Skip to content

Latest commit

Β 

History

26 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

🎯 Penetration Testing Roadmap (2026 Edition)

Stars Forks Last Commit License PRs Welcome Free Labs

A structured, comprehensive 60-week curriculum to master penetration testing, web security, network hacking, and ethical hacking from scratch.

πŸ“š Explore Roadmaps β€’ πŸ₯½ 500+ Free Labs β€’ πŸ› οΈ Tools Directory β€’ 🀝 Contribute


πŸ“– Overview

Feeling overwhelmed by the vast world of cybersecurity? You are not alone. Penetration testing requires a blend of networking, Linux/Windows administration, web architecture, and security methodology.

This repository provides a step-by-step, self-paced learning path designed to take you from absolute zero to a market-ready penetration tester through hands-on practice, vulnerable labs, real-world CTFs, and free certifications.


πŸ—ΊοΈ Visual Learning Flowchart

graph TD
    A[πŸ”§ Prerequisites<br/>Linux, Networking, Scripting] --> B[πŸ—οΈ Phase 1: Foundations<br/>4-6 Weeks]
    B --> C[🎯 Phase 2: Core Pentesting<br/>8-12 Weeks]
    C --> D[πŸš€ Phase 3: Specialization<br/>12+ Weeks]
    D --> E[πŸ† Phase 4: Professional Dev<br/>CTFs & Bug Bounties]
    
    C --> C1[🌐 Web Security<br/>OWASP Top 10, Injection, XSS]
    C --> C2[πŸ”Œ Network Security<br/>Nmap, Metasploit, Post-Ex]
    C --> C3[🐍 Scripting & Auto<br/>Python, Bash, PowerShell]
    
    D --> D1[⚑ 2026 Emerging Vectors<br/>AI/LLM, Cloud & APIs]
    
    style A fill:#2d3748,stroke:#4a5568,color:#fff
    style B fill:#1a365d,stroke:#2b6cb0,color:#fff
    style C fill:#2c5282,stroke:#3182ce,color:#fff
    style D fill:#2b6cb0,stroke:#4299e1,color:#fff
    style E fill:#2f855a,stroke:#38a169,color:#fff
    style D1 fill:#805ad5,stroke:#9f7aea,color:#fff
Loading

πŸ“š Learning Paths & Modules

Choose the roadmap that matches your learning style and goals:

Module / Resource Target Audience Focus Area Description
πŸ—ΊοΈ Roadmap 1: Foundations to Professional All Levels Complete 60-Week Journey Comprehensive 4-phase curriculum covering prerequisites, core pentesting, specializations, and career pathways.
πŸ§ͺ Roadmap 2: Practical Labs & Videos Hands-on Learners Weekly Lab Schedule 60-week breakdown with YouTube tutorials, TryHackMe labs, and detailed subpages for each week.
⚑ Roadmap 3: 12-Week Fast Track Accelerated Learners 12-Week Core Sprint High-intensity 12-week curriculum focused strictly on web application vulnerabilities and free certs.
🎯 500+ Free TryHackMe Rooms Checklist Practice & CTF Hands-on Exercises Featured Item: Curated checklist of 500+ free TryHackMe labs categorized by topic.
πŸ› οΈ Penetration Testing Tools Directory All Pentesters Tool Mastery Categorized guide to essential scanners, proxies, exploitation frameworks, and wordlists.
πŸ“œ Certifications Guide All Learners Career Credentials Comprehensive guide to OSCP, Security+, eJPT, free certs (ISC2 CC, PortSwigger), and prep tips.
πŸ‘₯ Community & Learning Channels All Learners Mentorship & Books Recommended InfoSec books, podcasts, Discord servers, subreddits, and YouTube creators.

⚑ What's New in the 2026 Edition?

Cybersecurity moves fast. The 2026 edition introduces modern attack vectors and defense paradigms:

  • πŸ€– AI & LLM Security: Prompt injection attacks, indirect prompt hijacking, model inversion, and auditing OWASP Top 10 for LLM Applications.
  • ☁️ Cloud Pentesting: AWS/Azure/GCP identity misconfigurations, IAM privilege escalation, and container escape techniques (Docker/K8s).
  • πŸ”Œ API & Microservices: GraphQL introspection abuse, gRPC security testing, OAuth 2.0 / JWT misconfigurations, and BOLA (Broken Object Level Authorization).
  • πŸ“¦ Supply Chain & CI/CD Security: Poisoned pipeline execution (PPE), dependency confusion, and auditing GitHub Actions workflows.
  • πŸ›‘οΈ Zero Trust Architecture: Bypassing identity-aware proxies, Mutual TLS (mTLS) testing, and microsegmentation evasion.

🌟 Featured Highlight: 500+ Free TryHackMe Rooms

One of the largest open-source collections of free security labs:

β”œβ”€β”€ 🐧 Linux Fundamentals (Part 1-3)
β”œβ”€β”€ πŸͺŸ Windows Fundamentals
β”œβ”€β”€ πŸ” Reconnaissance & OSINT (Google Dorking, Shodan, Passive Recon)
β”œβ”€β”€ 🌐 Web Hacking (SQLi, XSS, CSRF, SSRF, LFI/RFI, IDOR)
β”œβ”€β”€ πŸ” Active Directory & Privilege Escalation
β”œβ”€β”€ 🦠 Reverse Engineering & Malware Analysis
└── πŸ† 200+ CTF Rooms (Easy, Medium, Hard, Insane)

πŸ‘‰ Access the Full Checklist & Progress Tracker


πŸ“œ Certification & Career Roadmap

Entry-Level ────► Professional ────► Expert Level
  β€’ CompTIA Sec+    β€’ OSCP            β€’ OSEP
  β€’ CompTIA PenTest+ β€’ CEH             β€’ GPEN
  β€’ ISC2 CC (Free)  β€’ GCIH            β€’ OSCE

πŸ‘‰ Access the Full Certifications & Career Guide


βš–οΈ Legal & Ethical Disclaimer

Caution

Authorized Testing Only: Penetration testing without explicit written authorization is illegal and punishable under computer crime laws (e.g., Computer Fraud and Abuse Act). Always perform testing strictly within authorized environments, lab VMs, or approved bug bounty scopes. Follow responsible disclosure practices at all times.


🀝 Contributing & Community

Contributions make this roadmap better for everyone! Whether you want to add a new TryHackMe room, fix a broken link, or translate a section:


Maintained with ❀️ by @SagarBiswas-MultiHAT and the global InfoSec community under the CC BY-SA 4.0 License.

About

🎯 A structured 60-week penetration testing curriculum with 500+ free TryHackMe labs, OWASP Top 10 deep dives, tool mastery guides, and certification roadmaps. Three learning paths from zero to professional pentester. 2026 Edition; includes AI/LLM, Cloud & API security.

Topics

Resources

Contributing

Stars

47 stars

Watchers

0 watching

Forks

Releases

Contributors