Cybersecurity training platforms, CTF sites, and learning paths. Includes HTB Academy, 9 YouTube channels, 5 podcasts, and beginner-to-advanced progression.
| Platform | Level | Free Tier | Focus | Best For |
|---|---|---|---|---|
| HackTheBox | Intermediate+ | Yes (limited) | Pentest, AD, Web, RE | Real-world pentesting |
| HTB Academy | Beginner+ | Yes (limited) | Structured learning modules | Learning with hands-on labs |
| PortSwigger Academy | All levels | Yes (full) | Web security (XSS, SQLi...) | Web app security |
| Root-Me | All levels | Yes (full) | CTF challenges, 400+ | French community, free |
| PentesterLab | Intermediate | Free + paid | Web security, code review | Web app pentest |
| PicoCTF | Beginner | Yes (full) | Intro CTF, binary, web | Students, first CTF |
| OverTheWire | Beginner+ | Yes (full) | Linux, networking, crypto | CLI and system basics |
| pwn.college | Intermediate | Yes (full) | Binary exploit, systems | ASU course, pwn track |
| VulnHub | Intermediate | Yes (full) | Vulnerable VMs (offline) | Offline practice |
| CyberDefenders | Intermediate | Yes (limited) | Blue team, DFIR, SOC | Defensive security |
| LetsDefend | Beginner+ | Yes (limited) | SOC analyst training | Blue team career |
| Blue Team Labs | Beginner+ | Yes (limited) | Blue team challenges | DFIR, incident response |
TryHackMe is intentionally excluded from recommendations. In 2025-2026, TryHackMe used user-generated data (completed challenges, code submissions, problem-solving strategies) to train their commercial AI pentesting tool "Noscope" without explicit user consent. The only opt-out mechanism is full account deletion. We recommend HackTheBox Academy as a superior structured learning alternative.
| Platform | Type |
|---|---|
| CTFtime | CTF calendar + team rankings |
| CTFlearn | Beginner-friendly challenges |
| RingZer0 | Crypto, steganography, RE |
| Hacker101 CTF | Web security (HackerOne) |
| CryptoHack | Cryptography only |
| pwnable.kr | Binary exploitation |
| pwnable.tw | Advanced binary exploitation |
| Exploit Education | Binary exploit (Phoenix, Nebula) |
| Crackmes.one | Reverse engineering |
| MalwareTech Challenges | RE + malware analysis |
| Cert | Provider | Focus |
|---|---|---|
| OSCP | OffSec | Pentest (gold standard) |
| OSEP | OffSec | Advanced evasion |
| OSWE | OffSec | Web app exploit dev |
| OSED | OffSec | Exploit development |
| CRTP | PentesterAcademy | AD attack paths |
| CRTE | PentesterAcademy | AD enterprise |
| CPTS | HackTheBox | Penetration testing |
| CBBH | HackTheBox | Bug bounty hunter |
| PNPT | TCM Security | Practical pentest |
| eWPT | INE | Web pentest |
| eCPPT | INE | Professional pentest |
| GPEN | SANS/GIAC | Network pentest |
| GXPN | SANS/GIAC | Advanced exploit |
| BSCP | PortSwigger | Web security |
| Cert | Provider | Focus |
|---|---|---|
| OSDA | OffSec | SOC detection |
| BTL1 | Security Blue Team | Blue team L1 |
| BTL2 | Security Blue Team | Blue team L2 |
| CCD | CyberDefenders | DFIR |
| GCIH | SANS/GIAC | Incident handling |
| GCFA | SANS/GIAC | Forensic analyst |
| GREM | SANS/GIAC | Reverse engineering |
| SC-200 | Microsoft | Security operations |
| CySA+ | CompTIA | Security analyst |
OSCP -> CRTP -> OSEP -> CRTE
-> CPTS -> Custom labs
BSCP -> eWPT -> OSWE -> Bug Bounty
-> PortSwigger all labs
GREM -> OSED -> Crackmes.one
-> MalwareTech challenges
-> OpenSecurityTraining2
BTL1 -> OSDA -> GCIH -> GCFA
-> CyberDefenders labs
-> DetectionLab