PiSencePiSence

Learn Cybersecurity — Roadmaps, Labs & Practical Steps

Structured learning path for students, developers and engineers. Practical labs, role-based roadmaps and a small quiz to check understanding.

Progressive Curriculum

Foundations (0 → 1 month)

  • Basic computer and networking concepts (IP, DNS, HTTP/S).
  • Intro to security principles: CIA triad, least privilege, attack surface.
  • Basic Linux command line and Windows essentials.
  • Safe online habits: phishing recognition, password hygiene, MFA.

Applied Basics (1 → 3 months)

  • Intro to web security (OWASP Top 10) and simple vulnerability testing.
  • Intro to packet inspection (Wireshark) and basic network scanning (Nmap).
  • Hands-on: build a lab with a VM and intentionally vulnerable app (e.g., Juice Shop).

Intermediate (3 → 9 months)

  • Secure coding basics and code review principles.
  • Authentication, sessions, cookies, CORS, and API security.
  • Intro to threat modelling and basic incident handling.
  • Hands-on: CTF exercises, capture-the-flag platforms, bug bounties (beginner tracks).

Advanced / Career (9+ months)

  • Network exploitation, reverse engineering basics, and forensics foundations.
  • Cloud security, IAM, and infrastructure hardening (AWS/Azure/GCP basics).
  • Red team vs blue team paths, certifications mapping (e.g., CompTIA Security+, OSCP, eJPT).

Roadmap by Role

Student / Beginner

  1. Foundations
  2. Build a home lab
  3. Complete beginner CTFs
  4. Learn Git & Linux

Developer

  1. Secure coding patterns
  2. SAST tools (SonarQube)
  3. Threat modelling
  4. Secure CI/CD pipelines

Sysadmin / Cloud Engineer

  1. Network fundamentals
  2. Harden servers
  3. IAM best practices
  4. Cloud posture management

Aspiring Red-teamer / Researcher

  1. Exploit dev basics
  2. Reverse engineering
  3. Binary analysis tools
  4. Participate in CTFs and write-ups

Tools & Learning Paths

Burp Suite (Community)
HTTP intercepting proxy for testing web apps
Open resource
OWASP ZAP
Free web security scanner and intercepting proxy
Open resource
Juice Shop
Intentionally insecure app for practice
Open resource

Click a category to reveal curated tools & starter links for that speciality.

Quick Self-Check

Which of these is strongest for account protection?

Frequently Asked Questions

Start with fundamentals: networking basics, an introduction to Linux, and safe online habits. Use a guided platform like TryHackMe beginner rooms.
Basic scripting (Python/bash) helps a lot. For offensive or secure-coding roles, proficiency is recommended.
Not required, but they help demonstrate knowledge. Start with vendor-neutral certs (CompTIA Security+) and progress to practical ones (e.g., OSCP) depending on your path.
Only practice in labs you control or platforms that explicitly allow it (TryHackMe, HackTheBox). Never test systems you do not own or have explicit permission to test.
Try both: defensive work (blue team) focuses on detection, monitoring, and response while offensive (red team) emphasizes discovery and exploitation. Early exposure helps decide.
OWASP, TryHackMe free rooms, YouTube beginner series, and vendor docs (AWS free tier) are excellent starting points.
Isolate your lab network from your home network (VLANs or separate router), use snapshots, and only run vulnerable apps within the isolated environment.
Internships give practical exposure, mentorship, and real-world constraints that self-study cannot fully replicate.
CompTIA Security+, eJPT, and provider fundamentals (e.g., AWS Cloud Practitioner) are good early steps.
Maintain a learning log with notes, links, CTF writeups, and sample projects — this becomes your portfolio for interviews.
Python is widely used for scripting and tooling; JavaScript/TypeScript for web security understanding; low-level C/C++ helps for exploit development.
Use sanctioned platforms, never attack third-party infrastructure without permission, and follow legal/ethical guidelines.
With focused study and labs, many people can apply for junior roles in 6–12 months; internships and demonstrable projects accelerate hiring.
“The Web Application Hacker’s Handbook”, OWASP guides, and vendor whitepapers (e.g., AWS security docs) are solid references.
Balance hands-on practice with rest; work on small, achievable projects and join study groups or communities to stay motivated.

This page is a practical learning guide and not a certification pathway by itself. For career transitions, combine hands-on practice, formal coursework and mentorship.