A YouTube-first, hands-on cybersecurity roadmap that takes a complete beginner from computer, networking, Linux and Windows foundations through security fundamentals, cryptography, network and web/API security, vulnerability management, offensive security and Active Directory, into defensive security: SOC, log analysis, SIEM (Splunk/Sentinel), threat intelligence, incident response, forensics and malware analysis — plus cloud security, DevSecOps, security automation, AI security and security architecture. Every stage pairs learning with authorized labs and a documented report, ending in a full end-to-end security capstone. All offensive practice uses only authorized, intentionally vulnerable or CTF environments.
Track your progress, earn XP, and pick up where you left off.
Milestone 01 (Computer & Networking Foundations) begins. Understand how computers work — CPU/RAM/storage, processes, filesystems, users, permissions and virtualization — and see them as an attack surface.
Systems, Processes & Attack Surface
Architecture, processes/threads, filesystems, users/permissions, virtualization; assets, services and attack surface.
~6h · 4 resources
The OSI/TCP-IP models, addressing, subnetting and the protocols that carry every attack and defense.
Models, Addressing & Subnetting
OSI/TCP-IP, Ethernet/MAC, IPv4/IPv6, subnetting, CIDR, routing/switching, ARP, ICMP, TCP/UDP.
~10h · 4 resources
Milestone 04 (First Network Investigation) target. DNS, HTTP(S), SSH, mail and more — and reading them on the wire.
Core Protocols & Packet Capture
DNS, DHCP, HTTP/HTTPS, SSH, FTP/SFTP, SMTP/IMAP/POP3, SNMP, NTP; ports, sockets and packet flow.
~8h · 8 resources
Milestone 02 (Linux + Windows) begins. The Linux command line, permissions, services, logs and SSH.
Command Line, Permissions & Services
Filesystem, terminal, core commands, permissions, users/groups, processes, services, packages, logs, SSH, cron, systemd.
~12h · 7 resources
Milestone 02 continues. Windows internals, the registry, PowerShell, Event Viewer and the security event IDs.
Windows Internals & Event Logs
Architecture, users/groups, services, registry, PowerShell, Defender, Event Viewer, Task Scheduler; event IDs 4624/4625/4688/4698/7045.
~10h · 5 resources
Automate security work with scripting across all three shells.
Scripting for Security
Python (files, JSON, requests, sockets, regex, subprocess), Bash (pipelines, grep/awk/sed, loops), PowerShell (objects, pipelines).
~12h · 13 resources
Milestone 03 (Security Fundamentals). The CIA triad, AAA, least privilege, defense in depth, zero trust — and how attacks map to them.
Principles, Risk & Common Attacks
CIA triad, authn/authz/accounting, least privilege, defense in depth, zero trust; threat/vulnerability/risk/exploit/control; phishing, malware, ransomware, brute force, priv-esc, exfiltration, DoS.
~8h · 5 resources
Encryption, hashing, signatures, certificates and TLS — with the crucial distinction: encryption ≠ hashing.
Encryption, Hashing & PKI
Symmetric/asymmetric encryption, hashing, digital signatures, certificates, PKI, TLS/HTTPS; AES, RSA, ECC, SHA-256.
~8h · 3 resources
Firewalls, IDS/IPS, proxies, VPN, segmentation and monitoring — plus practical packet and traffic analysis.
Defenses, Monitoring & Traffic Analysis
Firewalls, IDS/IPS, proxies, VPN, segmentation, NAC, secure DNS, monitoring; packet and traffic analysis with Wireshark.
~8h · 4 resources
Host discovery, port/service/OS detection and enumeration — demonstrated only against authorized systems.
Scanning & Enumeration (authorized only)
Host discovery, port scanning, service/OS detection, NSE concepts, scan types and enumeration.
~6h · 5 resources
Milestone 05 (First Vulnerability Assessment). CVE/CVSS, scanning, prioritization and remediation.
CVEs, Scanning & Remediation
Vulnerabilities, CVE, CVSS, asset inventory, scanning, risk prioritization, remediation and patch management.
~8h · 5 resources
How the web actually works — the foundation for web security.
HTTP, Sessions & the Request Lifecycle
Browsers, servers, HTTP/HTTPS, cookies, sessions, headers, authentication, APIs, REST, JSON, databases.
~6h · 5 resources
Milestone 06 (Web Security Assessment). The OWASP Top 10 with hands-on PortSwigger labs.
OWASP Top 10 & Hands-on Labs
Broken access control, crypto failures, injection, insecure design, misconfiguration, vulnerable components, auth failures, integrity failures, logging/monitoring failures, SSRF.
~14h · 10 resources
Secure REST APIs: authn/authz, JWT/OAuth, rate limiting and the OWASP API Top 10.
API Auth & the OWASP API Top 10
API keys, JWT, OAuth concepts, rate limiting, input validation, object-level authorization, excessive data exposure.
~8h · 5 resources
The web tester's core tool — proxy, repeater and analysis, used only on legal targets.
Proxy, Repeater & Request Analysis
Proxy, repeater, intruder concepts, decoder, HTTP history, request modification and response analysis.
~6h · 4 resources
Milestone 07 (First Penetration Testing Lab). The pentest methodology end to end — in authorized labs only.
Recon → Exploit → Report (labs only)
Reconnaissance, enumeration, vulnerability discovery, exploitation concepts, privilege escalation, post-exploitation concepts and reporting.
~14h · 9 resources
Domains, Kerberos, LDAP and Group Policy — plus the misconfigurations attackers abuse (in authorized labs).
AD, Kerberos & Common Misconfigurations
Domains, domain controllers, users/groups/OUs, Kerberos, LDAP, NTLM, Group Policy; priv-esc, credential attacks and lateral-movement concepts.
~10h · 3 resources
Milestone 08 (SOC Fundamentals). The SOC workflow: alert → triage → investigate → contain → recover → lessons learned.
SOC Workflow & Triage
SOC roles, alerts, incidents, detection, triage, investigation, containment, eradication, recovery.
~8h · 4 resources
Reconstruct what happened from logs across hosts, network, web, DNS and cloud.
Timelines from Logs
Authentication, process, firewall, web, DNS, endpoint and cloud logs; reconstructing a timeline.
~8h · 5 resources
Milestone 09 (SIEM Investigation). Splunk (SPL) and Microsoft Sentinel (KQL). After this stage, learners can choose a SPECIALIZATION: Blue Team, Red Team, AppSec, Cloud Security or AI Security — the main roadmap continues in common.
Splunk (SPL) & Microsoft Sentinel (KQL)
Log ingestion, normalization, searches, dashboards, alerts, correlation and detection rules; SPL and KQL fundamentals.
~12h · 7 resources
IOCs, TTPs and threat actors, organized with MITRE ATT&CK and enriched with VirusTotal.
IOCs, TTPs & MITRE ATT&CK
IOC types (IP/domain/URL/hash), TTPs, threat actors, campaigns and attribution concepts; MITRE ATT&CK and enrichment.
~8h · 3 resources
Milestone 10 (Incident Response). The NIST IR lifecycle applied to realistic scenarios.
The IR Lifecycle & Scenarios
Preparation, identification, containment, eradication, recovery, lessons learned; phishing, malware, brute force, suspicious login, ransomware, exfiltration.
~10h · 4 resources
Evidence handling and artifact analysis across disk, memory, browser and logs.
Disk, Memory & Timeline Forensics
Forensic principles, evidence handling, disk/memory/browser artifacts, event logs, timeline analysis and file metadata.
~10h · 3 resources
Static and dynamic triage of samples — only in isolated, provided lab environments.
Static & Dynamic Triage (isolated labs only)
Malware types, static analysis, dynamic analysis, hashes, strings, PE files, sandboxing, indicators and behavioral analysis.
~8h · 3 resources
Milestone 11 (Cloud Security). IAM, storage/network security, logging and misconfiguration on AWS and Azure.
IAM, Misconfiguration & Cloud Logging
IAM, roles/policies, storage/network security, security groups, logging/monitoring, secrets, encryption and cloud misconfiguration.
~10h · 5 resources
Shift security left: secure SDLC, code/dependency scanning and CI/CD security.
Secure SDLC, SAST/DAST & CI/CD Security
Secure SDLC, threat modeling, code review, dependency scanning, SAST, DAST, secrets scanning, container security and CI/CD security.
~10h · 9 resources
Milestone 12 (Security Automation). Build a Python toolkit for SOC/analyst workflows.
Building a Security Operations Toolkit
IOC parser, log parser, IP reputation checker, hash lookup, alert enrichment and simple incident automation.
~10h · 5 resources
Securing LLM/RAG applications: prompt injection, insecure tool use, excessive agency and the AI supply chain.
LLM/RAG Security & MITRE ATLAS
LLM security, prompt injection, jailbreaks, sensitive-info disclosure, insecure tool use, excessive agency, RAG security, model supply chain and AI threat modeling.
~8h · 4 resources
Design secure architectures: zero trust, identity, segmentation, logging and detection.
Secure Architecture & Zero Trust
Security architecture, zero trust, identity, segmentation, logging/SIEM/detection architecture, endpoint & cloud security, secrets, DR and backup security.
~10h · 4 resources
Milestone 14 (Final Cybersecurity Capstone). Build one complete security environment: network → web app/API → cloud → logs → SIEM → detection → alerts → incident response, with a vulnerability assessment and a full report. Milestone 13 (Specialization Project) should also be completed.
End-to-End Security Environment
Network architecture, Linux + Windows hosts, a web app with auth, logging, vulnerability assessment, SIEM, detection rules, an incident investigation, a report and remediation.
~40h · 6 resources