KNOWLEDGE IS YOUR FIRST LINE OF DEFENSE

Find your way into
cybersecurity.

Build the foundations. Follow your curiosity. Explore the skills
that connect security operations, intelligence and investigation.

NEWS4CYBER LEARNING PATH
121learning nodes
05specialist paths

One shared foundation.
Many ways to make an impact.

Loading the learning map…

Drag to explore · Select a node to learn
100%

Learn with purpose. The paths share skills and are not prerequisites for a job title. Practice in systems you own or are authorized to use.

Explore the text guide ↓
Accessible text guide & learning resources

Cybersecurity Fundamentals

Cybersecurity Fundamentals

Start with the purpose of security: protecting people, systems and information. Build practical IT knowledge before choosing a specialization.

Recommended level: Beginner

Suggested prerequisites: None

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

No dedicated tool required

Resources

IT Fundamentals

IT Fundamentals

Understand how computers, applications and infrastructure fit together. These foundations make security findings easier to explain.

Recommended level: Beginner

Suggested prerequisites: Cybersecurity Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

No dedicated tool required

Resources

Computer Fundamentals

Trace how a program uses the CPU, memory, storage and operating system to complete a task.

Recommended level: Beginner

Suggested prerequisites: IT Fundamentals

Concepts

  • CPU and memory
  • Storage
  • Applications and operating systems

Tools

No dedicated tool required

Resources

Hardware

Recognize common computer components and how failure, physical access and firmware affect security.

Recommended level: Beginner

Suggested prerequisites: IT Fundamentals

Concepts

  • CPU architecture
  • Storage devices
  • Firmware and boot

Tools

No dedicated tool required

Resources

Virtualization

Use isolated virtual machines to learn safely and understand the boundary between host and guest.

Recommended level: Beginner

Suggested prerequisites: Computer Fundamentals

Concepts

  • Hypervisors
  • Virtual networking
  • Snapshots

Tools

VirtualBox, Hyper-V

Resources

Cloud Fundamentals

Compare cloud service models and identify which security duties belong to the provider or customer.

Recommended level: Beginner

Suggested prerequisites: IT Fundamentals

Concepts

  • IaaS, PaaS and SaaS
  • Shared responsibility
  • Regions and identities

Tools

No dedicated tool required

Resources

Networking

Networking

Follow a packet across a network and learn the protocols that defenders and investigators rely on.

Recommended level: Beginner

Suggested prerequisites: IT Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Wireshark

Resources

OSI Model

Use a layered model to describe where a connection fails and where a security control operates.

Recommended level: Beginner

Suggested prerequisites: Networking

Concepts

  • Seven layers
  • Encapsulation
  • Troubleshooting

Tools

Wireshark

Resources

TCP/IP

Compare reliable connections with connectionless delivery and identify common protocol fields.

Recommended level: Beginner

Suggested prerequisites: OSI Model

Concepts

  • TCP handshake
  • UDP
  • Ports

Tools

Wireshark

Resources

IPv4 / IPv6

Read addresses and understand the different addressing and discovery mechanisms in IPv4 and IPv6.

Recommended level: Beginner

Suggested prerequisites: TCP/IP

Concepts

  • Address structure
  • Private ranges
  • Neighbor discovery

Tools

Wireshark

Resources

Subnetting

Calculate network boundaries and use address ranges to explain segmentation.

Recommended level: Beginner

Suggested prerequisites: IPv4 / IPv6

Concepts

  • CIDR
  • Network masks
  • Address planning

Tools

Wireshark

Resources

DNS

Trace a name lookup and recognize how DNS records and caching affect visibility and trust.

Recommended level: Beginner

Suggested prerequisites: TCP/IP

Concepts

  • Resolvers
  • Record types
  • Caching

Tools

Wireshark

Resources

DHCP

Understand how a device receives network settings and what unexpected leases can reveal.

Recommended level: Beginner

Suggested prerequisites: IPv4 / IPv6

Concepts

  • Lease lifecycle
  • Reservations
  • Rogue services

Tools

Wireshark

Resources

HTTP / HTTPS

Read a web request and response, then separate application behavior from transport protection.

Recommended level: Beginner

Suggested prerequisites: TCP/IP

Concepts

  • Methods and status codes
  • Headers
  • Cookies

Tools

Wireshark

Resources

TLS

Explain how a secure channel authenticates a peer and protects traffic in transit.

Recommended level: Beginner

Suggested prerequisites: HTTP / HTTPS

Concepts

  • Handshake
  • Certificates
  • Protocol negotiation

Tools

Wireshark

Resources

VPN

Compare remote-access and site-to-site tunnels and identify their trust boundaries.

Recommended level: Beginner

Suggested prerequisites: Routing, TLS

Concepts

  • Tunnels
  • Routing
  • Access control

Tools

Wireshark

Resources

Firewalls

Read traffic policy as a set of conditions and understand stateful filtering.

Recommended level: Beginner

Suggested prerequisites: TCP/IP

Concepts

  • State tracking
  • Rule order
  • Segmentation

Tools

Wireshark

Resources

Proxy

Follow traffic through an intermediary and distinguish forward from reverse proxies.

Recommended level: Beginner

Suggested prerequisites: HTTP / HTTPS

Concepts

  • Forward and reverse proxy
  • Headers
  • Trust boundaries

Tools

Wireshark

Resources

Routing

Explain how traffic moves between networks and how route selection changes its path.

Recommended level: Beginner

Suggested prerequisites: Subnetting

Concepts

  • Routing tables
  • Gateways
  • Longest prefix match

Tools

Wireshark

Resources

Switching

Understand local frame forwarding and the role of VLANs in network separation.

Recommended level: Beginner

Suggested prerequisites: TCP/IP

Concepts

  • MAC tables
  • VLANs
  • Broadcast domains

Tools

Wireshark

Resources

Operating Systems

Operating Systems

Learn both operating system families. Security events make more sense when you understand normal administration.

Recommended level: Beginner

Suggested prerequisites: Networking

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

No dedicated tool required

Resources

Linux

Linux

Build confidence administering a Linux host and investigating its normal behavior.

Recommended level: Beginner

Suggested prerequisites: Operating Systems

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Linux VM

Resources

Linux Fundamentals

Navigate a shell and identify the main responsibilities of a Linux operating system.

Recommended level: Beginner

Suggested prerequisites: Linux

Concepts

  • Distributions
  • Shell navigation
  • Package management

Tools

Linux VM

Resources

Filesystem

Locate configuration, executable and runtime files using the filesystem hierarchy.

Recommended level: Beginner

Suggested prerequisites: Linux Fundamentals

Concepts

  • Paths
  • Mounts
  • File types

Tools

Linux VM

Resources

Users & Groups

Understand local identities and how group membership grants access.

Recommended level: Beginner

Suggested prerequisites: Linux Fundamentals

Concepts

  • UID and GID
  • Account lifecycle
  • Group membership

Tools

Linux VM

Resources

Permissions

Read file permissions and apply least privilege to users and services.

Recommended level: Beginner

Suggested prerequisites: Users & Groups

Concepts

  • Owner and group
  • Permission bits
  • sudo

Tools

Linux VM

Resources

Processes

Inspect running processes and connect resource use to executable behavior.

Recommended level: Beginner

Suggested prerequisites: Linux Fundamentals

Concepts

  • PIDs
  • Signals
  • Parent-child relationships

Tools

Linux VM

Resources

Services

Inspect service configuration and understand how software starts and runs in the background.

Recommended level: Beginner

Suggested prerequisites: Processes

Concepts

  • systemd
  • Unit files
  • Service accounts

Tools

Linux VM

Resources

Networking

Inspect interfaces, sockets and local network configuration on a Linux host.

Recommended level: Beginner

Suggested prerequisites: Networking, Linux Fundamentals

Concepts

  • Interfaces
  • Listening sockets
  • Routes

Tools

Linux VM

Resources

Bash

Automate repeatable administration tasks while handling input and errors carefully.

Recommended level: Beginner

Suggested prerequisites: Linux Fundamentals

Concepts

  • Pipelines
  • Variables
  • Exit codes

Tools

Bash

Resources

Logs

Find relevant host logs and correlate events without losing timestamp context.

Recommended level: Beginner

Suggested prerequisites: Services

Concepts

  • journalctl
  • Authentication logs
  • Time zones

Tools

Linux VM

Resources

Windows

Windows

Learn Windows administration, identity and event collection before investigating enterprise environments.

Recommended level: Beginner

Suggested prerequisites: Operating Systems

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Windows VM

Resources

Windows Fundamentals

Identify normal Windows components and use built-in administrative tools to inspect a host.

Recommended level: Beginner

Suggested prerequisites: Windows

Concepts

  • Accounts
  • Filesystem
  • Administrative tools

Tools

Windows VM

Resources

Active Directory

Understand how a directory organizes identities, computers and trust in an enterprise.

Recommended level: Beginner

Suggested prerequisites: Windows Fundamentals, DNS

Concepts

  • Domains
  • Domain controllers
  • Kerberos

Tools

Windows VM

Resources

PowerShell

Use structured objects and safe scripts to query and administer Windows.

Recommended level: Beginner

Suggested prerequisites: Windows Fundamentals

Concepts

  • Cmdlets
  • Pipelines
  • Execution context

Tools

PowerShell

Resources

Windows Services

Inspect service accounts and startup behavior to distinguish expected from unusual activity.

Recommended level: Beginner

Suggested prerequisites: Windows Fundamentals

Concepts

  • Service Control Manager
  • Startup types
  • Service identities

Tools

Windows VM

Resources

Registry

Navigate the configuration store and understand how changes affect system behavior.

Recommended level: Beginner

Suggested prerequisites: Windows Fundamentals

Concepts

  • Hives
  • Keys and values
  • Persistence locations

Tools

Windows VM

Resources

Event Logs

Find Windows events and interpret their fields in the context of host activity.

Recommended level: Beginner

Suggested prerequisites: Windows Fundamentals

Concepts

  • Channels
  • Event IDs
  • Audit policy

Tools

Event Viewer

Resources

Group Policy

Trace how centrally managed settings reach domain users and computers.

Recommended level: Beginner

Suggested prerequisites: Active Directory

Concepts

  • GPOs
  • Scope and inheritance
  • Policy processing

Tools

Windows VM

Resources

Authentication

Compare Windows authentication mechanisms and recognize the logs they produce.

Recommended level: Beginner

Suggested prerequisites: Active Directory

Concepts

  • Kerberos
  • NTLM
  • Logon types

Tools

Windows VM

Resources

Security Fundamentals

Security Fundamentals

Connect technical foundations with identity, risk and defensive controls. From here, choose one or more specialties.

Recommended level: Beginner

Suggested prerequisites: Linux, Windows

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

No dedicated tool required

Resources

CIA Triad

Describe a security requirement in terms of confidentiality, integrity and availability.

Recommended level: Beginner

Suggested prerequisites: Security Fundamentals

Concepts

  • Confidentiality
  • Integrity
  • Availability

Tools

No dedicated tool required

Resources

Authentication

Explain how a system verifies an identity and what can weaken that assurance.

Recommended level: Beginner

Suggested prerequisites: Security Fundamentals

Concepts

  • Identity proof
  • Credentials
  • Session lifecycle

Tools

No dedicated tool required

Resources

Authorization

Separate identity verification from decisions about what an identity may do.

Recommended level: Beginner

Suggested prerequisites: Authentication

Concepts

  • Access decisions
  • Least privilege
  • Role-based access

Tools

No dedicated tool required

Resources

IAM

Understand how organizations create, review and retire access across systems.

Recommended level: Beginner

Suggested prerequisites: Authentication, Authorization

Concepts

  • Joiner-mover-leaver
  • Access reviews
  • Federation

Tools

No dedicated tool required

Resources

MFA

Compare authentication factors and understand how recovery and user experience affect protection.

Recommended level: Beginner

Suggested prerequisites: Authentication

Concepts

  • Knowledge, possession, inherence
  • Phishing resistance
  • Recovery

Tools

No dedicated tool required

Resources

Cryptography

Explain the purpose of encryption and signatures without inventing cryptographic schemes.

Recommended level: Beginner

Suggested prerequisites: Security Fundamentals

Concepts

  • Symmetric and asymmetric encryption
  • Keys
  • Digital signatures

Tools

No dedicated tool required

Resources

Hashing

Distinguish a fingerprint from encryption and recognize the need for dedicated password hashing.

Recommended level: Beginner

Suggested prerequisites: Cryptography

Concepts

  • Integrity checks
  • Collisions
  • Password hashing

Tools

No dedicated tool required

Resources

PKI

Trace how certificates bind identities to keys and how trust can be revoked.

Recommended level: Beginner

Suggested prerequisites: Cryptography, TLS

Concepts

  • Certificate chains
  • Trust anchors
  • Revocation

Tools

No dedicated tool required

Resources

Vulnerability Management

Turn findings into a repeatable process for prioritization, remediation and verification.

Recommended level: Beginner

Suggested prerequisites: Security Fundamentals

Concepts

  • Asset inventory
  • Risk prioritization
  • Remediation

Tools

No dedicated tool required

Resources

CVE / CVSS

Distinguish a vulnerability identifier from a severity score and add environmental context.

Recommended level: Beginner

Suggested prerequisites: Vulnerability Management

Concepts

  • Identifiers
  • Severity metrics
  • Exposure

Tools

No dedicated tool required

Resources

Security Hardening

Reduce unnecessary functionality and verify that secure settings remain effective.

Recommended level: Beginner

Suggested prerequisites: Linux, Windows

Concepts

  • Baseline configuration
  • Attack surface
  • Configuration drift

Tools

No dedicated tool required

Resources

MITRE ATT&CK

Use documented adversary behavior to organize observations and identify coverage gaps.

Recommended level: Beginner

Suggested prerequisites: Security Fundamentals

Concepts

  • Tactics
  • Techniques
  • Evidence mapping

Tools

No dedicated tool required

Resources

SOC Analyst

SOC Analyst

Turn telemetry into decisions: investigate alerts, build detections and help coordinate a measured response.

Recommended level: Intermediate

Suggested prerequisites: Security Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Splunk, Microsoft Sentinel, Elastic, QRadar, CrowdStrike, Microsoft Defender

Resources

SOC Fundamentals

Understand how people, processes and telemetry combine to support security operations.

Recommended level: Intermediate

Suggested prerequisites: SOC Analyst

Concepts

  • Roles and handoffs
  • Escalation
  • Service metrics

Tools

No dedicated tool required

Resources

SIEM

Collect and normalize security events so analysts can search, correlate and investigate them.

Recommended level: Intermediate

Suggested prerequisites: SOC Fundamentals

Concepts

  • Ingestion
  • Parsing
  • Correlation

Tools

Splunk, Microsoft Sentinel, Elastic, QRadar

Resources

Log Analysis

Ask a specific question of logs and preserve the context needed to interpret the answer.

Recommended level: Intermediate

Suggested prerequisites: SIEM

Concepts

  • Field interpretation
  • Baselines
  • Time correlation

Tools

No dedicated tool required

Resources

Windows Event Logs

Choose useful Windows event sources and interpret logon, process and policy activity.

Recommended level: Intermediate

Suggested prerequisites: Event Logs, Log Analysis

Concepts

  • Audit policy
  • Logon events
  • Collection coverage

Tools

No dedicated tool required

Resources

Sysmon

Understand enriched Windows telemetry and tune collection to the environment.

Recommended level: Intermediate

Suggested prerequisites: Windows Event Logs

Concepts

  • Process creation
  • Network connections
  • Configuration rules

Tools

Sysmon

Resources

Detection Engineering

Design and test detections against observable behavior, including their blind spots.

Recommended level: Intermediate

Suggested prerequisites: Log Analysis, MITRE ATT&CK

Concepts

  • Detection hypotheses
  • Test cases
  • False positives

Tools

No dedicated tool required

Resources

Sigma

Read portable detection logic and validate how a backend translates it into a query.

Recommended level: Intermediate

Suggested prerequisites: Detection Engineering

Concepts

  • Log sources
  • Conditions
  • Backend conversion

Tools

Sigma

Resources

Alert Triage

Assess urgency and confidence before deciding whether to escalate an alert.

Recommended level: Intermediate

Suggested prerequisites: Log Analysis

Concepts

  • Context gathering
  • Severity
  • Escalation

Tools

No dedicated tool required

Resources

Incident Response

Help contain an incident while recording evidence and coordinating the next steps.

Recommended level: Intermediate

Suggested prerequisites: Alert Triage

Concepts

  • Containment
  • Communication
  • Recovery

Tools

No dedicated tool required

Resources

Threat Hunting

Test a hypothesis about activity that existing alerts may not detect.

Recommended level: Intermediate

Suggested prerequisites: Detection Engineering

Concepts

  • Hypothesis
  • Data requirements
  • Documented findings

Tools

No dedicated tool required

Resources

EDR

Use endpoint telemetry and response controls while considering sensor coverage and side effects.

Recommended level: Intermediate

Suggested prerequisites: Windows, Linux

Concepts

  • Endpoint visibility
  • Investigation
  • Response actions

Tools

CrowdStrike, Microsoft Defender

Resources

Network Detection

Identify suspicious network behavior using traffic metadata and available packet evidence.

Recommended level: Intermediate

Suggested prerequisites: Networking, Log Analysis

Concepts

  • Flow data
  • Protocol anomalies
  • Encrypted traffic limits

Tools

Wireshark, Zeek

Resources

Email Security

Investigate suspicious messages using headers, authentication results and user context.

Recommended level: Intermediate

Suggested prerequisites: DNS, HTTP / HTTPS

Concepts

  • Message headers
  • SPF, DKIM, DMARC
  • Phishing triage

Tools

No dedicated tool required

Resources

Digital Forensics & Incident Response

Digital Forensics & Incident Response

Reconstruct what happened from evidence, preserve its integrity and support a defensible response.

Recommended level: Intermediate

Suggested prerequisites: Security Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Volatility, Autopsy, Wireshark, Velociraptor

Resources

Incident Response

Plan investigation and containment as coordinated activities rather than isolated tool actions.

Recommended level: Intermediate

Suggested prerequisites: Digital Forensics & Incident Response

Concepts

  • Preparation
  • Containment
  • Recovery

Tools

No dedicated tool required

Resources

Evidence Collection

Choose a collection method that preserves useful data and records its provenance.

Recommended level: Intermediate

Suggested prerequisites: Incident Response

Concepts

  • Chain of custody
  • Volatile evidence
  • Integrity checks

Tools

No dedicated tool required

Resources

Disk Forensics

Interpret a forensic image and distinguish filesystem artifacts from conclusions.

Recommended level: Intermediate

Suggested prerequisites: Evidence Collection

Concepts

  • Images
  • Filesystem metadata
  • Deleted data limits

Tools

Autopsy

Resources

Memory Forensics

Use memory evidence to investigate runtime state that disk evidence may miss.

Recommended level: Intermediate

Suggested prerequisites: Evidence Collection

Concepts

  • Processes
  • Memory acquisition
  • Artifact interpretation

Tools

Volatility

Resources

Network Forensics

Reconstruct network activity while accounting for missing packets and encryption.

Recommended level: Intermediate

Suggested prerequisites: Evidence Collection, Networking

Concepts

  • PCAP
  • Flows
  • Session reconstruction

Tools

Wireshark

Resources

Timeline Analysis

Combine sources into a timeline while preserving clock differences and uncertainty.

Recommended level: Intermediate

Suggested prerequisites: Disk Forensics, Event Logs

Concepts

  • Timestamp semantics
  • Clock skew
  • Event correlation

Tools

No dedicated tool required

Resources

Windows Forensics

Correlate Windows artifacts with account, application and execution history.

Recommended level: Intermediate

Suggested prerequisites: Windows, Evidence Collection

Concepts

  • Registry artifacts
  • Event logs
  • Filesystem artifacts

Tools

Velociraptor

Resources

Linux Forensics

Investigate Linux host activity using logs, filesystem artifacts and service configuration.

Recommended level: Intermediate

Suggested prerequisites: Linux, Evidence Collection

Concepts

  • Authentication logs
  • Shell artifacts
  • Service changes

Tools

No dedicated tool required

Resources

Malware Triage

Collect safe initial observations about a suspicious file and decide what analysis is needed next.

Recommended level: Intermediate

Suggested prerequisites: Evidence Collection, Hashing

Concepts

  • File identification
  • Hashes
  • Safe handling

Tools

No dedicated tool required

Resources

Cyber Threat Intelligence

Cyber Threat Intelligence

Connect observations to a clear intelligence question. Track adversary behavior and turn uncertain evidence into useful assessments.

Recommended level: Intermediate

Suggested prerequisites: Security Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

VirusTotal, OpenCTI, MISP, Shodan

Resources

CTI Fundamentals

Define an intelligence requirement and produce an assessment that helps someone make a decision.

Recommended level: Intermediate

Suggested prerequisites: Cyber Threat Intelligence

Concepts

  • Intelligence cycle
  • Requirements
  • Confidence

Tools

No dedicated tool required

Resources

IOC

Treat indicators as contextual observations with a lifespan, not permanent proof of compromise.

Recommended level: Intermediate

Suggested prerequisites: CTI Fundamentals

Concepts

  • Indicator types
  • Context
  • Expiration

Tools

No dedicated tool required

Resources

TTP

Describe patterns of adversary behavior and separate them from individual infrastructure indicators.

Recommended level: Intermediate

Suggested prerequisites: CTI Fundamentals

Concepts

  • Tactics
  • Techniques
  • Procedures

Tools

No dedicated tool required

Resources

MITRE ATT&CK

Map a sourced observation to adversary behavior without overstating the evidence.

Recommended level: Intermediate

Suggested prerequisites: TTP, MITRE ATT&CK

Concepts

  • Technique mapping
  • Sources
  • Coverage

Tools

No dedicated tool required

Resources

OSINT

Gather public information with a defined question and record how reliable each source is.

Recommended level: Intermediate

Suggested prerequisites: CTI Fundamentals

Concepts

  • Source evaluation
  • Collection scope
  • Provenance

Tools

No dedicated tool required

Resources

Threat Actors

Compare behavior and reporting while separating actor labels from verified attribution.

Recommended level: Intermediate

Suggested prerequisites: TTP, OSINT

Concepts

  • Clustering
  • Aliases
  • Attribution uncertainty

Tools

No dedicated tool required

Resources

Campaign Tracking

Link related activity across time and describe what supports or weakens the relationship.

Recommended level: Intermediate

Suggested prerequisites: Threat Actors, IOC

Concepts

  • Activity clusters
  • Time windows
  • Confidence

Tools

No dedicated tool required

Resources

Malware Tracking

Track malware families using behavior and evidence rather than relying on a single vendor label.

Recommended level: Intermediate

Suggested prerequisites: IOC, TTP

Concepts

  • Family naming
  • Behavior
  • Sample relationships

Tools

No dedicated tool required

Resources

Infrastructure Tracking

Connect domains, addresses and certificates with explicit time and evidence boundaries.

Recommended level: Intermediate

Suggested prerequisites: IOC, DNS

Concepts

  • Infrastructure relationships
  • Time context
  • Shared hosting

Tools

No dedicated tool required

Resources

Domain Analysis

Evaluate a domain using registration, resolution and usage context without assuming that age proves intent.

Recommended level: Intermediate

Suggested prerequisites: DNS, OSINT

Concepts

  • Registration
  • DNS history
  • Hosting context

Tools

VirusTotal

Resources

URL Analysis

Separate a URL into components and assess redirects, hosting and observed behavior safely.

Recommended level: Intermediate

Suggested prerequisites: HTTP / HTTPS, OSINT

Concepts

  • URL structure
  • Redirects
  • Context

Tools

VirusTotal

Resources

IP Analysis

Interpret address ownership and observations while accounting for reassignment and shared services.

Recommended level: Intermediate

Suggested prerequisites: IPv4 / IPv6, OSINT

Concepts

  • ASN
  • Hosting
  • Time-sensitive context

Tools

Shodan

Resources

Passive DNS

Use historical resolutions to investigate relationships while recognizing collection gaps.

Recommended level: Intermediate

Suggested prerequisites: DNS, Infrastructure Tracking

Concepts

  • Observation windows
  • Record history
  • Coverage bias

Tools

No dedicated tool required

Resources

WHOIS / RDAP

Read registration data and understand privacy, availability and protocol differences.

Recommended level: Intermediate

Suggested prerequisites: Domain Analysis

Concepts

  • Registration records
  • RDAP
  • Data limitations

Tools

No dedicated tool required

Resources

YARA

Describe patterns in files with rules and validate their specificity against representative samples.

Recommended level: Intermediate

Suggested prerequisites: Hashing, Malware Tracking

Concepts

  • Strings
  • Conditions
  • Rule testing

Tools

YARA

Resources

Sigma

Translate intelligence about observable behavior into portable detection ideas.

Recommended level: Intermediate

Suggested prerequisites: TTP, Sigma

Concepts

  • Log sources
  • Detection conditions
  • Validation

Tools

Sigma

Resources

STIX

Represent intelligence as structured objects and relationships with provenance.

Recommended level: Intermediate

Suggested prerequisites: CTI Fundamentals

Concepts

  • Objects
  • Relationships
  • Markings

Tools

OpenCTI, MISP

Resources

TAXII

Understand how structured intelligence is exchanged and how clients discover collections.

Recommended level: Intermediate

Suggested prerequisites: STIX

Concepts

  • Collections
  • API transport
  • Authentication

Tools

No dedicated tool required

Resources

Threat Intelligence Platforms

Organize intelligence with consistent relationships, access controls and a clear publishing workflow.

Recommended level: Intermediate

Suggested prerequisites: STIX, TAXII

Concepts

  • Data model
  • Enrichment
  • Sharing policies

Tools

OpenCTI, MISP

Resources

Offensive Security

Offensive Security

Learn to assess security in systems you own or are explicitly authorized to test. Connect every finding to remediation.

Recommended level: Intermediate

Suggested prerequisites: Security Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

Burp Suite, Wireshark

Resources

Reconnaissance

Define scope and gather information that helps plan an authorized assessment.

Recommended level: Advanced

Suggested prerequisites: Offensive Security

Concepts

  • Rules of engagement
  • Asset discovery
  • Scope boundaries

Tools

No dedicated tool required

Resources

OSINT

Use public sources to understand an authorized target and document collection limits.

Recommended level: Advanced

Suggested prerequisites: Reconnaissance

Concepts

  • Source validation
  • Exposure
  • Responsible collection

Tools

No dedicated tool required

Resources

Enumeration

Identify services and configurations in a controlled environment and record observations accurately.

Recommended level: Advanced

Suggested prerequisites: Reconnaissance, Networking

Concepts

  • Service inventory
  • Configuration
  • Evidence

Tools

No dedicated tool required

Resources

Web Security

Understand how application trust boundaries can fail and how to test them in a lab.

Recommended level: Advanced

Suggested prerequisites: HTTP / HTTPS, Authorization

Concepts

  • Input handling
  • Sessions
  • Access control

Tools

No dedicated tool required

Resources

OWASP Top 10

Use a risk overview to guide learning without treating it as a complete testing checklist.

Recommended level: Advanced

Suggested prerequisites: Web Security

Concepts

  • Application risk categories
  • Root causes
  • Mitigation

Tools

No dedicated tool required

Resources

Burp Suite

Inspect and replay lab HTTP traffic to understand application behavior within an agreed scope.

Recommended level: Advanced

Suggested prerequisites: Web Security

Concepts

  • Intercepting proxy
  • Request analysis
  • Scope configuration

Tools

Burp Suite

Resources

Network Pentesting

Plan an authorized network assessment and connect observations to defensible findings.

Recommended level: Advanced

Suggested prerequisites: Enumeration, Networking

Concepts

  • Scope
  • Service exposure
  • Reporting

Tools

No dedicated tool required

Resources

Active Directory Attacks

Study directory attack paths in a lab and identify the controls that interrupt them.

Recommended level: Advanced

Suggested prerequisites: Active Directory, IAM

Concepts

  • Identity relationships
  • Trust boundaries
  • Defensive controls

Tools

No dedicated tool required

Resources

Privilege Escalation

Recognize conditions that allow more access than intended and validate fixes in a controlled lab.

Recommended level: Advanced

Suggested prerequisites: Permissions, Windows Services

Concepts

  • Permission mistakes
  • Service context
  • Least privilege

Tools

No dedicated tool required

Resources

Exploitation

Understand why a vulnerability is exploitable, using intentionally vulnerable labs and clear safety limits.

Recommended level: Advanced

Suggested prerequisites: Vulnerability Management, Enumeration

Concepts

  • Root cause
  • Lab isolation
  • Remediation validation

Tools

No dedicated tool required

Resources

Password Attacks

Study credential risks using synthetic lab accounts and compare preventive controls.

Recommended level: Advanced

Suggested prerequisites: Hashing, MFA

Concepts

  • Password storage
  • Rate limiting
  • MFA

Tools

No dedicated tool required

Resources

Post Exploitation

Understand potential impact in an authorized simulation and document cleanup and defensive lessons.

Recommended level: Advanced

Suggested prerequisites: Exploitation

Concepts

  • Impact assessment
  • Scope limits
  • Cleanup

Tools

No dedicated tool required

Resources

Malware Analysis

Malware Analysis

Examine suspicious software in an isolated environment and explain its behavior with evidence.

Recommended level: Intermediate

Suggested prerequisites: Security Fundamentals

Concepts

  • Purpose and scope
  • A practical learning plan

Tools

REMnux, Ghidra, YARA

Resources

Malware Fundamentals

Distinguish malicious behavior from labels and define an analysis question before opening a sample.

Recommended level: Advanced

Suggested prerequisites: Malware Analysis

Concepts

  • Behavior
  • Safe handling
  • Analysis goals

Tools

No dedicated tool required

Resources

Static Analysis

Inspect a file without running it and separate useful clues from unverified assumptions.

Recommended level: Advanced

Suggested prerequisites: Malware Fundamentals, Hashing

Concepts

  • File type
  • Strings
  • Imports

Tools

No dedicated tool required

Resources

Dynamic Analysis

Observe a sample in an isolated lab while controlling network access and preserving the baseline.

Recommended level: Advanced

Suggested prerequisites: Malware Fundamentals, Virtualization

Concepts

  • Isolation
  • Behavior monitoring
  • Snapshots

Tools

No dedicated tool required

Resources

Sandboxing

Understand what automated analysis can reveal and where its coverage stops.

Recommended level: Advanced

Suggested prerequisites: Dynamic Analysis

Concepts

  • Detonation environment
  • Evasion
  • Report interpretation

Tools

No dedicated tool required

Resources

Reverse Engineering

Read program structure to explain behavior, beginning with small educational binaries.

Recommended level: Advanced

Suggested prerequisites: Static Analysis

Concepts

  • Assembly basics
  • Control flow
  • Functions

Tools

Ghidra

Resources

PE Files

Identify Windows executable structures and how sections and imports support analysis.

Recommended level: Advanced

Suggested prerequisites: Windows Fundamentals, Static Analysis

Concepts

  • Headers
  • Sections
  • Import table

Tools

No dedicated tool required

Resources

Obfuscation

Recognize transformations that make code harder to inspect and document their effect on confidence.

Recommended level: Advanced

Suggested prerequisites: Static Analysis, Reverse Engineering

Concepts

  • Packing
  • Encoding
  • Control-flow changes

Tools

No dedicated tool required

Resources

Persistence

Identify mechanisms that restore execution and connect them to host artifacts and detection.

Recommended level: Advanced

Suggested prerequisites: Windows Services, Services

Concepts

  • Startup locations
  • Services
  • Scheduled tasks

Tools

No dedicated tool required

Resources

Command & Control

Characterize communication behavior from controlled observations and distinguish facts from hypotheses.

Recommended level: Advanced

Suggested prerequisites: Networking, Dynamic Analysis

Concepts

  • Protocols
  • Timing
  • Infrastructure

Tools

No dedicated tool required

Resources

YARA

Build and test file-matching rules against benign and malicious examples in an isolated workflow.

Recommended level: Advanced

Suggested prerequisites: Static Analysis

Concepts

  • Strings
  • Conditions
  • False positives

Tools

YARA

Resources

Before you start

Concepts to know

Tools & technologies

Learning resources

Go at your own pace. Prerequisites are suggested knowledge, not locked gates.