LEARNING RESOURCES

Learn. Practice.
Build Skills.

A curated collection of learning platforms, documentation, courses, tools, and practical labs organized around the cybersecurity roadmap.

01 / LEARNING PATH

Resources arranged by stage.

Follow the roadmap progressively instead of trying to learn every cybersecurity topic at once.

01Foundation
06Security
08Web
13Ethical Hacking
28Pentesting
31Specialization
02 / STAGE RESOURCES

Choose a topic. Start learning.

Each topic contains recommended learning resources and practical environments.

🖥️
Stage 01

Computer Fundamentals

Build a strong foundation in computer systems, operating systems, hardware, and basic IT concepts.

LEARN
Professor MesserCiscoMicrosoft Learn
PRACTICE
VirtualBoxVMware
🌐
Stage 02

Networking

Understand networking concepts, protocols, communication, addressing, and network analysis.

LEARN
Cisco Networking AcademyProfessor Messer
PRACTICE
WiresharkCisco Packet Tracer
🐧
Stage 03

Linux

Learn Linux fundamentals, command-line usage, filesystem concepts, permissions, and administration.

LEARN
Linux JourneyOverTheWire
PRACTICE
Kali LinuxLinux VM
🪟
Stage 04

Windows

Understand Windows administration, security concepts, PowerShell, and Windows environments.

LEARN
Microsoft LearnProfessor Messer
PRACTICE
Windows VM
🐍
Stage 05

Python

Learn Python programming and apply it to automation, scripting, and cybersecurity tasks.

LEARN
Python DocumentationfreeCodeCamp
PRACTICE
Security Automation
💻
Stage 05

Bash & PowerShell

Develop command-line and scripting skills for Linux and Windows security environments.

LEARN
Linux JourneyMicrosoft Learn
PRACTICE
Bash ScriptsPowerShell Scripts
🔐
Stage 06

Cybersecurity Fundamentals

Build an understanding of security principles, threats, vulnerabilities, controls, and defensive concepts.

LEARN
Professor MesserCisco
PRACTICE
TryHackMe
🔑
Stage 07

Cryptography

Explore encryption, hashing, encoding, cryptographic concepts, and practical challenges.

LEARN
CryptoHackProfessor Messer
PRACTICE
Crypto Challenges
🌐
Stage 08

Web Security

Learn modern web security concepts and practice identifying vulnerabilities in controlled environments.

LEARN
PortSwigger Web Security Academy
PRACTICE
Burp Suite
🔌
Stage 09

API Security

Understand API architecture, authentication, authorization, common vulnerabilities, and API testing.

LEARN
PortSwiggerOWASP
PRACTICE
PostmanBurp Suite
🔎
Stage 10

Reconnaissance

Learn reconnaissance concepts and information gathering within authorized security assessments.

LEARN
TryHackMeHTB Academy
PRACTICE
Authorized Labs
🛡️
Stage 12

Vulnerability Assessment

Understand vulnerability discovery, assessment, prioritization, and security validation.

LEARN
Nessus DocumentationGreenbone Documentation
PRACTICE
Lab Machines
⚔️
Stage 13

Ethical Hacking

Learn ethical hacking methodologies and practice security testing in controlled environments.

LEARN
TryHackMeHTB Academy
PRACTICE
CTF LabsAuthorized Labs
🎯
Stage 28

Penetration Testing

Learn professional penetration-testing methodology, assessment workflows, and reporting.

LEARN
HTB AcademyTryHackMe
PRACTICE
Vulnerable VMs
🐧
Stage 15

Linux Privilege Escalation

Study Linux privilege boundaries and common privilege-escalation concepts in authorized labs.

LEARN
HTB AcademyTryHackMe
PRACTICE
Linux Labs
🪟
Stage 17

Windows & Active Directory

Explore Windows security, Active Directory concepts, identity, authentication, and enterprise environments.

LEARN
HTB AcademyTryHackMe
PRACTICE
AD Labs
☁️
Stage 21

Cloud Security

Build cloud security knowledge across identity, infrastructure, services, and cloud environments.

LEARN
AWS Skill BuilderMicrosoft LearnGoogle Cloud Skills
PRACTICE
Cloud Labs
🔵
Stage 26

Blue Team

Learn defensive security, monitoring, detection, SIEM concepts, threat hunting, and incident response.

LEARN
Microsoft LearnSplunk TrainingTryHackMe
PRACTICE
SIEM LabsLog Analysis
🦠
Stage 23

Malware Analysis & Reverse Engineering

Explore malware behavior, analysis techniques, reverse engineering, and debugging concepts.

LEARN
Malware UnicornOpenSecurityTraining
PRACTICE
Ghidra Labs
🔬
Stage 27

Vulnerability Research

Develop deeper vulnerability-research skills using security research resources and legal testing environments.

LEARN
PortSwiggerGoogle VRP Resources
PRACTICE
Legal Research Labs
03 / CORE PLATFORMS

The platforms worth knowing.

These platforms cover a large portion of the practical and theoretical learning journey.

🎯
Hands-on Learning

TryHackMe

Beginner-friendly structured learning with guided cybersecurity rooms and practical exercises.

Explore Resource
Technical Learning

Hack The Box Academy

Deeper technical modules and realistic hands-on environments after building the fundamentals.

Explore Resource
🌐
Web & API Security

PortSwigger Web Security Academy

A focused learning resource for web vulnerabilities, API security, and Burp Suite-based testing.

Explore Resource
Linux & Security

OverTheWire

Practical command-line and security challenges for developing Linux fundamentals.

Explore Resource
🛡️
Web Security

OWASP

Security standards, web application security concepts, and secure-development resources.

Explore Resource
🌐
Networking

Cisco Networking Academy

Networking-focused learning resources for building a strong infrastructure foundation.

Explore Resource
🪟
Microsoft & Cloud

Microsoft Learn

Resources covering Windows, PowerShell, Azure, identity, and defensive security.

Explore Resource
☁️
Cloud

AWS Skill Builder

AWS-focused learning resources for developing cloud and cloud-security knowledge.

Explore Resource
🔑
Cryptography

CryptoHack

Practical cryptography challenges designed to reinforce cryptographic concepts.

Explore Resource
📚
Fundamentals

Professor Messer

Certification-oriented learning resources covering networking, security, and IT fundamentals.

Explore Resource
04 / PRACTICAL LABS

Build a safe security lab.

Practical cybersecurity learning should happen inside controlled and authorized environments. Use vulnerable applications, virtual machines, and dedicated training platforms to develop your skills safely.

Authorized Practice Only

Never test systems that you do not own or have explicit permission to assess.

LAB ENVIRONMENTISOLATED
01
Metasploitable

Intentionally vulnerable environment for controlled security practice.

02
OWASP Juice Shop

Deliberately insecure web application for learning web security.

03
DVWA

Damn Vulnerable Web Application for practicing web application security concepts.

04
WebGoat

OWASP educational environment for learning web application security.

05
VulnHub

Collection of vulnerable virtual machines for authorized security practice.

06
HTB Academy

Structured technical training with practical security environments.

07
TryHackMe

Guided rooms and practical cybersecurity learning environments.

05 / RECOMMENDED STACK

A simple path to follow.

01
Foundation

Cisco / Professor Messer + Linux Journey + Microsoft Learn

02
Cybersecurity

TryHackMe

03
Web Security

PortSwigger Academy + Burp Suite

04
Penetration Testing

HTB Academy + TryHackMe

05
Advanced

HTB + VulnHub + Self-Built Labs

06
Specialization

Web/API OR AD OR Cloud OR Red Team OR Blue Team

SUPPLEMENTARY RESOURCE

Use YouTube as a supporting resource.

YouTube can be useful when a difficult concept needs another explanation, but it should complement structured learning rather than replace it.

READY TO START?

Follow the roadmap. Build the skills.

Start from the fundamentals and progress toward the cybersecurity domain that interests you.