KNOWLEDGE IS YOUR FIRST LINE OF DEFENSE
Find your way into
cybersecurity.
Build the foundations. Follow your curiosity. Explore the skills
that connect security operations, intelligence and investigation.
One shared foundation.
Many ways to make an impact.
Loading the learning map…
Learn with purpose. The paths share skills and are not prerequisites for a job title. Practice in systems you own or are authorized to use.
Explore the text guide ↓Accessible text guide & learning resources
Cybersecurity Fundamentals
Cybersecurity Fundamentals
Start with the purpose of security: protecting people, systems and information. Build practical IT knowledge before choosing a specialization.
Recommended level: Beginner
Suggested prerequisites: None
Concepts
- Purpose and scope
- A practical learning plan
Tools
No dedicated tool required
Resources
IT Fundamentals
IT Fundamentals
Understand how computers, applications and infrastructure fit together. These foundations make security findings easier to explain.
Recommended level: Beginner
Suggested prerequisites: Cybersecurity Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
No dedicated tool required
Resources
Computer Fundamentals
Trace how a program uses the CPU, memory, storage and operating system to complete a task.
Recommended level: Beginner
Suggested prerequisites: IT Fundamentals
Concepts
- CPU and memory
- Storage
- Applications and operating systems
Tools
No dedicated tool required
Resources
Hardware
Recognize common computer components and how failure, physical access and firmware affect security.
Recommended level: Beginner
Suggested prerequisites: IT Fundamentals
Concepts
- CPU architecture
- Storage devices
- Firmware and boot
Tools
No dedicated tool required
Resources
Virtualization
Use isolated virtual machines to learn safely and understand the boundary between host and guest.
Recommended level: Beginner
Suggested prerequisites: Computer Fundamentals
Concepts
- Hypervisors
- Virtual networking
- Snapshots
Tools
VirtualBox, Hyper-V
Resources
Cloud Fundamentals
Compare cloud service models and identify which security duties belong to the provider or customer.
Recommended level: Beginner
Suggested prerequisites: IT Fundamentals
Concepts
- IaaS, PaaS and SaaS
- Shared responsibility
- Regions and identities
Tools
No dedicated tool required
Resources
Networking
Networking
Follow a packet across a network and learn the protocols that defenders and investigators rely on.
Recommended level: Beginner
Suggested prerequisites: IT Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
Wireshark
Resources
OSI Model
Use a layered model to describe where a connection fails and where a security control operates.
Recommended level: Beginner
Suggested prerequisites: Networking
Concepts
- Seven layers
- Encapsulation
- Troubleshooting
Tools
Wireshark
Resources
TCP/IP
Compare reliable connections with connectionless delivery and identify common protocol fields.
Recommended level: Beginner
Suggested prerequisites: OSI Model
Concepts
- TCP handshake
- UDP
- Ports
Tools
Wireshark
Resources
IPv4 / IPv6
Read addresses and understand the different addressing and discovery mechanisms in IPv4 and IPv6.
Recommended level: Beginner
Suggested prerequisites: TCP/IP
Concepts
- Address structure
- Private ranges
- Neighbor discovery
Tools
Wireshark
Resources
Subnetting
Calculate network boundaries and use address ranges to explain segmentation.
Recommended level: Beginner
Suggested prerequisites: IPv4 / IPv6
Concepts
- CIDR
- Network masks
- Address planning
Tools
Wireshark
Resources
DNS
Trace a name lookup and recognize how DNS records and caching affect visibility and trust.
Recommended level: Beginner
Suggested prerequisites: TCP/IP
Concepts
- Resolvers
- Record types
- Caching
Tools
Wireshark
Resources
DHCP
Understand how a device receives network settings and what unexpected leases can reveal.
Recommended level: Beginner
Suggested prerequisites: IPv4 / IPv6
Concepts
- Lease lifecycle
- Reservations
- Rogue services
Tools
Wireshark
Resources
HTTP / HTTPS
Read a web request and response, then separate application behavior from transport protection.
Recommended level: Beginner
Suggested prerequisites: TCP/IP
Concepts
- Methods and status codes
- Headers
- Cookies
Tools
Wireshark
Resources
TLS
Explain how a secure channel authenticates a peer and protects traffic in transit.
Recommended level: Beginner
Suggested prerequisites: HTTP / HTTPS
Concepts
- Handshake
- Certificates
- Protocol negotiation
Tools
Wireshark
Resources
VPN
Compare remote-access and site-to-site tunnels and identify their trust boundaries.
Recommended level: Beginner
Suggested prerequisites: Routing, TLS
Concepts
- Tunnels
- Routing
- Access control
Tools
Wireshark
Resources
Firewalls
Read traffic policy as a set of conditions and understand stateful filtering.
Recommended level: Beginner
Suggested prerequisites: TCP/IP
Concepts
- State tracking
- Rule order
- Segmentation
Tools
Wireshark
Resources
Proxy
Follow traffic through an intermediary and distinguish forward from reverse proxies.
Recommended level: Beginner
Suggested prerequisites: HTTP / HTTPS
Concepts
- Forward and reverse proxy
- Headers
- Trust boundaries
Tools
Wireshark
Resources
Routing
Explain how traffic moves between networks and how route selection changes its path.
Recommended level: Beginner
Suggested prerequisites: Subnetting
Concepts
- Routing tables
- Gateways
- Longest prefix match
Tools
Wireshark
Resources
Switching
Understand local frame forwarding and the role of VLANs in network separation.
Recommended level: Beginner
Suggested prerequisites: TCP/IP
Concepts
- MAC tables
- VLANs
- Broadcast domains
Tools
Wireshark
Resources
Operating Systems
Operating Systems
Learn both operating system families. Security events make more sense when you understand normal administration.
Recommended level: Beginner
Suggested prerequisites: Networking
Concepts
- Purpose and scope
- A practical learning plan
Tools
No dedicated tool required
Resources
Linux
Linux
Build confidence administering a Linux host and investigating its normal behavior.
Recommended level: Beginner
Suggested prerequisites: Operating Systems
Concepts
- Purpose and scope
- A practical learning plan
Tools
Linux VM
Resources
Linux Fundamentals
Navigate a shell and identify the main responsibilities of a Linux operating system.
Recommended level: Beginner
Suggested prerequisites: Linux
Concepts
- Distributions
- Shell navigation
- Package management
Tools
Linux VM
Resources
Filesystem
Locate configuration, executable and runtime files using the filesystem hierarchy.
Recommended level: Beginner
Suggested prerequisites: Linux Fundamentals
Concepts
- Paths
- Mounts
- File types
Tools
Linux VM
Resources
Users & Groups
Understand local identities and how group membership grants access.
Recommended level: Beginner
Suggested prerequisites: Linux Fundamentals
Concepts
- UID and GID
- Account lifecycle
- Group membership
Tools
Linux VM
Resources
Permissions
Read file permissions and apply least privilege to users and services.
Recommended level: Beginner
Suggested prerequisites: Users & Groups
Concepts
- Owner and group
- Permission bits
- sudo
Tools
Linux VM
Resources
Processes
Inspect running processes and connect resource use to executable behavior.
Recommended level: Beginner
Suggested prerequisites: Linux Fundamentals
Concepts
- PIDs
- Signals
- Parent-child relationships
Tools
Linux VM
Resources
Services
Inspect service configuration and understand how software starts and runs in the background.
Recommended level: Beginner
Suggested prerequisites: Processes
Concepts
- systemd
- Unit files
- Service accounts
Tools
Linux VM
Resources
Networking
Inspect interfaces, sockets and local network configuration on a Linux host.
Recommended level: Beginner
Suggested prerequisites: Networking, Linux Fundamentals
Concepts
- Interfaces
- Listening sockets
- Routes
Tools
Linux VM
Resources
Bash
Automate repeatable administration tasks while handling input and errors carefully.
Recommended level: Beginner
Suggested prerequisites: Linux Fundamentals
Concepts
- Pipelines
- Variables
- Exit codes
Tools
Bash
Resources
Logs
Find relevant host logs and correlate events without losing timestamp context.
Recommended level: Beginner
Suggested prerequisites: Services
Concepts
- journalctl
- Authentication logs
- Time zones
Tools
Linux VM
Resources
Windows
Windows
Learn Windows administration, identity and event collection before investigating enterprise environments.
Recommended level: Beginner
Suggested prerequisites: Operating Systems
Concepts
- Purpose and scope
- A practical learning plan
Tools
Windows VM
Resources
Windows Fundamentals
Identify normal Windows components and use built-in administrative tools to inspect a host.
Recommended level: Beginner
Suggested prerequisites: Windows
Concepts
- Accounts
- Filesystem
- Administrative tools
Tools
Windows VM
Resources
Active Directory
Understand how a directory organizes identities, computers and trust in an enterprise.
Recommended level: Beginner
Suggested prerequisites: Windows Fundamentals, DNS
Concepts
- Domains
- Domain controllers
- Kerberos
Tools
Windows VM
Resources
PowerShell
Use structured objects and safe scripts to query and administer Windows.
Recommended level: Beginner
Suggested prerequisites: Windows Fundamentals
Concepts
- Cmdlets
- Pipelines
- Execution context
Tools
PowerShell
Resources
Windows Services
Inspect service accounts and startup behavior to distinguish expected from unusual activity.
Recommended level: Beginner
Suggested prerequisites: Windows Fundamentals
Concepts
- Service Control Manager
- Startup types
- Service identities
Tools
Windows VM
Resources
Registry
Navigate the configuration store and understand how changes affect system behavior.
Recommended level: Beginner
Suggested prerequisites: Windows Fundamentals
Concepts
- Hives
- Keys and values
- Persistence locations
Tools
Windows VM
Resources
Event Logs
Find Windows events and interpret their fields in the context of host activity.
Recommended level: Beginner
Suggested prerequisites: Windows Fundamentals
Concepts
- Channels
- Event IDs
- Audit policy
Tools
Event Viewer
Resources
Group Policy
Trace how centrally managed settings reach domain users and computers.
Recommended level: Beginner
Suggested prerequisites: Active Directory
Concepts
- GPOs
- Scope and inheritance
- Policy processing
Tools
Windows VM
Resources
Authentication
Compare Windows authentication mechanisms and recognize the logs they produce.
Recommended level: Beginner
Suggested prerequisites: Active Directory
Concepts
- Kerberos
- NTLM
- Logon types
Tools
Windows VM
Resources
Security Fundamentals
Security Fundamentals
Connect technical foundations with identity, risk and defensive controls. From here, choose one or more specialties.
Recommended level: Beginner
Suggested prerequisites: Linux, Windows
Concepts
- Purpose and scope
- A practical learning plan
Tools
No dedicated tool required
Resources
CIA Triad
Describe a security requirement in terms of confidentiality, integrity and availability.
Recommended level: Beginner
Suggested prerequisites: Security Fundamentals
Concepts
- Confidentiality
- Integrity
- Availability
Tools
No dedicated tool required
Resources
Authentication
Explain how a system verifies an identity and what can weaken that assurance.
Recommended level: Beginner
Suggested prerequisites: Security Fundamentals
Concepts
- Identity proof
- Credentials
- Session lifecycle
Tools
No dedicated tool required
Resources
IAM
Understand how organizations create, review and retire access across systems.
Recommended level: Beginner
Suggested prerequisites: Authentication, Authorization
Concepts
- Joiner-mover-leaver
- Access reviews
- Federation
Tools
No dedicated tool required
Resources
MFA
Compare authentication factors and understand how recovery and user experience affect protection.
Recommended level: Beginner
Suggested prerequisites: Authentication
Concepts
- Knowledge, possession, inherence
- Phishing resistance
- Recovery
Tools
No dedicated tool required
Resources
Cryptography
Explain the purpose of encryption and signatures without inventing cryptographic schemes.
Recommended level: Beginner
Suggested prerequisites: Security Fundamentals
Concepts
- Symmetric and asymmetric encryption
- Keys
- Digital signatures
Tools
No dedicated tool required
Resources
Hashing
Distinguish a fingerprint from encryption and recognize the need for dedicated password hashing.
Recommended level: Beginner
Suggested prerequisites: Cryptography
Concepts
- Integrity checks
- Collisions
- Password hashing
Tools
No dedicated tool required
Resources
PKI
Trace how certificates bind identities to keys and how trust can be revoked.
Recommended level: Beginner
Suggested prerequisites: Cryptography, TLS
Concepts
- Certificate chains
- Trust anchors
- Revocation
Tools
No dedicated tool required
Resources
Vulnerability Management
Turn findings into a repeatable process for prioritization, remediation and verification.
Recommended level: Beginner
Suggested prerequisites: Security Fundamentals
Concepts
- Asset inventory
- Risk prioritization
- Remediation
Tools
No dedicated tool required
Resources
CVE / CVSS
Distinguish a vulnerability identifier from a severity score and add environmental context.
Recommended level: Beginner
Suggested prerequisites: Vulnerability Management
Concepts
- Identifiers
- Severity metrics
- Exposure
Tools
No dedicated tool required
Resources
Security Hardening
Reduce unnecessary functionality and verify that secure settings remain effective.
Recommended level: Beginner
Suggested prerequisites: Linux, Windows
Concepts
- Baseline configuration
- Attack surface
- Configuration drift
Tools
No dedicated tool required
Resources
MITRE ATT&CK
Use documented adversary behavior to organize observations and identify coverage gaps.
Recommended level: Beginner
Suggested prerequisites: Security Fundamentals
Concepts
- Tactics
- Techniques
- Evidence mapping
Tools
No dedicated tool required
Resources
SOC Analyst
SOC Analyst
Turn telemetry into decisions: investigate alerts, build detections and help coordinate a measured response.
Recommended level: Intermediate
Suggested prerequisites: Security Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
Splunk, Microsoft Sentinel, Elastic, QRadar, CrowdStrike, Microsoft Defender
Resources
SOC Fundamentals
Understand how people, processes and telemetry combine to support security operations.
Recommended level: Intermediate
Suggested prerequisites: SOC Analyst
Concepts
- Roles and handoffs
- Escalation
- Service metrics
Tools
No dedicated tool required
Resources
SIEM
Collect and normalize security events so analysts can search, correlate and investigate them.
Recommended level: Intermediate
Suggested prerequisites: SOC Fundamentals
Concepts
- Ingestion
- Parsing
- Correlation
Tools
Splunk, Microsoft Sentinel, Elastic, QRadar
Resources
Log Analysis
Ask a specific question of logs and preserve the context needed to interpret the answer.
Recommended level: Intermediate
Suggested prerequisites: SIEM
Concepts
- Field interpretation
- Baselines
- Time correlation
Tools
No dedicated tool required
Resources
Windows Event Logs
Choose useful Windows event sources and interpret logon, process and policy activity.
Recommended level: Intermediate
Suggested prerequisites: Event Logs, Log Analysis
Concepts
- Audit policy
- Logon events
- Collection coverage
Tools
No dedicated tool required
Resources
Sysmon
Understand enriched Windows telemetry and tune collection to the environment.
Recommended level: Intermediate
Suggested prerequisites: Windows Event Logs
Concepts
- Process creation
- Network connections
- Configuration rules
Tools
Sysmon
Resources
Detection Engineering
Design and test detections against observable behavior, including their blind spots.
Recommended level: Intermediate
Suggested prerequisites: Log Analysis, MITRE ATT&CK
Concepts
- Detection hypotheses
- Test cases
- False positives
Tools
No dedicated tool required
Resources
Sigma
Read portable detection logic and validate how a backend translates it into a query.
Recommended level: Intermediate
Suggested prerequisites: Detection Engineering
Concepts
- Log sources
- Conditions
- Backend conversion
Tools
Sigma
Resources
Alert Triage
Assess urgency and confidence before deciding whether to escalate an alert.
Recommended level: Intermediate
Suggested prerequisites: Log Analysis
Concepts
- Context gathering
- Severity
- Escalation
Tools
No dedicated tool required
Resources
Incident Response
Help contain an incident while recording evidence and coordinating the next steps.
Recommended level: Intermediate
Suggested prerequisites: Alert Triage
Concepts
- Containment
- Communication
- Recovery
Tools
No dedicated tool required
Resources
Threat Hunting
Test a hypothesis about activity that existing alerts may not detect.
Recommended level: Intermediate
Suggested prerequisites: Detection Engineering
Concepts
- Hypothesis
- Data requirements
- Documented findings
Tools
No dedicated tool required
Resources
EDR
Use endpoint telemetry and response controls while considering sensor coverage and side effects.
Recommended level: Intermediate
Suggested prerequisites: Windows, Linux
Concepts
- Endpoint visibility
- Investigation
- Response actions
Tools
CrowdStrike, Microsoft Defender
Resources
Network Detection
Identify suspicious network behavior using traffic metadata and available packet evidence.
Recommended level: Intermediate
Suggested prerequisites: Networking, Log Analysis
Concepts
- Flow data
- Protocol anomalies
- Encrypted traffic limits
Tools
Wireshark, Zeek
Resources
Email Security
Investigate suspicious messages using headers, authentication results and user context.
Recommended level: Intermediate
Suggested prerequisites: DNS, HTTP / HTTPS
Concepts
- Message headers
- SPF, DKIM, DMARC
- Phishing triage
Tools
No dedicated tool required
Resources
Digital Forensics & Incident Response
Digital Forensics & Incident Response
Reconstruct what happened from evidence, preserve its integrity and support a defensible response.
Recommended level: Intermediate
Suggested prerequisites: Security Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
Volatility, Autopsy, Wireshark, Velociraptor
Resources
Incident Response
Plan investigation and containment as coordinated activities rather than isolated tool actions.
Recommended level: Intermediate
Suggested prerequisites: Digital Forensics & Incident Response
Concepts
- Preparation
- Containment
- Recovery
Tools
No dedicated tool required
Resources
Evidence Collection
Choose a collection method that preserves useful data and records its provenance.
Recommended level: Intermediate
Suggested prerequisites: Incident Response
Concepts
- Chain of custody
- Volatile evidence
- Integrity checks
Tools
No dedicated tool required
Resources
Disk Forensics
Interpret a forensic image and distinguish filesystem artifacts from conclusions.
Recommended level: Intermediate
Suggested prerequisites: Evidence Collection
Concepts
- Images
- Filesystem metadata
- Deleted data limits
Tools
Autopsy
Resources
Memory Forensics
Use memory evidence to investigate runtime state that disk evidence may miss.
Recommended level: Intermediate
Suggested prerequisites: Evidence Collection
Concepts
- Processes
- Memory acquisition
- Artifact interpretation
Tools
Volatility
Resources
Network Forensics
Reconstruct network activity while accounting for missing packets and encryption.
Recommended level: Intermediate
Suggested prerequisites: Evidence Collection, Networking
Concepts
- PCAP
- Flows
- Session reconstruction
Tools
Wireshark
Resources
Timeline Analysis
Combine sources into a timeline while preserving clock differences and uncertainty.
Recommended level: Intermediate
Suggested prerequisites: Disk Forensics, Event Logs
Concepts
- Timestamp semantics
- Clock skew
- Event correlation
Tools
No dedicated tool required
Resources
Windows Forensics
Correlate Windows artifacts with account, application and execution history.
Recommended level: Intermediate
Suggested prerequisites: Windows, Evidence Collection
Concepts
- Registry artifacts
- Event logs
- Filesystem artifacts
Tools
Velociraptor
Resources
Linux Forensics
Investigate Linux host activity using logs, filesystem artifacts and service configuration.
Recommended level: Intermediate
Suggested prerequisites: Linux, Evidence Collection
Concepts
- Authentication logs
- Shell artifacts
- Service changes
Tools
No dedicated tool required
Resources
Malware Triage
Collect safe initial observations about a suspicious file and decide what analysis is needed next.
Recommended level: Intermediate
Suggested prerequisites: Evidence Collection, Hashing
Concepts
- File identification
- Hashes
- Safe handling
Tools
No dedicated tool required
Resources
Cyber Threat Intelligence
Cyber Threat Intelligence
Connect observations to a clear intelligence question. Track adversary behavior and turn uncertain evidence into useful assessments.
Recommended level: Intermediate
Suggested prerequisites: Security Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
VirusTotal, OpenCTI, MISP, Shodan
Resources
CTI Fundamentals
Define an intelligence requirement and produce an assessment that helps someone make a decision.
Recommended level: Intermediate
Suggested prerequisites: Cyber Threat Intelligence
Concepts
- Intelligence cycle
- Requirements
- Confidence
Tools
No dedicated tool required
Resources
IOC
Treat indicators as contextual observations with a lifespan, not permanent proof of compromise.
Recommended level: Intermediate
Suggested prerequisites: CTI Fundamentals
Concepts
- Indicator types
- Context
- Expiration
Tools
No dedicated tool required
Resources
TTP
Describe patterns of adversary behavior and separate them from individual infrastructure indicators.
Recommended level: Intermediate
Suggested prerequisites: CTI Fundamentals
Concepts
- Tactics
- Techniques
- Procedures
Tools
No dedicated tool required
Resources
MITRE ATT&CK
Map a sourced observation to adversary behavior without overstating the evidence.
Recommended level: Intermediate
Suggested prerequisites: TTP, MITRE ATT&CK
Concepts
- Technique mapping
- Sources
- Coverage
Tools
No dedicated tool required
Resources
OSINT
Gather public information with a defined question and record how reliable each source is.
Recommended level: Intermediate
Suggested prerequisites: CTI Fundamentals
Concepts
- Source evaluation
- Collection scope
- Provenance
Tools
No dedicated tool required
Resources
Threat Actors
Compare behavior and reporting while separating actor labels from verified attribution.
Recommended level: Intermediate
Suggested prerequisites: TTP, OSINT
Concepts
- Clustering
- Aliases
- Attribution uncertainty
Tools
No dedicated tool required
Resources
Campaign Tracking
Link related activity across time and describe what supports or weakens the relationship.
Recommended level: Intermediate
Suggested prerequisites: Threat Actors, IOC
Concepts
- Activity clusters
- Time windows
- Confidence
Tools
No dedicated tool required
Resources
Malware Tracking
Track malware families using behavior and evidence rather than relying on a single vendor label.
Recommended level: Intermediate
Suggested prerequisites: IOC, TTP
Concepts
- Family naming
- Behavior
- Sample relationships
Tools
No dedicated tool required
Resources
Infrastructure Tracking
Connect domains, addresses and certificates with explicit time and evidence boundaries.
Recommended level: Intermediate
Suggested prerequisites: IOC, DNS
Concepts
- Infrastructure relationships
- Time context
- Shared hosting
Tools
No dedicated tool required
Resources
Domain Analysis
Evaluate a domain using registration, resolution and usage context without assuming that age proves intent.
Recommended level: Intermediate
Suggested prerequisites: DNS, OSINT
Concepts
- Registration
- DNS history
- Hosting context
Tools
VirusTotal
Resources
URL Analysis
Separate a URL into components and assess redirects, hosting and observed behavior safely.
Recommended level: Intermediate
Suggested prerequisites: HTTP / HTTPS, OSINT
Concepts
- URL structure
- Redirects
- Context
Tools
VirusTotal
Resources
IP Analysis
Interpret address ownership and observations while accounting for reassignment and shared services.
Recommended level: Intermediate
Suggested prerequisites: IPv4 / IPv6, OSINT
Concepts
- ASN
- Hosting
- Time-sensitive context
Tools
Shodan
Resources
Passive DNS
Use historical resolutions to investigate relationships while recognizing collection gaps.
Recommended level: Intermediate
Suggested prerequisites: DNS, Infrastructure Tracking
Concepts
- Observation windows
- Record history
- Coverage bias
Tools
No dedicated tool required
Resources
WHOIS / RDAP
Read registration data and understand privacy, availability and protocol differences.
Recommended level: Intermediate
Suggested prerequisites: Domain Analysis
Concepts
- Registration records
- RDAP
- Data limitations
Tools
No dedicated tool required
Resources
YARA
Describe patterns in files with rules and validate their specificity against representative samples.
Recommended level: Intermediate
Suggested prerequisites: Hashing, Malware Tracking
Concepts
- Strings
- Conditions
- Rule testing
Tools
YARA
Resources
Sigma
Translate intelligence about observable behavior into portable detection ideas.
Recommended level: Intermediate
Suggested prerequisites: TTP, Sigma
Concepts
- Log sources
- Detection conditions
- Validation
Tools
Sigma
Resources
STIX
Represent intelligence as structured objects and relationships with provenance.
Recommended level: Intermediate
Suggested prerequisites: CTI Fundamentals
Concepts
- Objects
- Relationships
- Markings
Tools
OpenCTI, MISP
Resources
TAXII
Understand how structured intelligence is exchanged and how clients discover collections.
Recommended level: Intermediate
Suggested prerequisites: STIX
Concepts
- Collections
- API transport
- Authentication
Tools
No dedicated tool required
Resources
Threat Intelligence Platforms
Organize intelligence with consistent relationships, access controls and a clear publishing workflow.
Recommended level: Intermediate
Suggested prerequisites: STIX, TAXII
Concepts
- Data model
- Enrichment
- Sharing policies
Tools
OpenCTI, MISP
Resources
Offensive Security
Offensive Security
Learn to assess security in systems you own or are explicitly authorized to test. Connect every finding to remediation.
Recommended level: Intermediate
Suggested prerequisites: Security Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
Burp Suite, Wireshark
Resources
Reconnaissance
Define scope and gather information that helps plan an authorized assessment.
Recommended level: Advanced
Suggested prerequisites: Offensive Security
Concepts
- Rules of engagement
- Asset discovery
- Scope boundaries
Tools
No dedicated tool required
Resources
OSINT
Use public sources to understand an authorized target and document collection limits.
Recommended level: Advanced
Suggested prerequisites: Reconnaissance
Concepts
- Source validation
- Exposure
- Responsible collection
Tools
No dedicated tool required
Resources
Enumeration
Identify services and configurations in a controlled environment and record observations accurately.
Recommended level: Advanced
Suggested prerequisites: Reconnaissance, Networking
Concepts
- Service inventory
- Configuration
- Evidence
Tools
No dedicated tool required
Resources
Web Security
Understand how application trust boundaries can fail and how to test them in a lab.
Recommended level: Advanced
Suggested prerequisites: HTTP / HTTPS, Authorization
Concepts
- Input handling
- Sessions
- Access control
Tools
No dedicated tool required
Resources
OWASP Top 10
Use a risk overview to guide learning without treating it as a complete testing checklist.
Recommended level: Advanced
Suggested prerequisites: Web Security
Concepts
- Application risk categories
- Root causes
- Mitigation
Tools
No dedicated tool required
Resources
Burp Suite
Inspect and replay lab HTTP traffic to understand application behavior within an agreed scope.
Recommended level: Advanced
Suggested prerequisites: Web Security
Concepts
- Intercepting proxy
- Request analysis
- Scope configuration
Tools
Burp Suite
Resources
Network Pentesting
Plan an authorized network assessment and connect observations to defensible findings.
Recommended level: Advanced
Suggested prerequisites: Enumeration, Networking
Concepts
- Scope
- Service exposure
- Reporting
Tools
No dedicated tool required
Resources
Active Directory Attacks
Study directory attack paths in a lab and identify the controls that interrupt them.
Recommended level: Advanced
Suggested prerequisites: Active Directory, IAM
Concepts
- Identity relationships
- Trust boundaries
- Defensive controls
Tools
No dedicated tool required
Resources
Privilege Escalation
Recognize conditions that allow more access than intended and validate fixes in a controlled lab.
Recommended level: Advanced
Suggested prerequisites: Permissions, Windows Services
Concepts
- Permission mistakes
- Service context
- Least privilege
Tools
No dedicated tool required
Resources
Exploitation
Understand why a vulnerability is exploitable, using intentionally vulnerable labs and clear safety limits.
Recommended level: Advanced
Suggested prerequisites: Vulnerability Management, Enumeration
Concepts
- Root cause
- Lab isolation
- Remediation validation
Tools
No dedicated tool required
Resources
Password Attacks
Study credential risks using synthetic lab accounts and compare preventive controls.
Recommended level: Advanced
Suggested prerequisites: Hashing, MFA
Concepts
- Password storage
- Rate limiting
- MFA
Tools
No dedicated tool required
Resources
Post Exploitation
Understand potential impact in an authorized simulation and document cleanup and defensive lessons.
Recommended level: Advanced
Suggested prerequisites: Exploitation
Concepts
- Impact assessment
- Scope limits
- Cleanup
Tools
No dedicated tool required
Resources
Malware Analysis
Malware Analysis
Examine suspicious software in an isolated environment and explain its behavior with evidence.
Recommended level: Intermediate
Suggested prerequisites: Security Fundamentals
Concepts
- Purpose and scope
- A practical learning plan
Tools
REMnux, Ghidra, YARA
Resources
Malware Fundamentals
Distinguish malicious behavior from labels and define an analysis question before opening a sample.
Recommended level: Advanced
Suggested prerequisites: Malware Analysis
Concepts
- Behavior
- Safe handling
- Analysis goals
Tools
No dedicated tool required
Resources
Static Analysis
Inspect a file without running it and separate useful clues from unverified assumptions.
Recommended level: Advanced
Suggested prerequisites: Malware Fundamentals, Hashing
Concepts
- File type
- Strings
- Imports
Tools
No dedicated tool required
Resources
Dynamic Analysis
Observe a sample in an isolated lab while controlling network access and preserving the baseline.
Recommended level: Advanced
Suggested prerequisites: Malware Fundamentals, Virtualization
Concepts
- Isolation
- Behavior monitoring
- Snapshots
Tools
No dedicated tool required
Resources
Sandboxing
Understand what automated analysis can reveal and where its coverage stops.
Recommended level: Advanced
Suggested prerequisites: Dynamic Analysis
Concepts
- Detonation environment
- Evasion
- Report interpretation
Tools
No dedicated tool required
Resources
Reverse Engineering
Read program structure to explain behavior, beginning with small educational binaries.
Recommended level: Advanced
Suggested prerequisites: Static Analysis
Concepts
- Assembly basics
- Control flow
- Functions
Tools
Ghidra
Resources
PE Files
Identify Windows executable structures and how sections and imports support analysis.
Recommended level: Advanced
Suggested prerequisites: Windows Fundamentals, Static Analysis
Concepts
- Headers
- Sections
- Import table
Tools
No dedicated tool required
Resources
Obfuscation
Recognize transformations that make code harder to inspect and document their effect on confidence.
Recommended level: Advanced
Suggested prerequisites: Static Analysis, Reverse Engineering
Concepts
- Packing
- Encoding
- Control-flow changes
Tools
No dedicated tool required
Resources
Persistence
Identify mechanisms that restore execution and connect them to host artifacts and detection.
Recommended level: Advanced
Suggested prerequisites: Windows Services, Services
Concepts
- Startup locations
- Services
- Scheduled tasks
Tools
No dedicated tool required
Resources
Command & Control
Characterize communication behavior from controlled observations and distinguish facts from hypotheses.
Recommended level: Advanced
Suggested prerequisites: Networking, Dynamic Analysis
Concepts
- Protocols
- Timing
- Infrastructure
Tools
No dedicated tool required
Resources
YARA
Build and test file-matching rules against benign and malicious examples in an isolated workflow.
Recommended level: Advanced
Suggested prerequisites: Static Analysis
Concepts
- Strings
- Conditions
- False positives
Tools
YARA