Skip to content

Where this is going

Roadmap

The tracks I am working through, in order — what each covers, what I actually practise on, and what it has to produce before I call it done.
Every item is ticked off as it is finished. Nothing unticked is presented as experience, which is the same rule the certifications list follows.

Overall

10 of 66 items · 15%

Last updated 15 August 2026

  • Complete
  • In progress
  • Planned
  1. CompleteTwo years

    Web application security

    The base everything else builds on. Over 100 PortSwigger Web Security Academy labs plus CTF work, and bug bounty reporting on HackerOne and Bugcrowd.

    Progress6/6 · 100%
    • Complete:OWASP Top 10Read6h
    • Complete:PortSwigger Web Security Academy — 100+ labsPractice80h
    • Complete:Access control and business logic testingPractice20h
    • Complete:REST and GraphQL API testingPractice15h
    • Complete:RootMe CTF challengesPractice20h
    • Complete:Accepted bug bounty reports on HackerOne and BugcrowdMilestone
  2. In progressIn progress

    Android application security

    Finishing structured mobile training, then a deep review from my own notes — rebuilding exploits unaided rather than re-watching them, and turning the result into a written methodology.

    Progress4/9 · 44%
    • Not started:HexTree Android security courseStudy25h
    • Complete:Static analysis with jadx and ApktoolStudy8h
    • Complete:SMALI modificationStudy6h
    • Complete:Runtime hooking with FridaPractice8h
    • Not started:Broadcast receivers, deeplink hijacking, intent redirectStudy8h
    • Not started:PendingIntent abusePractice4h
    • Complete:SSL pinning bypassPractice5h
    • Not started:Rebuild 3-4 exploits from scratch, no lab solutionPractice12h
    • Not started:Mobile methodology document mapped to OWASP MASTGMilestone10h
  3. Planned~ 2 weeks

    Advanced web topics

    Closing the specific gaps rather than revising what I already know. Expert-level labs only, in the seven areas that are genuinely harder than the day-to-day.

    Progress0/8 · 0%
    • Not started:HTTP request smuggling — Expert labsPractice6h
    • Not started:Prototype pollution — Expert labsPractice5h
    • Not started:Insecure deserialization — Expert labsPractice5h
    • Not started:OAuth and OIDC flaws — Expert labsPractice6h
    • Not started:Race conditions — Expert labsPractice5h
    • Not started:Web cache poisoning — Expert labsPractice5h
    • Not started:GraphQL — Expert labsPractice4h
    • Not started:Published writeups from the gap topicsMilestone
  4. Planned~ 6 weeks

    AI and LLM security

    Not started. Foundation first — the OWASP LLM Top 10 read end to end rather than in summary — then agentic attacks, tooling, and red-teaming my own production agent stack.

    Progress0/12 · 0%
    • Not started:OWASP Top 10 for LLM Applications, end to endRead8h
    • Not started:PortSwigger Academy — Web LLM attacks, every labPractice10h
    • Not started:Prompt injection depth — direct and indirectRead8h
    • Not started:Gandalf and HackAPromptPractice5h
    • Not started:MITRE ATLASStudy6h
    • Not started:OWASP LLM to MITRE ATLAS mapping table, built by handMilestone6h
    • Not started:OWASP Agentic Security Initiative taxonomyRead6h
    • Not started:Damn Vulnerable LLM Agent and AI GoatPractice8h
    • Not started:Garak, PyRIT and promptfoo against one targetPractice10h
    • Not started:Red-team my own agent stack for indirect injectionMilestone12h
    • Not started:AI red-team methodology repositoryMilestone12h
    • Not started:First huntr or 0din submissionMilestone
  5. Planned~ 4 weeks

    Network penetration testing

    Not started. Fundamentals and enumeration first, then service exploitation, then volume on retired machines — finishing with a methodology document of my own.

    Progress0/9 · 0%
    • Not started:TCM Security — Practical Ethical HackingStudy25h
    • Not started:Protocols and enumeration methodologyStudy8h
    • Not started:Nmap in depthPractice6h
    • Not started:SMB, SSH, FTP and SNMP exploitationPractice10h
    • Not started:Privilege escalationPractice10h
    • Not started:Retired HackTheBox machines with published writeupsPractice20h
    • Not started:Proving Grounds Practice for volumePractice20h
    • Not started:~10 machines rootedMilestone
    • Not started:Network methodology documentMilestone8h
  6. Planned2-3 months

    Active Directory

    Target: CRTP

    Not started hands-on, though the concepts sit close to work I have already done administering AD. Theory first, then a full lab.

    Progress0/6 · 0%
    • Not started:Kerberos and delegationStudy10h
    • Not started:Trust relationshipsStudy6h
    • Not started:Attack path analysisStudy8h
    • Not started:GOAD labPractice40h
    • Not started:thehacker.recipes and adsecurity.orgRead12h
    • Not started:CRTP certificationMilestone
  7. PlannedPaired with AD

    Network defence

    Not started. Deliberately paired with the offensive work: build the lab, attack it, then change seats and read what the defence actually saw.

    Progress0/5 · 0%
    • Not started:Build the lab: pfSense, Suricata and WazuhPractice15h
    • Not started:Firewall policy and segmentationStudy6h
    • Not started:IDS and IPS tuningStudy8h
    • Not started:Detection engineeringStudy10h
    • Not started:Attack the lab, then review the alerts it raisedMilestone12h
  8. PlannedPaired with AD

    Digital forensics and incident response

    Not started. The other half of the pairing method — forensicate my own attacks, so the offensive work and the artefacts it leaves behind are learned as one subject.

    Progress0/5 · 0%
    • Not started:13Cubed — Windows forensicsStudy20h
    • Not started:CyberDefenders blue team labsPractice20h
    • Not started:NIST 800-61 incident handling processRead6h
    • Not started:thedfirreport.com intrusion reportsRead10h
    • Not started:Forensicate the intrusions from my own labMilestone15h
  9. Planned2-3 months

    Cloud security

    Not started, and last on purpose: it needs continuous lab time rather than short sessions. AWS first, then Azure.

    Progress0/6 · 0%
    • Not started:flaws.cloudPractice8h
    • Not started:CloudGoatPractice15h
    • Not started:AzureGoatPractice15h
    • Not started:Pwned LabsPractice15h
    • Not started:IAM privilege escalationStudy10h
    • Not started:Cloud attack path writeupsMilestone

How I study


The method matters more than the material list. These are the rules the plan above is built on.

One topic at a time

Running two tracks in parallel means finishing neither, and the second is always the one dropped quietly. Small and daily beats a weekend sprint that never repeats.

Notes are written during the work

Fifteen minutes per session, never skipped. The notes are the deliverable, not a by-product — every deep review afterwards depends entirely on them existing.

Rewrite from memory before re-reading

For a real review, rewrite the notes from memory first, then compare. The gap between the two is exactly what was never learned. Re-watching a video hides that gap instead of exposing it.

Explain the why in two sentences

For every technique: why it works, not the steps. If it cannot be explained in two sentences, it was watched rather than learned.

Rebuild exploits unaided

Three or four from scratch with the solution closed. This is where understanding actually forms, and it is the difference between having completed a course and being able to do the work.

Reload, then close out

Study time comes in separated blocks, so each one opens by re-reading the last set of notes and re-running one solved exercise before touching new material, and ends by writing everything up as if for someone else.

Attack, then change seats

For anything with a defensive counterpart: attack the lab, then read the logs, alerts and memory the attack just polluted. That loop is why defence and forensics are worth studying without a certificate attached.

Every track ends in a document

A methodology, a writeup, or a repository someone else could follow. Finishing a course proves attendance; a document another tester can use proves rather more.

Where this ends up


The offensive tracks and their defensive counterparts are deliberately paired rather than separated. Network defence sits with Active Directory; forensics sits with the intrusions that generate the artefacts. Learning the attack and the trace it leaves as one subject is the point.

Certifications appear where the plan names one, and only there. Most of these tracks end in a written methodology instead — the more useful artefact, and the harder one to fake.

Current capabilitiesCertifications held