All Roadmaps

Cybersecurity Roadmap

A step-by-step path from networking and security fundamentals to penetration testing, SIEM & incident response, cloud security, and DevSecOps, 22 stages, in the order you should learn them.

= Trending= Recommended
Filter by stack:
Your Progress0/106 · 0%
  1. 1

    Internet

    Understand how requests actually travel from a client to your server, before you start defending or attacking them.

  2. 2

    Security Fundamentals

    The core principles every security decision gets measured against.

  3. 3

    Networking Fundamentals

    You can't secure what you don't understand, the fundamentals every attack and defense sits on top of.

  4. 4

    OS & Terminal Fundamentals

    Be fluent in the operating systems you'll be attacking, defending, or investigating.

  5. 5

    Version Control Systems

    Track changes to your scripts and tooling and collaborate with other engineers.

  6. 6

    Repo Hosting Services

    Host your Git repositories and collaborate via pull requests.

    Pick only one to get started, GitHub is trending
  7. 7

    Pick a Scripting Language

    Automate recon, parsing, and tooling. A scripting language is how you glue everything together.

    Pick one to start with
  8. 8

    Cryptography

    The math that keeps data confidential and verifiable in transit and at rest.

  9. 9

    Web Application Security

    The vulnerability classes that show up in almost every real-world breach.

  10. 10

    Network Recon & Traffic Analysis

    Discover what's on a network, then watch what actually crosses it.

    Network Scanning
    Traffic Analysis
  11. 11

    Vulnerability Assessment

    Systematically find known weaknesses before someone else does.

    Pick one
  12. 12

    Penetration Testing

    Simulate a real attacker end to end, then write it up so someone can fix it.

    Pick a framework
  13. 13

    Web App Security Testing

    Intercept, tamper with, and replay requests to find flaws by hand.

    Pick a tool
  14. 14

    Identity & Access Management

    Control who can prove who they are, and what they're allowed to touch once they do.

    Pick one
  15. 15

    SIEM & Monitoring

    Aggregate logs from everywhere into one place you can actually search and alert on.

    Pick one
  16. 16

    Incident Response

    What actually happens in the hours after something goes wrong.

  17. 17

    Threat Intelligence & Hunting

    Know your adversary before they show up in your logs.

  18. 18

    Malware Analysis

    Figure out what a suspicious binary actually does without running it blind.

    Pick a tool
  19. 19

    Cloud Security

    The shared responsibility model, and the misconfigurations that break it.

    Pick one to start with
  20. 20

    Application Security & DevSecOps

    Catch vulnerabilities in code before they ever reach production.

    Pick a tool
  21. 21

    CI/CD & Pipeline Security

    Keep secrets, dependencies, and build artifacts trustworthy through the whole pipeline.

    Pick a tool
  22. 22

    Security Compliance & GRC

    The frameworks and regulations most organizations are actually measured against.

Keep going!

You're 0% of the way through. Every checkbox you tick is saved automatically in your browser.

Browse Tutorials