Roadmap
Absolute Beginner
The foundations everything else assumes: how machines address each other, how a shell works, and how to read what a program actually outputs. No prior security knowledge required.
Prerequisites
- Basic computer literacy
- Willingness to read command output
Who it is for
Complete newcomers, students, developers moving into security
Outcome: You can set up a lab, navigate Linux comfortably, explain what happens between a URL and a response, and read tool output without guessing.
Stages
Work them in order the first time. Ticking a stage only records your own progress, in this browser.
Stored in this browser only. No account, no sync.
Build a safe lab
A virtual machine you own, isolated from other networks, plus snapshots so mistakes are reversible.
3–5 hoursLearn
- Virtualisation and network modes (NAT vs host-only)
- Snapshots and reset discipline
- Why practice ranges must be isolated
Do
- Create a Linux VM on host-only networking and confirm it cannot reach your LAN.
- Snapshot before every experiment; restore once and note what you lost.
ToolsNmapLinux fundamentals
Files, permissions, processes and services — the layer almost every security tool lives on.
1–2 weeksLearn
- Filesystem layout and paths
- Permissions, ownership and the umask
- Processes, systemd services and logs
- What a shell actually is
Do
- List files by size in /var/log and open the newest with less.
- Find which process owns port 22 with `ss -ltnp`.
ToolsNetcatNetworking basics
Addresses, ports, protocols and the handshake. Everything below is unverifiable without this.
1–2 weeksDo
- Capture your own DNS queries and read the response codes.
- Explain to a colleague why 'closed' and 'filtered' are different answers.
HTTP and DNS
The two protocols that carry most of the web: requests, responses, status classes, name resolution.
1 weekLearn
- HTTP request/response
- DNS resolution chain
- Headers, cookies and same-origin basics
Do
- Print a request's headers with `curl -v` and label each one.
- Decode a Base64 header value and explain what it contained.
ToolsCyberChefReading tool output
Turning raw output into a note: what a scanner claims, what it measured, and what it could not see.
4–6 hoursLearn
- Evidence vs inference
- Saving output in a reproducible format
- Recording the exact command you ran
Do
- Scan one host with `-oA` and produce a three-line summary from the XML.
- Write one paragraph that states a limitation of your own scan.
Data, hashes and encodings
Encoding is not encryption. Learn the difference before touching anything credential-related.
1 weekLearn
- Hashing vs encryption
- Base64, hex, URL encoding
- Checksums for download verification
Do
- Verify a downloaded file against its published SHA-256.
- Encode then decode the same string through three encodings.
Your first vulnerability class
Input handling, on a deliberately vulnerable app you own. Depth on one class beats a survey of ten.
1–2 weeksLearn
- What a vulnerability is
- Injection, in theory and in a lab
- Output encoding and validation
Do
- Trigger an error with a single quote, then explain why it happened.
- Re-test the same parameter after applying a fix.
Notes, ethics and reporting
Scope, permission and how to write something another person can act on.
4–6 hoursLearn
- Rules of engagement in plain language
- Writing a finding: condition, evidence, impact
- CyberAtlas's responsible-use framing
Do
- Write a one-page report on your lab finding for a non-specialist.
- Draft the scope statement you would need before testing anything real.
ToolsNmap
Tools in this path
Each tool page carries installation steps, commands and the errors you will hit.