Curriculum/Cybersecurity

Learning Track

Cybersecurity

From curious to capable defender.

A parent track containing 11 domain-specific sub-tracks. Start with the free Intro lesson, then choose the domains that interest you. Complete all sub-tracks to earn the full Cybersecurity certification.

Sub-Tracks

Intro to Cybersecurity

Understand every domain before picking your path.

A single free lesson covering all nine cybersecurity domains. Required before unlocking any sub-track.

1 lesson·Beginner·~1h

First lesson: Overview of All Cybersecurity Domains

Identity and Access Management

Control who can access what, and prove it.

Passwords, MFA, RBAC, SSO, Privileged Access Management, hands-on Entra ID / AWS IAM / OAuth flows / Zero Trust.

12 lessons·Beginner → Intermediate·~12h

First lesson: What is IAM?

Vulnerability Management

Find weaknesses before attackers do.

CVEs, CVSS, Nmap scanning, hands-on OpenVAS, enterprise patch management, and continuous vulnerability programs.

11 lessons·Beginner → Intermediate·~11h

First lesson: What is Vulnerability Management?

Application Security

Secure the software itself.

OWASP Top 10 (hands-on in DVWA and WebGoat), injection, XSS, secure code review, bug bounty, and WAFs.

21 lessons·Beginner → Intermediate·~18h

First lesson: What is Application Security?

Incident Response

Be ready before something goes wrong.

NIST IR lifecycle, detection, containment, eradication, recovery, SIEM with Splunk, and tabletop exercises.

10 lessons·Beginner → Intermediate·~10h

First lesson: What is Incident Response?

Data Leakage Prevention

Keep sensitive data inside the organization.

Data classification, encryption, DLP tools, insider threats, and compliance regulations.

8 lessons·Beginner → Intermediate·~8h

First lesson: What is Data Leakage?

Penetration Testing

Authorized attack simulation.

Ethics-first legal frame, full PTES methodology, exploitation, web app testing, post-exploit, HTB Starting Point passion project, and professional reporting.

11 lessons·Beginner → Advanced·~12h

First lesson: Ethics and the Law (Mandatory First)

Risk Management and Governance

The business side of security.

Risk assessment, security policies, compliance frameworks, and business continuity.

8 lessons·Beginner → Advanced·~8h

First lesson: What is Risk Management?

End User Device Management

Secure every endpoint: laptops, phones, IoT.

OS hardening, endpoint protection platforms, MDM, patch management, and IoT security.

8 lessons·Beginner → Intermediate·~8h

First lesson: What is Endpoint Security?

Threat Intelligence

Know your adversaries.

Threat actors, IoCs vs IoAs, OSINT toolkit (Shodan, Censys, VirusTotal, URLscan), MITRE ATT&CK Navigator, threat-report writing, and ISACs.

12 lessons·Beginner → Advanced·~12h

First lesson: What is Threat Intelligence?

NIST Cybersecurity Framework

The five core functions: Identify, Protect, Detect, Respond, Recover.

An in-depth study of the NIST CSF. Understand how each function maps to real controls and other frameworks.

8 lessons·Beginner → Advanced·~8h

First lesson: Introduction to the NIST Framework

AI Application: Cybersecurity

How AI is reshaping offense and defense.

AI-powered threat detection, SOC automation, vulnerability assessment, pen testing augmentation, and securing AI systems. Optional sub-track within Cybersecurity.

8 lessons·Beginner → Advanced·~8h

First lesson: AI in Cybersecurity: The Landscape

Networking and Protocol Security

How computers talk, and how attackers exploit it.

The networking foundation for the whole Cybersecurity track: OSI and TCP/IP, TCP vs UDP, Wireshark, ARP spoofing, man-in-the-middle, SYN floods and DDoS, DNS attacks, and wireless attacks. Hands-on labs in isolated environments. Prerequisite knowledge for Penetration Testing and Incident Response.

10 lessons·Beginner → Intermediate·~9h

First lesson: Networking for Security: Why Protocols Are the Battleground

Password Attacks and Credential Security

Credentials are the keys to the kingdom.

How attackers brute force, crack, and stuff credentials (Hydra, hashcat, John), the online-vs-offline distinction, and the defensive side: password managers, passkeys, and credential hygiene for users and developers. Hands-on DVWA lab.

4 lessons·Beginner → Intermediate·~4h

First lesson: Credentials: The Keys to the Kingdom

Kali Linux and Security Lab Setup

Build the lab the rest of the track runs in.

The practical foundation for every hands-on lab: install VirtualBox and Kali Linux, configure isolated networking, use snapshots, add a vulnerable target VM, and learn the Kali tool categories you will use throughout the track. Take this before any lab that requires Kali.

3 lessons·Beginner → Intermediate·~3h

First lesson: Setting Up a Kali Linux Lab

Cryptography

The math that makes security possible.

Symmetric and asymmetric encryption, hash functions and HMAC, key exchange and digital signatures, TLS 1.3 in depth, and practical cryptography for developers (which primitive to use, which library, and what never to implement yourself).

8 lessons·Beginner → Intermediate·~7h

First lesson: What Cryptography Protects

Mobile Security

Attacking and defending Android and iOS apps.

Android and iOS security models, the OWASP Mobile Top 10, static analysis (jadx, APK decompilation), dynamic analysis (Frida, Burp proxy), and common mobile vulnerabilities. Hands-on with a deliberately vulnerable app.

6 lessons·Beginner → Advanced·~5h

First lesson: The Mobile Security Landscape

Cloud Security

Securing what you run in AWS, Azure, and GCP.

The shared responsibility model, IAM misconfigurations and least privilege, cloud attack techniques (metadata SSRF, privilege escalation), cloud security tooling (Prowler, ScoutSuite, Trivy), and secrets management. Hands-on with CloudGoat.

5 lessons·Beginner → Advanced·~5h

First lesson: Cloud Security and the Shared Responsibility Model

Reverse Engineering and Malware Analysis

Understanding software without the source.

An advanced subtrack: static analysis (file formats, PE/ELF), disassembly and decompilation with Ghidra, dynamic analysis and safe handling, malware categories, sandbox analysis, and YARA rules. No real malware is ever used in labs.

6 lessons·Intermediate → Advanced·~6h

First lesson: What Reverse Engineering Is

Active Directory and Windows Security

The enterprise attack surface that matters most.

Active Directory structure, Kerberos and NTLM authentication, common AD attacks (Pass-the-Hash, Kerberoasting, AS-REP Roasting, Golden Ticket), BloodHound attack-path mapping, and AD defense and monitoring. Hands-on with a lab AD environment.

6 lessons·Intermediate → Advanced·~6h

First lesson: Active Directory: The Enterprise Attack Surface

Burp Suite: Web Application Testing

Zero to professional web app tester.

The industry-standard web application security testing tool, from never having opened it to working as a professional tester. Four mini-tracks (Setup and Core Concepts, Repeater and Manual Testing, Intruder and Automated Attacks, Advanced Techniques) plus a portfolio passion project and job readiness. Labs use the free PortSwigger Web Security Academy. Prerequisite: Networking and Protocol Security.

16 lessons·Beginner → Advanced·~12h

First lesson: What is Burp Suite and Why Do Security Professionals Use It?