On-screen text
want a
Cybersecurity
roadmap?
here's how you become cracked :p you
don't even need a degree
>>>
+ save to reference later
cybersecurity is vast
pick your niche
pentesting / ethical hacking
blue team / defence / SOC
cloud security
malware analysis / reverse
engineering
bug bounty
they require diff skills.
pick one direction or youll
learn everything and know
nothing 😭
before you specialise, you need to
learn
foundations
how networking works
(TCP/IP, DNS, HTTP)
linux. just linux. live in
the terminal
basic scripting (python,
bash, powershell)
how the web works
(HTTP requests,
cookies, auth)
you'll need
resources
free
tryhackme (literally
start here, so beginner
friendly)
hackthebox (once you
got some basics)
professor messer
(networking +
security+)
overthewire (linux + ctf
fundamentals)
paid
tcm security courses
(affordable and actually
good)
portswigger web
academy (free actually
AND the best for web
hacking)
certificates that matter
entry level
comptia security+
(industry standard, get
this first)
comptia network+ (if
your networking is
weak)
advanced
OSCP (the gold standard
for pentesting, hard af)
CISSP (management/
enterprise track)
mid-level
CEH (controversial but
some employers want it)
eJPT (practical, cheap,
actually respected)
you cannot learn cybersec just be ingesting content
build your homelab!
virtualbox or vmware
(free)
spin up kali linux + a
vulnerable VM
(metasploitable,
vulnhub)
hack your own stuff
legally before you hack
anything else
a homelab on your cv is
more impressive than
10 udemy certs
for my
pentester's
tryhackme -> hackthebox -> CTF
competitions -> bug bounty -> OSCP
tools:
nmap, burpsuite, metasploit, wireshark
don't just run tools, understand what they're doing
for my
blue teamers
security+ -> SOC analyst role -> splunk/
SIEM tools -> threat hunting
platforms:
blueteamlabs.online
cyberdefenders.org
lets defend
pentesting isn't the
only job, there's more
that pay well and are
stable
bug bounties
this brings moneyyyyy
hackerone and
bugcrowd are where you first bug bounty
start
could take
months but when
you do one, you
could generate 6
figures off of
them alone
portsWigger web
academy first or you
will get destroyed
learn OWASP top 10
like your life depends on
it
you need
visibility
document everything on
github (scripts,
writeups, tools)
recruiters in cybersec
actively hunt people.
make yourself findable
write CTF writeups on
medium or a blog
do HTB/THM and post
your methodology
linkedin is actually
useful in cybersec
surprisingly
here's your
timeline
to follow:
0-3 months: networking, linux, python basics,
tryhackme
3-6 months: security+, home lab, pick ur lane
6-12 months: HTB, specialise, first cert in your lane
12-18 months: job ready or first bug bounty
dont let anyone tell you it takes years
you got this, and if you dedicate
yourself to it, your roadmap and
timeline will be quicker!!