Learning

Curated platforms, labs, and resources for security learning and certifications.

Structured paths from beginner to OSCP-level, plus free resources and a suggested certification roadmap.

Learning Platforms

PlatformBest ForLink
HTB AcademyStructured learning, certification paths, BEST content depth
TryHackMeBeginners, guided rooms, browser-based
PortSwigger AcademyWeb security, 240+ labs, BSCP prep
TCM SecurityPNPT prep, practical courses
PentesterLabWeb app security, progressive

Practice Labs

PlatformBest ForLink
Hack The Box LabsReal machines, competitive, OSCP prep
HTB Pro LabsEnterprise environments (Dante, Zephyr, Offshore)
Proving GroundsOffSec machines, OSCP prep
VulnHubDownloadable VMs, offline practice

Bug Bounty Platforms

PlatformBest ForLink
HackerOneLargest platform, most programs
BugcrowdGood programs, VDP
IntigritiEuropean, good payouts
YesWeHackEuropean alternative

Free Learning Resources

YouTube Channels

ChannelFocusLink
IppSecHTB walkthroughs, methodology gold
John HammondCTF, malware, tutorials, HTB
The Cyber MentorPNPT prep, practical hacking
0xdfHTB writeups, detailed
LiveOverflowDeep technical, exploit dev
NahamsecBug bounty, web hacking
STÖKBug bounty lifestyle
HackerSploitPentesting tutorials
David BombalNetworking, certs, interviews
PinkDraconianHTB, CPTS content

Essential Books

BookAuthorFocusLink
The Web Application Hacker's HandbookStuttard & PintoWeb security bible
Penetration TestingGeorgia WeidmanPractical pentesting intro
The Hacker Playbook 3Peter KimRed team tactics
Red Team Field Manual (RTFM)Ben ClarkQuick reference
Bug Bounty BootcampVickie LiBug bounty guide
Black Hat PythonJustin SeitzPython for hackers

Reference Sites

ResourceFocusLink
HackTricksPentesting encyclopedia
PayloadsAllTheThingsAll the payloads
GTFOBinsLinux priv esc
LOLBASWindows living-off-the-land
WADComsAD cheat sheet
MITRE ATT&CKAdversary tactics

Suggested certifications

1Phase 1 (Months 1-3)

  • TryHackMe Complete Beginner path
  • OverTheWire Bandit
  • HTB Academy fundamentals

2Phase 2 (Months 4-8)

  • HTB Academy Penetration Tester path
  • Complete all 28 modules + skill assessments
  • HTB machines for practice

3Phase 3 (Months 9-10)

  • HTB Pro Labs: Dante → Zephyr (pivoting practice)
  • CPTS Exam — harder-than-OSCP skills

4Phase 4 (Months 11-14)

  • OSCP — industry recognition
  • Most content already covered by CPTS