Skip to content

Roadmap

Absolute Beginner

The foundations everything else assumes: how machines address each other, how a shell works, and how to read what a program actually outputs. No prior security knowledge required.

Beginner8 stages4–6 weeks at 4–6 hours per week

Prerequisites

  • Basic computer literacy
  • Willingness to read command output

Who it is for

Complete newcomers, students, developers moving into security

Outcome: You can set up a lab, navigate Linux comfortably, explain what happens between a URL and a response, and read tool output without guessing.

Stages

Work them in order the first time. Ticking a stage only records your own progress, in this browser.

Progress0 / 80%

Stored in this browser only. No account, no sync.

  1. Build a safe lab

    A virtual machine you own, isolated from other networks, plus snapshots so mistakes are reversible.

    3–5 hours

    Learn

    • Virtualisation and network modes (NAT vs host-only)
    • Snapshots and reset discipline
    • Why practice ranges must be isolated

    Do

    • Create a Linux VM on host-only networking and confirm it cannot reach your LAN.
    • Snapshot before every experiment; restore once and note what you lost.
    ToolsNmap
  2. Linux fundamentals

    Files, permissions, processes and services — the layer almost every security tool lives on.

    1–2 weeks

    Learn

    • Filesystem layout and paths
    • Permissions, ownership and the umask
    • Processes, systemd services and logs
    • What a shell actually is

    Do

    • List files by size in /var/log and open the newest with less.
    • Find which process owns port 22 with `ss -ltnp`.
    ToolsNetcat
  3. Networking basics

    Addresses, ports, protocols and the handshake. Everything below is unverifiable without this.

    1–2 weeks

    Do

    • Capture your own DNS queries and read the response codes.
    • Explain to a colleague why 'closed' and 'filtered' are different answers.
  4. HTTP and DNS

    The two protocols that carry most of the web: requests, responses, status classes, name resolution.

    1 week

    Learn

    Do

    • Print a request's headers with `curl -v` and label each one.
    • Decode a Base64 header value and explain what it contained.
  5. Reading tool output

    Turning raw output into a note: what a scanner claims, what it measured, and what it could not see.

    4–6 hours

    Learn

    • Evidence vs inference
    • Saving output in a reproducible format
    • Recording the exact command you ran

    Do

    • Scan one host with `-oA` and produce a three-line summary from the XML.
    • Write one paragraph that states a limitation of your own scan.
  6. Data, hashes and encodings

    Encoding is not encryption. Learn the difference before touching anything credential-related.

    1 week

    Learn

    Do

    • Verify a downloaded file against its published SHA-256.
    • Encode then decode the same string through three encodings.
  7. Your first vulnerability class

    Input handling, on a deliberately vulnerable app you own. Depth on one class beats a survey of ten.

    1–2 weeks

    Learn

    Do

    • Trigger an error with a single quote, then explain why it happened.
    • Re-test the same parameter after applying a fix.
  8. Notes, ethics and reporting

    Scope, permission and how to write something another person can act on.

    4–6 hours

    Learn

    Do

    • Write a one-page report on your lab finding for a non-specialist.
    • Draft the scope statement you would need before testing anything real.
    ToolsNmap

Tools in this path

Each tool page carries installation steps, commands and the errors you will hit.