Cybersecurity Roadmap
A step-by-step path from networking and security fundamentals to penetration testing, SIEM & incident response, cloud security, and DevSecOps, 22 stages, in the order you should learn them.
- 1
Internet
Understand how requests actually travel from a client to your server, before you start defending or attacking them.
0% - 2
Security Fundamentals
The core principles every security decision gets measured against.
0% - 3
Networking Fundamentals
You can't secure what you don't understand, the fundamentals every attack and defense sits on top of.
0% - 4
OS & Terminal Fundamentals
Be fluent in the operating systems you'll be attacking, defending, or investigating.
0% - 5
Version Control Systems
Track changes to your scripts and tooling and collaborate with other engineers.
0% - 6
Repo Hosting Services
Host your Git repositories and collaborate via pull requests.
0%Pick only one to get started, GitHub is trending - 7
Pick a Scripting Language
Automate recon, parsing, and tooling. A scripting language is how you glue everything together.
0%Pick one to start with - 8
Cryptography
The math that keeps data confidential and verifiable in transit and at rest.
0% - 9
Web Application Security
The vulnerability classes that show up in almost every real-world breach.
0% - 10
Network Recon & Traffic Analysis
Discover what's on a network, then watch what actually crosses it.
0%Network ScanningTraffic Analysis - 11
Vulnerability Assessment
Systematically find known weaknesses before someone else does.
0%Pick one - 12
Penetration Testing
Simulate a real attacker end to end, then write it up so someone can fix it.
0%Pick a framework - 13
Web App Security Testing
Intercept, tamper with, and replay requests to find flaws by hand.
0%Pick a tool - 14
Identity & Access Management
Control who can prove who they are, and what they're allowed to touch once they do.
0%Pick one - 15
SIEM & Monitoring
Aggregate logs from everywhere into one place you can actually search and alert on.
0%Pick one - 16
Incident Response
What actually happens in the hours after something goes wrong.
0% - 17
Threat Intelligence & Hunting
Know your adversary before they show up in your logs.
0% - 18
Malware Analysis
Figure out what a suspicious binary actually does without running it blind.
0%Pick a tool - 19
Cloud Security
The shared responsibility model, and the misconfigurations that break it.
0%Pick one to start with - 20
Application Security & DevSecOps
Catch vulnerabilities in code before they ever reach production.
0%Pick a tool - 21
CI/CD & Pipeline Security
Keep secrets, dependencies, and build artifacts trustworthy through the whole pipeline.
0%Pick a tool - 22
Security Compliance & GRC
The frameworks and regulations most organizations are actually measured against.
0%
Keep going!
You're 0% of the way through. Every checkbox you tick is saved automatically in your browser.
Browse Tutorials