Sifrsec Logo SifrSec
Structured Learning Pathway

Cybersecurity Roadmap

From Fundamental IT Competencies to Advanced Cyber Security Engineering

Master the foundational technical domains, protocols, security frameworks, threat hunting, incident response, and professional certifications required for modern security operations.

11
Core Modules
50+
Security Tools
10+
Certifications

01 Fundamental IT Skills

Core hardware, software ecosystems, and basic networking principles prerequisite to cybersecurity.

Hardware & Connectivity

Foundation

Software Suites

Productivity

Networking Basics

Essential

02 Operating Systems

OS architecture, command line navigation, permission models, and system administration.

Core OS Platforms

Platforms

Master operating system management across the major enterprise platforms:

Windows Linux macOS

Core Competencies

Skills

03 Networking Knowledge & Protocols

Deep dive into network architectures, protocols, routing, subnetting, and network services.

Core Concepts

Theory

IP & Subnetting

Addressing

Core Network Services

Services

Network Infrastructure & Terms

Infrastructure
VLAN DMZ ARP VM Router Switch VPN MAN LAN WAN WLAN
Topologies:
Star Ring Mesh Bus

Protocols & Port Mappings

Protocols
SSH (22) RDP (3389) FTP (20/21) SFTP (22) HTTP (80) HTTPS (443) SSL / TLS

04 Virtualization & Troubleshooting Tools

Lab setup technologies, essential network inspection command line utilities, and authentication identity systems.

Virtualization Tech & Concepts

Lab Setup
Platforms:
VMware VirtualBox ESXi Proxmox
Concepts:

Tool Categories

Categories

Authentication Methodologies

Identity
Essential Network & Security Diagnostic Utilities
sys-admin@sec-lab:~$ ipconfig | ping | dig | netstat | route | nmap | tcpdump | arp | tracert | nslookup | iptables
ipconfig ping dig netstat route nmap tcpdump arp tracert nslookup iptables

05 Practice Platforms

Hands-on cyber ranges, CTF arenas, and vulnerable lab environments to test offensive and defensive skills.

HTB

HackTheBox

Penetration testing labs, vulnerable boxes, and enterprise cyber range labs.

THM

TryHackMe

Guided hands-on cybersecurity learning paths and defensive/offensive rooms.

VH

VulnHub

Downloadable vulnerable virtual machines for offline boot-to-root practice.

CTF

picoCTF

Carnegie Mellon's cybersecurity competition platform for beginner-to-intermediate CTFs.

SANS

SANS Holiday Hack

Annual Christmas cybersecurity challenges, games, and scenario-based training.

06 Security Skills & Knowledge

Enterprise security frameworks, defense mechanisms, threat intelligence, and wireless protocols.

Frameworks & Paradigms

Architecture
Compliance Standards:
ISO NIST RMF CIS CSF

Concepts & Methodologies

Core Skills

Security Controls & Tech

Defensive Tech
Antivirus Antimalware EDR DLP Firewalls / NGFW HIPS NIDS NIPS Sandboxing Honeypots MFA & 2FA

Wireless & Auth Protocols

Wireless
EAP vs PEAP WPS WPA / WPA2 / WPA3 WEP ACLs

07 Attack Vectors & Common Attacks

Understanding threat actor techniques, social engineering vectors, and exploitation methods.

Social Engineering

Human Vector

Attack Types

Threat Categories

Common Exploits

Technical Exploits
DoS / DDoS MITM CSRF Spoofing SQL Injection XSS Evil Twin VLAN Hopping DNS Poisoning Deauth Attack Replay Attack Rogue AP Buffer Overflow Memory Leak Pass the Hash Directory Traversal

08 Incident Response, Discovery & Hardening

Digital forensics, log analysis, system hardening, and incident response life cycle.

Incident Response Phases

IR Life Cycle
1. Preparation
Establish IR policy, tools, communication channels, and response team roles.
2. Identification
Detect security breaches, analyze indicators of compromise (IOCs), and confirm incidents.
3. Containment
Isolate affected systems to prevent threat propagation (Short-term & Long-term).
4. Eradication
Remove malware, close vulnerabilities, and eliminate threat presence completely.
5. Recovery
Restore systems from verified backups, monitor for abnormal activity, and resume production.
6. Lessons Learned
Conduct post-incident reviews, update runbooks, and improve security posture.

Forensics & Response Tools

Forensics
nmap wireshark autopsy memdump FTK Imager winhex hping grep cat dd curl nslookup tracert
Living Off The Land (LOTL):
LOLBAS GTFOBINS WADCOMS
Online Inspection Tools:
VirusTotal urlscan any.run Joe Sandbox urlvoid WHOIS

Log Sources & Hardening

Defensive Hardening
Log Sources:
Event Logs Syslog NetFlow Packet Captures Firewall Logs
Hardening Practices:

Stakeholders & Communication

Organization

Incident response communication channels and key organizational stakeholders:

Executive Management Stakeholders Human Resources (HR) Legal Team Compliance & Auditors

09 Cloud Security & Infrastructure

Cloud service models, multi-cloud architectures, storage security, and IaC deployment pipelines.

Service Models

Models

Deployment Models

Deployment

Major Providers

Hyperscalers
AWS (Amazon Web Services) GCP (Google Cloud Platform) Azure (Microsoft Azure)

Cloud Concepts

Concepts

Cloud Storage Solutions

Storage
AWS S3 Dropbox Google Drive OneDrive Box iCloud

10 Programming Skills

Essential scripting and programming languages for tool building, exploit development, and automation.

Recommended Languages for Cybersecurity

Scripting & Dev
PY

Python

Primary language for scripting, exploit writing, automation, and malware analysis.

GO

Go (Golang)

High-performance security tools, network scanners, and cloud native utilities.

JS

JavaScript

Web application security testing, DOM analysis, and OWASP vulnerability research.

C++

C / C++

Low-level memory management, reverse engineering, buffer overflow analysis, and malware development.

SH

Bash

Linux command-line automation, system administration, and shell scripting.

PS

PowerShell

Windows enterprise administration, Active Directory management, and threat hunting.

11 Certifications

Industry-recognized professional certifications for career progression from entry-level to expert.

Beginner Certifications

Foundational

Advanced Certifications

Professional