CyberPath
PathsDomainsLibraryPracticeAbout
Begin →
CyberPath

A living cybersecurity learning directory. Pricing and availability change; verify on the provider page before enrolling.

Explore

Learning pathsDomainsCourse library

Practice

Weekly planCertificationsStrategy

Site

AboutDisclosurePrivacyContact
ReviewedMay 27, 2026cyberpath.mistan.dev
Issue 01 · Updated May 27, 2026

A field guide to cybersecurity careers.

23 domains, 7 job-ready paths, and a curated reading list of courses, labs, certifications, and weekly practice — set in plain English, kept honest.

Start here
  • →Foundations1-2 months
  • →SOC Analyst3-6 months
  • →Penetration Tester6-12 months
  • →Cloud Security4-8 months
New to the field? Start at the top.
23 Domains100+ Resources7 PathsFree + Paid
01 — Paths

Job-ready paths.

7 paths
First 30-60 days

Foundations

For absolute beginners before choosing a job track.

  • Networking, Linux, Windows, web, and CLI basics
  • Daily notes with commands, screenshots, and summaries
  • Practice OverTheWire, picoCTF, TryHackMe Pre Security

Certs. Security+, ISC2 CC, SC-900

Portfolio. Home lab diagram, Linux notes, 5 beginner lab writeups

1-2 months 25+
Build base
Blue team entry role

SOC Analyst

For learners targeting SOC, monitoring, and detection jobs.

  • Learn logs, SIEM, Windows events, Linux auth, and networking
  • Practice CyberDefenders, BTLO, LetsDefend, Malware Traffic Analysis
  • Build detections with Sigma, Splunk SPL, KQL, or Elastic

Certs. CySA+, SC-200, BTL1

Portfolio. 3 incident reports, 5 detection rules, SIEM dashboard screenshots

3-6 months 40+
Triage alerts
Offensive security

Penetration Tester

For ethical hacking, web testing, and pentest preparation.

  • Master networking, HTTP, Linux, scripting, and methodology
  • Practice PortSwigger, Hack The Box, TryHackMe, OWASP Juice Shop
  • Write reports with scope, impact, proof, and remediation

Certs. eJPT, PNPT, OSCP

Portfolio. 10 machine/lab writeups, 3 web vuln reports, tooling notes

6-12 months 50+
Practice legally
Cloud / platform security

Cloud Security

For AWS, Azure, GCP, IAM, containers, and cloud detection.

  • Pick one cloud first and learn IAM, logging, networking, and storage
  • Study AWS, Microsoft, or Google security docs and labs
  • Build least-privilege policies and cloud monitoring use cases

Certs. AWS Security Specialty, SC-200, CCSP

Portfolio. Cloud threat model, IAM review, logging pipeline, hardening checklist

4-8 months 35+
Secure cloud
Risk, audit, compliance

GRC Analyst

For governance, risk, policy, audits, and security program work.

  • Learn NIST CSF, CIS Controls, ISO 27001, SOC 2, and risk basics
  • Practice control mapping, evidence requests, and policy writing
  • Translate technical findings into business impact

Certs. Security+, CRISC, CISA, CISSP later

Portfolio. Risk register, policy sample, control map, audit evidence checklist

2-5 months 25+
Map controls
Investigation and response

DFIR / Threat Hunter

For incident response, forensics, malware triage, and hunting.

  • Learn Windows internals, memory, disk, endpoint, and network evidence
  • Practice 13Cubed, CyberDefenders, Malware Traffic Analysis, YARA
  • Build timelines and map activity to MITRE ATT&CK

Certs. GCIH, GCIA, GREM, SC-200

Portfolio. 2 forensic timelines, PCAP analysis, YARA rule, IR report

6-12 months 35+
Investigate
Securing AI & LLM systems

AI Security

For securing LLM apps, AI agents, and machine-learning pipelines.

  • Learn how LLM apps, RAG, and agents are built and exposed
  • Practice prompt injection, jailbreaks, and OWASP LLM Top 10 labs
  • Map AI threats with MITRE ATLAS and govern risk with the NIST AI RMF

Certs. Security+ base, AppSec fundamentals, vendor AI security badges

Portfolio. LLM app threat model, prompt-injection writeups, guardrail/eval demo

3-6 months 15+
Secure AI
02 — Domains

The whole field, mapped.

23 domains
Domain

Foundations

Computer basics, networking, Linux, Windows, web, and safe lab habits.

NetworkingLinuxWindows
View roadmap →
Domain

Web / AppSec

Secure web apps, APIs, client-side code, and auth flows.

HTTPOWASP Top 10Burp Suite
View roadmap →
Domain

Network Security

Understand packets, segmentation, firewalls, VPNs, and monitoring.

TCP/IPWiresharkNmap
View roadmap →
Domain

Cloud Security

Protect AWS, Azure, GCP, containers, identity, and cloud workloads.

IAMCSPMKubernetes
View roadmap →
Domain

DFIR

Investigate incidents, collect evidence, and rebuild attack timelines.

TriageSIEMForensics
View roadmap →
Domain

GRC

Governance, risk, compliance, policies, audits, and security programs.

RiskISO 27001SOC 2
View roadmap →
Domain

Threat Intelligence

Track adversaries, TTPs, campaigns, and intelligence requirements.

MITRE ATT&CKOSINTYARA
View roadmap →
Domain

Malware / Reverse Engineering

Analyze malicious code, behavior, packers, and exploit artifacts.

AssemblyGhidraDebugging
View roadmap →
Domain

Exploit Development

Find and weaponize memory corruption bugs in controlled lab environments.

CAssemblyGDB/WinDbg
View roadmap →
Domain

Red Team / Adversary Emulation

Plan authorized attack simulations that test detection, response, and resilience.

ATT&CKOPSECC2
View roadmap →
Domain

Security Engineering

Build secure systems, detection pipelines, automation, and guardrails.

Secure SDLCDetectionAutomation
View roadmap →
Domain

Product Security

Scale AppSec inside engineering teams with design reviews, code review, and paved roads.

Threat modelingCode reviewSDLC
View roadmap →
Domain

IAM

Manage identity, access, privileges, federation, and zero trust.

SSOOAuth/OIDCPAM
View roadmap →
Domain

Mobile Security

Assess Android and iOS apps, mobile APIs, storage, auth, and reverse engineering risks.

AndroidiOSFrida
View roadmap →
Domain

Privacy / Cryptography

Understand privacy engineering, applied cryptography, data protection, and secure protocols.

PrivacyCryptoProtocols
View roadmap →
Domain

AI / LLM Security

Secure LLM apps, AI agents, and ML systems against prompt injection, data poisoning, and model abuse.

Prompt injectionLLM Top 10AI red teaming
View roadmap →
Domain

AI-Augmented Defense

Use AI, LLMs, and machine learning to detect threats, triage alerts, hunt, and automate the SOC.

ML detectionSOC automationAnomaly detection
View roadmap →
Domain

Hardware / IoT

Attack and defend embedded devices, firmware, and IoT: extraction, hardware interfaces, and device pentests.

FirmwareUART/JTAGBinwalk
View roadmap →
Domain

Blockchain / Web3

Audit smart contracts and DeFi: reentrancy, oracle and flash-loan attacks, and on-chain security.

SolidityReentrancyDeFi
View roadmap →
Domain

Supply Chain Security

Secure the build pipeline and dependencies: SBOMs, artifact signing, provenance, and SLSA.

SBOMSLSASigstore
View roadmap →
Domain

Detection Engineering

Build, test, and tune detections as code: Sigma rules, ATT&CK coverage, and false-positive management.

SigmaDetection-as-codeATT&CK
View roadmap →
Domain

OT / ICS

Secure industrial systems, safety-critical networks, and control environments.

SCADAPLC basicsSegmentation
View roadmap →
Domain

Vulnerability Research

Discover, reproduce, root-cause, and responsibly report vulnerabilities.

FuzzingRoot causeCVE research
View roadmap →
Filter the library
03 — Library

Curated courses.

30 matches
CourseDomainLevelProviderFormatPriceActions
Pre SecurityNo-prior-experience path covering computers, networking, web basics, and cyber concepts.FoundationsBeginnerTryHackMeLearning pathFree + Paid
Open
Web Security AcademyInteractive web vulnerability labs from the creators of Burp Suite.Web / AppSecBeginnerPortSwiggerLabsFree
Open
Introduction to CybersecurityEntry-level overview of threats, career areas, and core security concepts.FoundationsBeginnerCisco Networking AcademyCourseFree
Open
Certified in Cybersecurity TrainingFoundational security training connected to the ISC2 CC credential.FoundationsBeginnerISC2Certification prepFree + Paid
Open
Google Cybersecurity CertificateCareer-oriented program with Linux, SQL, SIEM, Python, and incident response basics.FoundationsBeginnerCoursera / GoogleCoursePaid
Open
Security Learning PlanAWS security curriculum covering IAM, governance, compliance, and workload protection.Cloud SecurityIntermediateAWS Skill BuilderLearning pathFree + Paid
Open
Security Operations AnalystDefender, Sentinel, incident response, and threat mitigation modules.DFIRIntermediateMicrosoft LearnLearning pathFree
Open
Hack The Box AcademyHands-on modules for penetration testing, infrastructure, web, and blue-team skills.Web / AppSecIntermediateHack The BoxLabsFree + Paid
Open
Blue Team Labs OnlineDefensive investigations, logs, SOC workflows, and incident-response challenges.DFIRIntermediateBTLOLabsFree + Paid
Open
LetsDefend SOC TrainingSOC analyst simulations with alerts, cases, investigation, and escalation workflows.DFIRIntermediateLetsDefendLabsFree + Paid
Open
OpenSecurityTraining2Free low-level security, x86, exploitation, and reverse engineering courses.Malware / Reverse EngineeringProfessionalOST2CourseFree
Open
SANS Cybersecurity CoursesPremium practitioner training across DFIR, cloud, ICS, leadership, and offense.ProfessionalProfessionalSANS InstituteCoursePaid
Open
PEN-200 / OSCP PrepAdvanced penetration testing preparation connected to the OSCP certification.Web / AppSecProfessionalOffSecCertification prepPaid
Open
Practical Ethical HackingPractical pentesting methodology, Active Directory basics, web attacks, and reporting.Red Team / Adversary EmulationBeginnerTCM Security AcademyCoursePaid
Open
Learn Ethical Hacking From ScratchBeginner-friendly Udemy course covering lab setup, network attacks, web attacks, and common tools.Web / AppSecBeginnerUdemy / z SecurityCoursePaid
Open
Complete Introduction to Cybersecurity 2026Broad beginner introduction to IT, cybersecurity concepts, attacks, defenses, and next-step planning.FoundationsBeginnerUdemy / Grant CollinsCoursePaid
Open
Exploit Development for Linux (x86)Linux x86 assembly, stack overflows, shellcode, NX, ASLR, and basic ROP practice.Exploit DevelopmentIntermediateUdemyCoursePaid
Open
Hands-on Fuzzing and Exploit DevelopmentShort practical introduction to fuzzing and stack-based buffer overflow workflow.Exploit DevelopmentIntermediateUdemyCourseFree
Open
EXP-301 / OSEDAdvanced Windows user-mode exploit development and OSED preparation.Exploit DevelopmentProfessionalOffSecCertification prepPaid
Open
Malware Unicorn WorkshopsReverse engineering and malware analysis workshops with practical exercises.Malware / Reverse EngineeringIntermediateMalware UnicornCourseFree
Open
Web LLM AttacksInteractive labs on prompt injection and attacking LLM APIs, integrations, and tool use.AI / LLM SecurityBeginnerPortSwiggerLabsFree
Open
AI Security FundamentalsCore concepts for securing AI systems: AI risks, controls, governance, and responsible AI.AI / LLM SecurityBeginnerMicrosoft LearnLearning pathFree
Open
Enhance Security Operations with Security CopilotUse generative-AI prompts and agents (SC-5006) to triage incidents, hunt, and respond at machine speed.AI-Augmented DefenseIntermediateMicrosoft LearnLearning pathFree
Open
Machine Learning & Emerging Technologies in CybersecurityApply ML to intrusion detection and anomaly detection with hands-on labs in Security Onion and RapidMiner.AI-Augmented DefenseIntermediateCoursera / Johns HopkinsCourseFree + Paid
Open
SEC595: Applied Data Science and AI/MLBuild custom AI-driven detection: neural networks for malware, phishing, and behavioral analysis (70%+ labs).AI-Augmented DefenseProfessionalSANS InstituteCoursePaid
Open
Beginner’s Guide to IoT and Hardware HackingFoundational hardware and IoT hacking: UART, SPI, firmware extraction, and device security research.Hardware / IoTBeginnerTCM SecurityCoursePaid
Open
SEC556: IoT Penetration TestingAssess the full IoT ecosystem: hardware, firmware, radio, and network attack surfaces.Hardware / IoTProfessionalSANS InstituteCoursePaid
Open
Secureum BootcampSmart-contract security and audit bootcamp covering Solidity, the EVM, and DeFi vulnerability classes.Blockchain / Web3IntermediateSecureumLearning pathFree
Open
Securing Your Software Supply Chain with Sigstore (LFS182)Free course on signing, verifying, and proving provenance of artifacts with Sigstore (Cosign, Fulcio, Rekor).Supply Chain SecurityBeginnerLinux FoundationCourseFree
Open
Detection Engineering with SigmaWrite and operationalize Sigma detections using real logs (Sysmon, Zeek, CloudTrail) with a detection-as-code workflow.Detection EngineeringIntermediateApplied Network DefenseCoursePaid
Open
04 — Directory

Everything else worth reading.

179 entries

Courses are one lane. The directory also covers YouTube educators, practice labs, official documentation, tools, research blogs, podcasts, communities, and books.

CoursesFree + Paid

Pre Security

No-prior-experience path covering computers, networking, web basics, and cyber concepts.

Best first
TryHackMeFoundationsBeginner
Open
CoursesFree

Introduction to Cybersecurity

Entry-level overview of threats, career areas, and core security concepts.

Best firstJob-ready
Cisco Networking AcademyFoundationsBeginner
Open
CoursesFree + Paid

Certified in Cybersecurity Training

Foundational security training connected to the ISC2 CC credential.

Best first
ISC2FoundationsBeginner
Open
CoursesPaid

Google Cybersecurity Certificate

Career-oriented program with Linux, SQL, SIEM, Python, and incident response basics.

Best firstJob-readyNeeds lab
Coursera / GoogleFoundationsBeginner
Open
CoursesFree + Paid

Security Learning Plan

AWS security curriculum covering IAM, governance, compliance, and workload protection.

AWS Skill BuilderCloud SecurityIntermediate
Open
CoursesFree

Security Operations Analyst

Defender, Sentinel, incident response, and threat mitigation modules.

Job-ready
Microsoft LearnDFIRIntermediate
Open
CoursesFree + Paid

Hack The Box Academy

Hands-on modules for penetration testing, infrastructure, web, and blue-team skills.

Hands-on
Hack The BoxWeb / AppSecIntermediate
Open
CoursesFree + Paid

Blue Team Labs Online

Defensive investigations, logs, SOC workflows, and incident-response challenges.

BTLODFIRIntermediate
Open
CoursesFree + Paid

LetsDefend SOC Training

SOC analyst simulations with alerts, cases, investigation, and escalation workflows.

Job-ready
LetsDefendDFIRIntermediate
Open
CoursesFree

OpenSecurityTraining2

Free low-level security, x86, exploitation, and reverse engineering courses.

Advanced
OST2Malware / Reverse EngineeringProfessional
Open
CoursesPaid

SANS Cybersecurity Courses

Premium practitioner training across DFIR, cloud, ICS, leadership, and offense.

AdvancedNeeds lab
SANS InstituteProfessionalProfessional
Open
CoursesPaid

PEN-200 / OSCP Prep

Advanced penetration testing preparation connected to the OSCP certification.

Job-readyAdvanced
OffSecWeb / AppSecProfessional
Open
CoursesPaid

Practical Ethical Hacking

Practical pentesting methodology, Active Directory basics, web attacks, and reporting.

Best first
TCM Security AcademyRed Team / Adversary EmulationBeginner
Open
CoursesPaid

Learn Ethical Hacking From Scratch

Beginner-friendly Udemy course covering lab setup, network attacks, web attacks, and common tools.

Best firstHands-onNeeds lab
Udemy / z SecurityWeb / AppSecBeginner
Open
CoursesPaid

Complete Introduction to Cybersecurity 2026

Broad beginner introduction to IT, cybersecurity concepts, attacks, defenses, and next-step planning.

Best first
Udemy / Grant CollinsFoundationsBeginner
Open
CoursesPaid

Exploit Development for Linux (x86)

Linux x86 assembly, stack overflows, shellcode, NX, ASLR, and basic ROP practice.

Hands-on
UdemyExploit DevelopmentIntermediate
Open
CoursesFree

Hands-on Fuzzing and Exploit Development

Short practical introduction to fuzzing and stack-based buffer overflow workflow.

UdemyExploit DevelopmentIntermediate
Open
CoursesPaid

EXP-301 / OSED

Advanced Windows user-mode exploit development and OSED preparation.

Job-readyAdvanced
OffSecExploit DevelopmentProfessional
Open
CoursesFree

Malware Unicorn Workshops

Reverse engineering and malware analysis workshops with practical exercises.

Malware UnicornMalware / Reverse EngineeringIntermediate
Open
CoursesFree

Web LLM Attacks

Interactive labs on prompt injection and attacking LLM APIs, integrations, and tool use.

Best firstHands-onNeeds lab
PortSwiggerAI / LLM SecurityBeginner
Open
CoursesFree

AI Security Fundamentals

Core concepts for securing AI systems: AI risks, controls, governance, and responsible AI.

Best first
Microsoft LearnAI / LLM SecurityBeginner
Open
CoursesFree

Enhance Security Operations with Security Copilot

Use generative-AI prompts and agents (SC-5006) to triage incidents, hunt, and respond at machine speed.

Microsoft LearnAI-Augmented DefenseIntermediate
Open
CoursesFree + Paid

Machine Learning & Emerging Technologies in Cybersecurity

Apply ML to intrusion detection and anomaly detection with hands-on labs in Security Onion and RapidMiner.

Hands-onNeeds lab
Coursera / Johns HopkinsAI-Augmented DefenseIntermediate
Open
CoursesPaid

SEC595: Applied Data Science and AI/ML

Build custom AI-driven detection: neural networks for malware, phishing, and behavioral analysis (70%+ labs).

Hands-onAdvancedNeeds lab
SANS InstituteAI-Augmented DefenseProfessional
Open
CoursesPaid

Beginner’s Guide to IoT and Hardware Hacking

Foundational hardware and IoT hacking: UART, SPI, firmware extraction, and device security research.

Best first
TCM SecurityHardware / IoTBeginner
Open
CoursesPaid

SEC556: IoT Penetration Testing

Assess the full IoT ecosystem: hardware, firmware, radio, and network attack surfaces.

Advanced
SANS InstituteHardware / IoTProfessional
Open
CoursesFree

Secureum Bootcamp

Smart-contract security and audit bootcamp covering Solidity, the EVM, and DeFi vulnerability classes.

Needs lab
SecureumBlockchain / Web3Intermediate
Open
CoursesFree

Securing Your Software Supply Chain with Sigstore (LFS182)

Free course on signing, verifying, and proving provenance of artifacts with Sigstore (Cosign, Fulcio, Rekor).

Best first
Linux FoundationSupply Chain SecurityBeginner
Open
CoursesPaid

Detection Engineering with Sigma

Write and operationalize Sigma detections using real logs (Sysmon, Zeek, CloudTrail) with a detection-as-code workflow.

Needs lab
Applied Network DefenseDetection EngineeringIntermediate
Open
YouTubeFree

NetworkChuck

Networking, Linux, cloud, home labs, and security basics with approachable projects.

Best firstHands-onNeeds lab
YouTubeFoundationsBeginner
Open
YouTubeFree

Professor Messer

CompTIA A+, Network+, and Security+ video courses and study sessions.

Best firstJob-ready
YouTubeCertificationsBeginner
Open
YouTubeFree

John Hammond

CTFs, malware analysis, threat breakdowns, tooling, and security career videos.

Hands-onJob-ready
YouTubeDFIRIntermediate
Open
YouTubeFree

IppSec

Hack The Box walkthroughs focused on methodology, enumeration, and exploitation.

YouTubeWeb / AppSecIntermediate
Open
YouTubeFree

LiveOverflow

Binary exploitation, reverse engineering, web hacking, and CTF fundamentals.

Hands-on
YouTubeMalware / Reverse EngineeringIntermediate
Open
YouTubeFree + Paid

The Cyber Mentor

Practical ethical hacking, pentesting, career guidance, and training previews.

Best firstJob-ready
YouTubeWeb / AppSecBeginner
Open
YouTubeFree

David Bombal

Networking, hacking, Python, Linux, interviews, and practical lab demos.

Best firstHands-onNeeds lab
YouTubeNetwork SecurityBeginner
Open
YouTubeFree

HackerSploit

Ethical hacking tutorials, Linux, tools, web testing, and red-team basics.

Best first
YouTubeWeb / AppSecBeginner
Open
YouTubeFree

NahamSec

Bug bounty, web security, recon, live hacking, and AppSec interviews.

YouTubeWeb / AppSecIntermediate
Open
YouTubeFree

STOK

Bug bounty methodology, interviews, web hacking workflows, and recon ideas.

YouTubeWeb / AppSecIntermediate
Open
YouTubeFree

InsiderPhD

Bug bounty learning paths, web testing basics, and beginner-friendly methodology.

Best first
YouTubeWeb / AppSecBeginner
Open
YouTubeFree

13Cubed

Windows forensics, memory analysis, event logs, and DFIR technique breakdowns.

YouTubeDFIRIntermediate
Open
YouTubeFree + Paid

Black Hills Information Security

Webcasts, purple-team content, detection, pentesting, and defensive tradecraft.

YouTubeSecurity EngineeringIntermediate
Open
YouTubeFree

DEF CON Conference

Security research talks across hardware, policy, privacy, exploitation, and defense.

Advanced
YouTubeProfessionalProfessional
Open
YouTubeFree

Black Hat

Conference briefings and technical research from Black Hat events.

Advanced
YouTubeProfessionalProfessional
Open
YouTubeFree

Computerphile Security

Accessible explanations of crypto, passwords, protocols, privacy, and computing concepts.

Best first
YouTubeFoundationsBeginner
Open
YouTubeFree

freeCodeCamp Cybersecurity

Long-form free courses on security, Linux, networking, Python, and cloud basics.

Best firstNeeds lab
YouTubeFoundationsBeginner
Open
LabsFree

OverTheWire

Wargames for Linux, command line, web, crypto, and exploitation fundamentals.

Best firstHands-on
Practice platformFoundationsBeginner
Open
LabsFree

picoCTF

Beginner-friendly CTF challenges built for students and self-learners.

Best firstHands-on
Practice platformFoundationsBeginner
Open
LabsFree + Paid

Hack The Box

Machines, Sherlocks, tracks, Academy modules, and competitive labs.

Hands-onNeeds lab
Practice platformWeb / AppSecIntermediate
Open
LabsFree + Paid

TryHackMe

Guided rooms, learning paths, and browser-based labs for red and blue team.

Best firstHands-onNeeds lab
Practice platformFoundationsBeginner
Open
LabsFree

PortSwigger Web Security Academy

Free interactive web vulnerability labs and topic explanations.

Best firstHands-onNeeds lab
Practice platformWeb / AppSecBeginner
Open
LabsFree

OWASP Juice Shop

Modern intentionally vulnerable web app covering OWASP Top Ten style issues.

Best firstHands-on
OWASPWeb / AppSecBeginner
Open
LabsFree

VulnHub

Downloadable vulnerable virtual machines for offline practice labs.

Hands-onNeeds lab
Practice platformWeb / AppSecIntermediate
Open
LabsFree

CTFtime

Calendar, teams, and ranking hub for public capture-the-flag competitions.

Hands-on
Practice calendarFoundationsIntermediate
Open
LabsFree + Paid

CyberDefenders

Blue-team labs for forensics, SIEM, malware, threat hunting, and incident response.

Hands-onNeeds lab
Practice platformDFIRIntermediate
Open
LabsFree

Malware Traffic Analysis

PCAP and malware traffic exercises for network forensics and detection practice.

Hands-on
Practice archiveDFIRIntermediate
Open
LabsFree

AttackIQ Academy

Threat-informed defense, MITRE ATT&CK, and purple-team learning modules.

Hands-on
Training platformThreat IntelligenceIntermediate
Open
DocsFree

NIST NICE Framework

Workforce framework for cybersecurity roles, skills, tasks, and career mapping.

Best firstTheoryJob-ready
NISTGRCBeginner
Open
DocsFree

NIST Cybersecurity Framework

Cybersecurity risk management framework for governance and security programs.

Theory
NISTGRCIntermediate
Open
DocsFree

MITRE ATT&CK

Globally accessible knowledge base of adversary tactics and techniques.

Theory
MITREThreat IntelligenceIntermediate
Open
DocsFree

CISA Cybersecurity Resources

Government guidance, alerts, advisories, ransomware resources, and security programs.

Best firstTheory
CISAGRCBeginner
Open
DocsFree

CISA KEV Catalog

Known exploited vulnerabilities catalog for prioritizing remediation.

Theory
CISAThreat IntelligenceIntermediate
Open
DocsFree

CIS Critical Security Controls

Prioritized security controls and safeguards for organizations.

Theory
CISGRCIntermediate
Open
DocsFree

OWASP Top Ten

Awareness document for common web application security risks.

Best firstTheory
OWASPWeb / AppSecBeginner
Open
DocsFree

OWASP Web Security Testing Guide

Testing methodology for web application security assessments.

Theory
OWASPWeb / AppSecIntermediate
Open
DocsFree

OWASP Cheat Sheet Series

Practical secure development checklists for auth, crypto, APIs, logging, and more.

Best firstTheory
OWASPWeb / AppSecBeginner
Open
DocsFree

OWASP ASVS

Application Security Verification Standard for requirements and assessments.

TheoryAdvanced
OWASPWeb / AppSecProfessional
Open
DocsFree

AWS Security Documentation

Security, identity, compliance, architecture, and service-specific AWS guidance.

Theory
AWSCloud SecurityIntermediate
Open
DocsFree

Microsoft Security Documentation

Microsoft security, compliance, Defender, Sentinel, identity, and Azure guidance.

Theory
MicrosoftCloud SecurityIntermediate
Open
DocsFree

Google Cloud Security Foundations

Google Cloud security foundations, IAM, architecture, and operations guidance.

TheoryNeeds lab
Google CloudCloud SecurityIntermediate
Open
ToolsFree

CyberChef

Browser-based data transformation, decoding, hashing, compression, and analysis tool.

Best first
GCHQDFIRBeginner
Open
ToolsFree

Wireshark Documentation

Packet analysis tool documentation, display filters, and protocol inspection.

Best first
WiresharkNetwork SecurityBeginner
Open
ToolsFree

SigmaHQ

Generic SIEM detection rule format and community rules.

Needs lab
SigmaDFIRIntermediate
Open
ToolsFree

YARA Documentation

Pattern matching rules for malware research and detection.

VirusTotalMalware / Reverse EngineeringIntermediate
Open
ToolsFree + Paid

Elastic Security Docs

SIEM, detection rules, endpoint, and threat hunting documentation.

Needs lab
ElasticDFIRIntermediate
Open
ToolsFree + Paid

Splunk Security Essentials

Security use cases, SPL examples, and detection content for Splunk environments.

SplunkDFIRIntermediate
Open
Blogs / NewsFree

Krebs on Security

Investigative security journalism on breaches, cybercrime, fraud, and threat actors.

BlogThreat IntelligenceIntermediate
Open
Blogs / NewsFree

SANS Internet Storm Center

Daily handlers diary, alerts, threat observations, and defensive analysis.

SANSThreat IntelligenceIntermediate
Open
Blogs / NewsFree

Google Project Zero

Vulnerability research, exploit analysis, root-cause work, and disclosure posts.

Advanced
GoogleSecurity EngineeringProfessional
Open
Blogs / NewsFree

Microsoft Security Blog

Threat intelligence, identity, cloud security, and Microsoft security product research.

Needs lab
MicrosoftCloud SecurityIntermediate
Open
Blogs / NewsFree

Mandiant Blog

Threat intelligence, incident response, malware, and adversary tracking research.

Advanced
Google CloudThreat IntelligenceProfessional
Open
Blogs / NewsFree

Cisco Talos Blog

Threat research, vulnerability analysis, malware reports, and detection context.

CiscoThreat IntelligenceIntermediate
Open
Blogs / NewsFree

Palo Alto Unit 42

Threat intelligence, malware analysis, cloud threats, and incident research.

Needs lab
Palo Alto NetworksThreat IntelligenceIntermediate
Open
PodcastsFree

Darknet Diaries

Narrative stories about breaches, hackers, investigations, and security history.

Best first
PodcastFoundationsBeginner
Open
PodcastsFree

Risky Business

Weekly security news, policy, vulnerability, vendor, and practitioner discussion.

PodcastThreat IntelligenceIntermediate
Open
PodcastsFree

CyberWire Daily

Daily cybersecurity news briefings and interviews.

Best first
PodcastThreat IntelligenceBeginner
Open
PodcastsFree

Smashing Security

Security and privacy stories explained in a lighter weekly format.

Best first
PodcastFoundationsBeginner
Open
CommunitiesFree

r/netsec

Technical security research links and discussion.

RedditProfessionalIntermediate
Open
CommunitiesFree

r/cybersecurity

General cybersecurity careers, news, questions, and community discussion.

Best firstJob-ready
RedditFoundationsBeginner
Open
CommunitiesFree

OWASP Community

Local chapters, projects, events, and application security community work.

Best first
OWASPWeb / AppSecBeginner
Open
CommunitiesFree

HackerOne Hacktivity

Public vulnerability reports useful for learning bug bounty patterns.

HackerOneWeb / AppSecIntermediate
Open
Books / ReadingFree

Bugcrowd University

Bug bounty learning content, methodology, and vulnerability examples.

Best first
BugcrowdWeb / AppSecBeginner
Open
Books / ReadingPaid

The Tangled Web

Classic book on browser and web platform security.

Theory
BookWeb / AppSecIntermediate
Open
Books / ReadingPaid

Practical Malware Analysis

Hands-on malware analysis book covering static and dynamic analysis.

Hands-onTheory
BookMalware / Reverse EngineeringIntermediate
Open
Books / ReadingPaid

Real-World Cryptography

Modern applied cryptography for engineers and security practitioners.

BookSecurity EngineeringIntermediate
Open
Books / ReadingPaid

Web Application Hacker’s Handbook

Classic web testing reference; older but still useful for methodology.

Advanced
BookWeb / AppSecProfessional
Open
DocsFree

OWASP Top 10 for LLMs

The canonical list of the most critical security risks in LLM and generative-AI applications.

Best firstTheory
OWASPAI / LLM SecurityBeginner
Open
DocsFree

MITRE ATLAS

Adversarial threat landscape and ATT&CK-style technique matrix for AI and ML systems.

Theory
MITREAI / LLM SecurityIntermediate
Open
DocsFree

NIST AI Risk Management Framework

Voluntary framework for governing, mapping, measuring, and managing AI risk.

Theory
NISTAI / LLM SecurityIntermediate
Open
LabsFree

Lakera Gandalf

Gamified prompt-injection challenge that teaches how LLM guardrails fail, level by level.

Best firstHands-on
LakeraAI / LLM SecurityBeginner
Open
LabsFree

HackAPrompt

Prompt-injection competition and playground for learning real-world LLM attack techniques.

Best firstHands-on
Learn PromptingAI / LLM SecurityBeginner
Open
DocsFree

awesome-ml-for-cybersecurity

Curated list of datasets, papers, tools, and courses for applying machine learning to security.

Theory
GitHubAI-Augmented DefenseIntermediate
Open
DocsFree

Microsoft Security Copilot Docs

Reference for the AI security analysis tool: prompting, plugins, agents, and SOC use cases.

Theory
MicrosoftAI-Augmented DefenseIntermediate
Open
Books / ReadingPaid

Machine Learning and Security

Practical guide to using data and algorithms for detection: spam, malware, anomalies, and clustering.

O’ReillyAI-Augmented DefenseIntermediate
Open
DocsFree

awesome-embedded-and-iot-security

Curated list of tools, papers, and labs for embedded and IoT security research.

Hands-onTheoryNeeds lab
GitHubHardware / IoTIntermediate
Open
LabsFree

OWASP IoTGoat

Deliberately insecure firmware (OpenWrt-based) for practicing IoT vulnerability discovery.

Hands-on
OWASPHardware / IoTIntermediate
Open
LabsFree

Ethernaut

Interactive smart-contract hacking game: reentrancy, delegatecall, access control, and storage bugs.

Best firstHands-on
OpenZeppelinBlockchain / Web3Beginner
Open
LabsFree

Damn Vulnerable DeFi

Offensive DeFi wargame: flash-loan manipulation, price-oracle exploits, and governance attacks.

Hands-on
Web3 wargameBlockchain / Web3Intermediate
Open
DocsFree

Awesome-web3-Security

Curated Web3 security materials for pentesters, auditors, and bug hunters.

Theory
GitHubBlockchain / Web3Intermediate
Open
DocsFree

SLSA Framework

Supply-chain Levels for Software Artifacts: provenance and integrity guarantees against tampering.

Theory
OpenSSFSupply Chain SecurityIntermediate
Open
ToolsFree

Sigstore

Keyless artifact signing and verification: Cosign, Fulcio certificates, and the Rekor transparency log.

OpenSSFSupply Chain SecurityIntermediate
Open
CommunitiesFree

OpenSSF

Open Source Security Foundation: guides, working groups, and best practices for securing the supply chain.

Best firstHands-on
Linux FoundationSupply Chain SecurityBeginner
Open
ToolsFree

Atomic Red Team

Library of small, portable tests mapped to MITRE ATT&CK for validating detections.

Red CanaryDetection EngineeringIntermediate
Open
Blogs / NewsFree

Detection Engineering Weekly

Weekly newsletter tracking detection-as-code, new rules, tooling, and threat research.

NewsletterDetection EngineeringIntermediate
Open
ToolsFree

Nmap Reference Guide

Official reference for host discovery, port scanning, version detection, and the Nmap Scripting Engine.

Best first
NmapNetwork SecurityBeginner
Open
DocsFree

Practical Networking

Clear, structured articles on how networks really work: routing, switching, NAT, TLS, and more.

Best firstTheory
Practical NetworkingNetwork SecurityBeginner
Open
YouTubeFree

Chris Greer

Wireshark and packet-analysis tutorials, TCP/IP deep dives, and troubleshooting walkthroughs.

Best first
YouTubeNetwork SecurityBeginner
Open
Books / ReadingPaid

Practical Packet Analysis

Hands-on guide to capturing and interpreting network traffic with Wireshark.

Hands-on
No StarchNetwork SecurityIntermediate
Open
LabsFree

pwn.college

University-grade modules and challenges covering binary exploitation, reversing, and system security.

Hands-on
Arizona State UniversityExploit DevelopmentIntermediate
Open
LabsFree

exploit.education

Phoenix and Nebula virtual machines for learning memory corruption and privilege escalation.

Best firstHands-on
exploit.educationExploit DevelopmentBeginner
Open
LabsFree

ROP Emporium

Focused challenges that teach return-oriented programming across multiple architectures.

Hands-on
ROP EmporiumExploit DevelopmentIntermediate
Open
DocsFree

Nightmare

Free intro-to-binary-exploitation course built from CTF challenges, from stack overflows to heap.

Hands-onTheory
guyinatuxedoExploit DevelopmentIntermediate
Open
DocsFree

Azeria Labs

ARM assembly and exploitation tutorials aimed at mobile and embedded targets.

Theory
Azeria LabsExploit DevelopmentIntermediate
Open
DocsFree

HackTricks

Massive practical hacking wiki covering pentest methodology, privilege escalation, and AD attacks.

Theory
Carlos PolopRed Team / Adversary EmulationIntermediate
Open
ToolsFree

MITRE Caldera

Automated adversary-emulation platform built on the ATT&CK framework.

Theory
MITRERed Team / Adversary EmulationIntermediate
Open
DocsFree

PayloadsAllTheThings

Reference of payloads and bypass techniques for web, Active Directory, and post-exploitation.

Theory
GitHubRed Team / Adversary EmulationIntermediate
Open
DocsFree

The C2 Matrix

Comparison matrix of command-and-control frameworks to pick the right tool for an engagement.

TheoryAdvanced
SANSRed Team / Adversary EmulationProfessional
Open
YouTubeFree

Red Team Village

Talks and workshops on offensive tradecraft, tooling, and adversary emulation.

YouTubeRed Team / Adversary EmulationIntermediate
Open
DocsFree

OWASP SAMM

Software Assurance Maturity Model for building and measuring a secure development program.

Theory
OWASPProduct SecurityIntermediate
Open
DocsFree

Microsoft SDL

Security Development Lifecycle practices for building security into software from the start.

Hands-onTheory
MicrosoftProduct SecurityIntermediate
Open
ToolsFree

OWASP Threat Dragon

Free threat-modeling tool for drawing data-flow diagrams and recording threats.

OWASPProduct SecurityIntermediate
Open
Books / ReadingPaid

Threat Modeling: Designing for Security

Comprehensive practitioner guide to threat modeling software systems.

Adam ShostackProduct SecurityIntermediate
Open
DocsFree

BSIMM

Building Security In Maturity Model: a data-driven view of what real software security programs do.

TheoryAdvanced
Black DuckProduct SecurityProfessional
Open
DocsFree

OAuth 2.0

Authoritative hub for the OAuth 2.0 authorization framework, specifications, and security guidance.

Theory
oauth.netIAMIntermediate
Open
DocsFree

OpenID Connect

How OpenID Connect adds an identity layer on top of OAuth 2.0 for authentication.

Theory
OpenID FoundationIAMIntermediate
Open
DocsFree

NIST SP 800-63 Digital Identity Guidelines

Federal guidelines for identity proofing, authentication, and federation assurance levels.

TheoryAdvanced
NISTIAMProfessional
Open
DocsFree

AWS IAM User Guide

Reference for AWS identity, policies, roles, and least-privilege access design.

Theory
AWSIAMIntermediate
Open
DocsFree

OWASP MAS (MASVS + MASTG)

Mobile Application Security Verification Standard and Testing Guide for iOS and Android.

Theory
OWASPMobile SecurityIntermediate
Open
ToolsFree

MobSF

Automated static and dynamic analysis framework for Android and iOS applications.

Theory
GitHubMobile SecurityIntermediate
Open
ToolsFree

Frida

Dynamic instrumentation toolkit for hooking and tracing apps at runtime.

FridaMobile SecurityIntermediate
Open
DocsFree

Android Security Documentation

Platform security model, app sandboxing, permissions, and secure-development guidance.

Theory
GoogleMobile SecurityIntermediate
Open
LabsFree

Cryptopals Crypto Challenges

Hands-on challenges that teach attacks against real-world crypto by building them yourself.

Hands-on
CryptopalsPrivacy / CryptographyIntermediate
Open
Books / ReadingFree

Crypto 101

Free introductory book on applied cryptography for programmers.

Best firstTheory
Crypto 101Privacy / CryptographyBeginner
Open
Books / ReadingFree

A Graduate Course in Applied Cryptography

Free, rigorous textbook covering modern cryptographic primitives and proofs.

TheoryAdvanced
Boneh & ShoupPrivacy / CryptographyProfessional
Open
DocsFree

EFF Surveillance Self-Defense

Practical guides to digital privacy, personal threat modeling, and protective tools.

Best firstTheory
EFFPrivacy / CryptographyBeginner
Open
Books / ReadingPaid

Serious Cryptography

Modern, practical introduction to cryptographic algorithms and how they are used.

No StarchPrivacy / CryptographyIntermediate
Open
DocsFree

CISA Industrial Control Systems

Advisories, recommended practices, and training for securing industrial control systems.

Hands-onTheory
CISAOT / ICSIntermediate
Open
DocsFree

MITRE ATT&CK for ICS

ATT&CK knowledge base of adversary tactics and techniques targeting ICS environments.

Theory
MITREOT / ICSIntermediate
Open
Blogs / NewsFree

SANS ICS Security

ICS/OT security blog, whitepapers, webcasts, and community resources.

SANSOT / ICSIntermediate
Open
LabsFree

GRFICS

Graphical framework simulating an industrial process for safe ICS attack-and-defend practice.

Hands-onTheory
Fortiphyd LogicOT / ICSIntermediate
Open
ToolsFree

AFL++

State-of-the-art fuzzer for finding memory-safety bugs in native code.

Advanced
GitHubVulnerability ResearchProfessional
Open
Books / ReadingFree

Phrack Magazine

Long-running ezine with deep technical articles on exploitation and system internals.

Advanced
PhrackVulnerability ResearchProfessional
Open
Books / ReadingPaid

Hacking: The Art of Exploitation

Foundational book on exploitation techniques, from C and assembly to shellcode.

Theory
No StarchVulnerability ResearchIntermediate
Open
DocsFree

Awesome Fuzzing

Curated list of fuzzing tools, papers, and tutorials.

TheoryAdvanced
GitHubVulnerability ResearchProfessional
Open
DocsFree

OWASP IoT Top 10

The ten most common IoT security weaknesses, from default passwords to insecure interfaces.

Best firstTheory
OWASPHardware / IoTBeginner
Open
ToolsFree

binwalk

Firmware-analysis tool for extracting and inspecting embedded file systems and code.

GitHubHardware / IoTIntermediate
Open
Books / ReadingPaid

The Hardware Hacking Handbook

Guide to attacking embedded systems with fault injection and side-channel analysis.

No StarchHardware / IoTIntermediate
Open
LabsFree

DetectionLab

Preconfigured lab with logging and tooling to build and test detections quickly.

Hands-onNeeds lab
GitHubDetection EngineeringIntermediate
Open
Blogs / NewsFree

The DFIR Report

Detailed intrusion reports with timelines, TTPs, and concrete detection opportunities.

The DFIR ReportDetection EngineeringIntermediate
Open
DocsFree

Awesome Detection Engineering

Curated resources on detection-as-code, methodologies, and rule repositories.

Theory
GitHubDetection EngineeringIntermediate
Open
ToolsFree

OWASP Dependency-Check

Software composition analysis tool that flags known-vulnerable dependencies.

Best first
OWASPSupply Chain SecurityBeginner
Open
ToolsFree

in-toto

Framework for cryptographically verifying the integrity of the software supply chain.

Theory
in-totoSupply Chain SecurityIntermediate
Open
DocsFree

Solidity by Example

Annotated Solidity snippets including common vulnerabilities and on-chain hacks.

Best firstTheory
Solidity by ExampleBlockchain / Web3Beginner
Open
LabsFree

Capture the Ether

Game of smart-contract security challenges on Ethereum.

Hands-on
Capture the EtherBlockchain / Web3Intermediate
Open
Blogs / NewsFree

rekt.news

Post-mortems of major DeFi hacks and exploits with technical breakdowns.

rektBlockchain / Web3Intermediate
Open
ToolsFree

garak

LLM vulnerability scanner that probes for jailbreaks, prompt injection, and data leakage.

NVIDIAAI / LLM SecurityIntermediate
Open
Blogs / NewsFree

Prompt injection (Simon Willison)

Ongoing analysis of prompt-injection attacks and why they remain hard to fix.

BlogAI / LLM SecurityIntermediate
Open
ToolsFree

PyRIT

Python Risk Identification Toolkit for red-teaming generative-AI systems.

MicrosoftAI-Augmented DefenseIntermediate
Open
ToolsFree

Adversarial Robustness Toolbox

Library for defending and attacking ML models: evasion, poisoning, and extraction.

IBMAI-Augmented DefenseIntermediate
Open
ToolsFree

Ghidra

Free software reverse-engineering suite with a powerful decompiler.

NSAMalware / Reverse EngineeringIntermediate
Open
YouTubeFree

OALabs

Practical malware reverse-engineering streams, unpacking, and tooling tutorials.

YouTubeMalware / Reverse EngineeringIntermediate
Open
ToolsFree

MalwareBazaar

Community malware-sample repository for research and detection.

abuse.chMalware / Reverse EngineeringIntermediate
Open
Books / ReadingFree

Building Secure and Reliable Systems

Free Google SRE book on designing, implementing, and maintaining secure systems.

TheoryAdvanced
GoogleSecurity EngineeringProfessional
Open
DocsFree

Awesome Security

Broad curated list of security tools, references, and learning resources.

Theory
GitHubSecurity EngineeringIntermediate
Open
LabsFree

flAWS Challenge

Guided AWS security challenge teaching common cloud misconfigurations step by step.

Hands-onNeeds lab
flaws.cloudCloud SecurityIntermediate
Open
LabsFree

CloudGoat

Vulnerable-by-design AWS deployment tool for practicing cloud attack scenarios.

Hands-onNeeds lab
Rhino Security LabsCloud SecurityIntermediate
Open
DocsFree

Hacking the Cloud

Encyclopedia of offensive techniques and TTPs across AWS, Azure, and GCP.

Theory
Hacking the CloudCloud SecurityIntermediate
Open
DocsFree

FAIR Institute

Quantitative risk analysis model (Factor Analysis of Information Risk) and supporting resources.

Theory
FAIR InstituteGRCIntermediate
Open
DocsFree

ISO/IEC 27001

Overview of the international standard for information security management systems.

Theory
ISOGRCIntermediate
Open
05 — Credentials

Certification roadmap.

Foundational

  • CompTIA Security+
  • ISC2 CC
  • Microsoft SC-900
  • Google Cybersecurity Certificate

Intermediate

  • CompTIA CySA+
  • Microsoft SC-200
  • AWS Security Specialty
  • eJPT / PNPT

Advanced

  • CISSP
  • OSCP
  • GIAC GCIH / GCIA / GREM
  • CCSP
06 — Practice

One disciplined week.

Mon
Foundations reviewNetworking, Linux, or security concepts
Learn1-2 hrs
Tue
Hands-on labWeb, SOC, or cloud exercise
Practice1-2 hrs
Wed
Tool drillWireshark, Burp, Splunk, KQL, or Ghidra
Build1 hr
Thu
Read a reportAdvisory, incident report, or ATT&CK technique
Analyze45 min
Fri
Scenario challengeCTF, detection, threat hunt, or case triage
Practice1-2 hrs
Sat
Portfolio noteDocument what you did, commands, screenshots, lessons
Build2 hrs
Sun
Review and planUpdate goals, backlog, and next week focus
Review45 min
07 — Dispatch

The weekly study path.

One short email per week — a domain to focus on, a project idea, and two or three picks worth your time. No churn.

 

08 — Business

How the atlas pays its way.

Best first: sponsor slots

Sell a small number of clearly labeled placements to security training, lab, newsletter, or tooling partners that fit the learning paths.

Affiliate links

Use affiliate links only where the resource is genuinely useful. Keep the directory ranking editorial and disclose paid relationships.

Ads later

Add display ads after the site has steady traffic, original notes, and enough trust pages for ad-network review.

09 — Colophon

About this atlas.

CyberPath Atlas is a curated learning map for cybersecurity beginners, career switchers, and working professionals. It points to legitimate education, legal practice environments, certifications, and the portfolio work that actually moves a job application forward.

Editorial promise

Resources are selected for learning value, practical relevance, job-path fit, and whether a learner can use them legally and systematically. Sponsored placements must be labeled and may not override editorial usefulness.

Disclosure

Some outbound links may become affiliate, sponsor, or partner links. If that happens, CyberPath Atlas may earn a commission or sponsorship fee at no extra cost to the reader, and paid placements should be marked near the relevant link.

Privacy

This static site does not require an account. If analytics, ads, payment, or newsletter tools are added later, this section should list the provider names, cookie behavior, collected data, retention purpose, and opt-out choices.

Contact

Corrections, sponsorships, resource suggestions, partnerships — all welcome at the address below.

contact@mistan.dev
10 — Method

Pick one path. Practice for thirty days. Write it down.

Breadth is comforting; skill comes from repeated, legal, hands-on work and clean writeups. One path, one platform, one notebook — for a month — beats five tabs open for a year.

Browse the libraryPlan this weekChoose a path