Learn
Cybersecurity roadmaps
Each roadmap is an ordered set of stages with the concepts, tools and exercises that belong to them. Progress is stored in your browser; nothing is tracked about you.
Available paths
Beginner through advanced. Estimated durations assume steady part-time study.
- Beginner08 stages
Absolute Beginner
The foundations everything else assumes: how machines address each other, how a shell works, and how to read what a program actually outputs. No prior security knowledge required.
- Audience
- Complete newcomers, students, developers moving into security
- Time
- 4–6 weeks at 4–6 hours per week
- Prerequisites
- 2 listed
- Outcome
- You can set up a lab, navigate Linux comfortably, ex…
- Beginner → Intermediate06 stages
OSINT Investigator
Structured, defensible research using public information: method, source discipline, verification and reporting about people and infrastructure.
- Audience
- Analysts, journalists, defenders, anyone doing public-record research
- Time
- 5–8 weeks
- Prerequisites
- 2 listed
- Outcome
- You can run a repeatable research process, distingui…
- Intermediate → Advanced08 stages
Web Pentester
Application testing from an honest methodology: scope, exploration, verification, impact and retest. Tooling supports the method rather than replacing it.
- Audience
- Developers moving into appsec, junior testers, bug bounty newcomers
- Time
- 10–16 weeks
- Prerequisites
- 3 listed
- Outcome
- You can plan a test, find and verify issues manually…
- Intermediate07 stages
Network Pentester
Internal and external network assessment: discovery, enumeration, exposure review, evidence and the conversations that follow.
- Audience
- Infrastructure testers, sysadmins moving into assessment work
- Time
- 8–12 weeks
- Prerequisites
- 3 listed
- Outcome
- You can map an authorized segment, describe exposure…
- Intermediate06 stages
Bug Bounty
A realistic route into responsible disclosure: program rules, asset knowledge, a repeatable testing loop, and report quality.
- Audience
- Self-directed learners aiming at public disclosure programs
- Time
- Ongoing; 6–12 weeks to a first solid report
- Prerequisites
- 2 listed
- Outcome
- You read a policy before you touch a target, focus o…
- Beginner → Intermediate06 stages
Blue Team Foundations
Detection and response basics: logging you can trust, reading traffic, triaging alerts, and writing the timeline that survives review.
- Audience
- SOC newcomers, sysadmins, developers owning production
- Time
- 8–10 weeks
- Prerequisites
- 1 listed
- Outcome
- You can tell whether an alert corresponds to real ac…