In-depth reading material across all cybersecurity domains. Structured into learning paths from beginner to expert.
Start from zero — navigation, files, permissions, processes, bash basics.
Windows OS, registry, services, file system, and PowerShell basics.
TCP/IP, subnetting, DNS, routing, OSI model, and packet analysis.
How HTTP works: methods, headers, cookies, proxies, and Burp basics.
Variables, functions, loops, file I/O, and scripting for automation.
Shell scripting, conditionals, loops, and automation on Linux.
Kali toolset, configuration, and staying organised during engagements.
The CIA triad, threat actors, vulnerability lifecycle, and security frameworks.
What pentesting is, legal context, scope, phases, and methodology.
Google dorking, Shodan, WHOIS, theHarvester, Maltego, and recon reports.
Scope documents, rules of engagement, and lab environment configuration.
Executive summaries, technical findings, remediation tables, and templates.
How CTFs work, common categories, tools, and tips for first-timers.
macOS architecture, filesystem, security model (SIP, Gatekeeper), and the command line.
ES6+, DOM, async/await, and security implications of JavaScript.
SELECT, INSERT, JOIN, subqueries, and understanding SQL for injection attacks.
Java OOP, JVM, serialisation, and security-relevant Java concepts.
.NET, C# basics, and Windows development context for security work.
Memory management, pointers, and C++ for understanding binary vulnerabilities.
Input validation, output encoding, and secure SDLC practices.
Sockets, subprocess, ctypes, pwntools, and offensive Python scripting.
AD architecture, objects, Kerberos, NTLM, GPOs, and trusts before attacking AD.
Deep dive into AD administration, enumeration, and attack paths.
SUID, sudo, services, tokens, DLL hijacking — complete privesc reference.
Writing detection rules, YARA, Sigma, and tuning for low false positive rates.
Evidence acquisition, chain of custody, disk and memory forensics fundamentals.
Incident lifecycle, communication, containment, eradication, and post-mortems.
Complete SOC analyst track: detection, response, and documentation.
Hypothesis-driven hunting, data sources, TTP mapping, and Elastic/Splunk.
Complete incident response from detection to lessons learned.
Complete web attack track: injection, authentication, client-side, and serialisation.
Advanced techniques: request smuggling, deserialization, prototype pollution, and more.
Full enterprise pentest from external recon to domain dominance.
AV evasion, EDR bypass, AppLocker, AMSI bypass, and living-off-the-land.
Stack overflows, SEH, egghunters, shellcoding on 32-bit Windows.
Heap exploitation, kernel basics, ROP chains, and 64-bit exploits.
Advanced adversarial attacks on AI systems, data poisoning, and model extraction.
Secure Java coding patterns, OWASP Java guidance, and code review.