Learning Platforms

Cybersecurity training platforms, CTF sites, and learning paths. Includes HTB Academy, 9 YouTube channels, 5 podcasts, and beginner-to-advanced progression.

#Training Platforms

#Hands-On Labs

Platform Level Free Tier Focus Best For
HackTheBox Intermediate+ Yes (limited) Pentest, AD, Web, RE Real-world pentesting
HTB Academy Beginner+ Yes (limited) Structured learning modules Learning with hands-on labs
PortSwigger Academy All levels Yes (full) Web security (XSS, SQLi...) Web app security
Root-Me All levels Yes (full) CTF challenges, 400+ French community, free
PentesterLab Intermediate Free + paid Web security, code review Web app pentest
PicoCTF Beginner Yes (full) Intro CTF, binary, web Students, first CTF
OverTheWire Beginner+ Yes (full) Linux, networking, crypto CLI and system basics
pwn.college Intermediate Yes (full) Binary exploit, systems ASU course, pwn track
VulnHub Intermediate Yes (full) Vulnerable VMs (offline) Offline practice
CyberDefenders Intermediate Yes (limited) Blue team, DFIR, SOC Defensive security
LetsDefend Beginner+ Yes (limited) SOC analyst training Blue team career
Blue Team Labs Beginner+ Yes (limited) Blue team challenges DFIR, incident response

TryHackMe is intentionally excluded from recommendations. In 2025-2026, TryHackMe used user-generated data (completed challenges, code submissions, problem-solving strategies) to train their commercial AI pentesting tool "Noscope" without explicit user consent. The only opt-out mechanism is full account deletion. We recommend HackTheBox Academy as a superior structured learning alternative.

#CTF Platforms

Platform Type
CTFtime CTF calendar + team rankings
CTFlearn Beginner-friendly challenges
RingZer0 Crypto, steganography, RE
Hacker101 CTF Web security (HackerOne)
CryptoHack Cryptography only
pwnable.kr Binary exploitation
pwnable.tw Advanced binary exploitation
Exploit Education Binary exploit (Phoenix, Nebula)
Crackmes.one Reverse engineering
MalwareTech Challenges RE + malware analysis

#Cloud & Infrastructure

#Active Directory Labs

#Certifications & Courses

#Offensive Certifications

Cert Provider Focus
OSCP OffSec Pentest (gold standard)
OSEP OffSec Advanced evasion
OSWE OffSec Web app exploit dev
OSED OffSec Exploit development
CRTP PentesterAcademy AD attack paths
CRTE PentesterAcademy AD enterprise
CPTS HackTheBox Penetration testing
CBBH HackTheBox Bug bounty hunter
PNPT TCM Security Practical pentest
eWPT INE Web pentest
eCPPT INE Professional pentest
GPEN SANS/GIAC Network pentest
GXPN SANS/GIAC Advanced exploit
BSCP PortSwigger Web security

#Defensive Certifications

Cert Provider Focus
OSDA OffSec SOC detection
BTL1 Security Blue Team Blue team L1
BTL2 Security Blue Team Blue team L2
CCD CyberDefenders DFIR
GCIH SANS/GIAC Incident handling
GCFA SANS/GIAC Forensic analyst
GREM SANS/GIAC Reverse engineering
SC-200 Microsoft Security operations
CySA+ CompTIA Security analyst

#Free Courses

#Learning Paths

#Beginner Path

  • Month 1-2: Linux + Networking fundamentals
    • OverTheWire Bandit (30 levels)
    • HTB Academy "Linux Fundamentals" + "Networking"
    • PicoCTF (general skills)
  • Month 3-4: Web Security basics
    • PortSwigger Academy (apprentice labs)
    • HTB Academy "Web Requests" + "Web Attacks"
    • OWASP Juice Shop
  • Month 5-6: Pentesting intro
    • HTB Academy "Penetration Testing Process"
    • HackTheBox Starting Point
    • VulnHub easy boxes
  • Month 7-9: CTF + specialization
    • Root-Me challenges by category
    • HackTheBox easy/medium boxes
    • Pick a focus: web / AD / binary
  • Month 10-12: Certification prep
    • PNPT or eJPT (entry certs)
    • Build writeup portfolio
    • Participate in CTF competitions

#Advanced Tracks

#Red Team

OSCP -> CRTP -> OSEP -> CRTE
     -> CPTS -> Custom labs

#Web Security

BSCP -> eWPT -> OSWE -> Bug Bounty
     -> PortSwigger all labs

#Malware / RE

GREM -> OSED -> Crackmes.one
     -> MalwareTech challenges
     -> OpenSecurityTraining2

#Blue Team / DFIR

BTL1 -> OSDA -> GCIH -> GCFA
     -> CyberDefenders labs
     -> DetectionLab
  • The Web Application Hacker's Handbook - Stuttard & Pinto
  • Penetration Testing - Georgia Weidman
  • Red Team Field Manual (RTFM) - Ben Clark
  • The Hacker Playbook 3 - Peter Kim
  • Practical Malware Analysis - Sikorski & Honig
  • Active Directory Attacks - Orange Cyberdefense (free PDF)
  • Black Hat Python - Justin Seitz
  • Bug Bounty Bootcamp - Vickie Li

#YouTube Channels

#Community & News

#Podcasts

#Also See

#Cyber Aurelien Guidi

  • Bug Bounty (Bug bounty platforms, methodology, and resources)
  • Nmap (Network scanning and reconnaissance)
  • Metasploit (Exploitation framework cheatsheet)
  • ffuf (Fast web fuzzer for directory and parameter discovery)
  • SQLmap (Automated SQL injection detection and exploitation)
  • Pentest Toolkit (Interactive pentest utilities by phase)