Notes
Pick a topic below. New here? Follow the Roadmap for the recommended order.
Foundations
Networking Basics
Linux for Security
Security Analyst Basics
Recon and Enumeration
Enumeration Basics
Nmap Basics
OSINT Basics
Web Application Security
Web Application Testing Basics
Burp Suite Basics
Authentication and Sessions
SQL Injection Basics
XSS Basics
Attack Tools and Techniques
Password Attacks Basics
Metasploit Basics
Blue Team and Detection
Log Analysis Basics
SIEM Basics
Incident Response Basics
Advanced Topics
Privilege Escalation Intro
Active Directory Basics
Red Teaming vs Pentesting
Web Vulnerabilities — Advanced
File Inclusion — LFI and RFI
Command Injection
SSRF — Server-Side Request Forgery
CSRF — Cross-Site Request Forgery
XXE — XML External Entity
IDOR — Insecure Direct Object Reference
Tools and Workflow
Gobuster Basics
ffuf — Fast Web Fuzzer
Wireshark Basics
Netcat and Socat
CyberChef Guide
CTF and Practice
CTF Tips for Beginners
More Notes
More notes are being added regularly. Join the Discussions to suggest what to add next or check the Roadmap to see what is coming soon.