treat client data and secrets like biohazards. 5. Uplift others: share knowledge, credit sources, be kind. 6. Your reputation is the career — the community is small and memory is long. Wear the white hat proudly. 🛡️