CYBERSECURITY LEARNING ROADMAP

7 Hands-On Platforms to Build Real-World Cybersecurity Skills

These platforms provide hands-on practice that can complement classroom learning and self-study. They combine guided lessons with real labs, so instead of just reading about security concepts, you apply them directly. None of them guarantee a job or a certification — what they give you is genuine, practical repetition, which is what actually builds skill over time.

1. TryHackMe

Platform 1 of 7

TryHackMe

Difficulty: Beginner → Advanced (progressive) Free + Paid (Freemium)

Best for

The most beginner-friendly, structured starting point on this list. TryHackMe teaches through short, guided "rooms" that mix reading material with hands-on virtual machines, so you're never left guessing what to do next.

Main areas

  • Networking and Linux fundamentals
  • Offensive security / penetration testing
  • SOC and defensive security (SOC Level 1 path)
  • Web application security
  • Active Directory attacks, digital forensics, malware basics

What you can practice

  • Basic Linux and networking commands in a browser-based VM
  • Reconnaissance and scanning with tools like Nmap
  • Web vulnerability exploitation in guided labs
  • SIEM-style log analysis and SOC triage (SOC Level 1 path)
  • Building a public profile that tracks completed rooms and paths

Free or paid

Freemium. TryHackMe's official free-rooms page confirms 650+ rooms are free to access with no payment, covering beginner through advanced topics, plus 1 hour of daily browser-based "AttackBox" VM time. The early rooms inside structured paths (Complete Beginner, Pre Security, Cyber Security 101, Jr Penetration Tester, SOC Level 1) are also free to start. Premium (paid) unlocks full paths end-to-end, unlimited AttackBox time, and certificates of completion.

Start here

Create a free account and begin with the Complete Beginner Path or Pre Security Path — both start with free rooms and assume no prior background.

Official resources

Why it is useful

TryHackMe removes the biggest barrier for beginners: not knowing where to start. Every room tells you exactly what to do, which makes it the gentlest on-ramp into hands-on cybersecurity practice on this list, whether your interest leans offensive or defensive.

Recommended for

Complete beginners, career-changers, and anyone who wants heavy guidance before moving to less structured platforms.

2. Hack The Box / HTB Academy

Platform 2 of 7

Hack The Box (HTB Labs) & HTB Academy

HTB Academy: Beginner → Advanced (Tiers 0–IV) HTB Labs: Intermediate → Advanced Free + Paid
Important distinction: HTB Academy and HTB Labs are two separate products with two separate subscriptions. Academy is the structured "classroom" — courses, modules, and step-by-step learning. Labs is the "proving ground" — realistic vulnerable machines with minimal guidance, intended for people who already have foundational skills. Paying for one does not give you access to the other.

Best for

Learners who have outgrown the most basic guided rooms and want a structured, module-based curriculum (Academy) before testing themselves against realistic, mostly unguided machines (Labs).

Main areas

  • Penetration testing methodology
  • Linux and networking fundamentals
  • Active Directory attacks
  • Web application security
  • Advanced offensive security and some defensive/enterprise scenarios (higher tiers)

What you can practice

  • Foundational Linux, networking, and web-request concepts (Tier 0 modules)
  • Interactive, spawn-on-demand targets tied directly to each lesson
  • Progressive skill-building from Tier 0 (absolute beginner) to Tier IV (expert)
  • Independent enumeration and exploitation against realistic machines (Labs)

Free or paid

Freemium, with a somewhat complex pricing structure. HTB Academy uses a "Cubes" currency: every new account starts with free Cubes, and all Tier 0 modules effectively cost nothing because you're refunded the Cubes on completion — so genuine beginner content is free. Higher tiers (I–IV) require either purchasing Cubes or an Academy subscription (a student plan and paid annual plans exist). HTB Labs is a separate product with its own free tier (a limited selection of active machines) and a paid VIP+ tier for full access to the machine library and official write-ups.

Start here — and should a beginner start with Academy first?

Yes. Because HTB Labs is intentionally "sink or swim" with little built-in guidance, most beginners get more value starting with HTB Academy's free Tier 0 modules (Linux Fundamentals, Introduction to Networking, Web Requests) before attempting HTB Labs machines.

Official resources

Why it is useful

Academy gives you a genuine curriculum with hints and interactive targets built directly into the lessons, which is rare at this level of realism. Labs then lets you apply that knowledge under more realistic, less forgiving conditions — closer to what independent penetration testing actually feels like.

Recommended for

Learners who've finished the basics elsewhere (e.g., TryHackMe's early rooms) and want a deeper, more industry-aligned curriculum, eventually progressing to Labs for realistic practice.

3. PortSwigger Web Security Academy

Platform 3 of 7

PortSwigger Web Security Academy

Beginner → Professional (self-paced tracks) Completely Free

Best for

Anyone who wants to specialize specifically in web application security. Built by the makers of Burp Suite, this is widely regarded as one of the most thorough web-security curricula available, and it is entirely free.

Main areas

  • Web application vulnerabilities (SQL injection, XSS, SSRF, XXE, and more)
  • Authentication and access-control flaws
  • API testing and request smuggling
  • Burp Suite usage
  • Modern web security research topics, continuously updated

What you can practice

  • Exploiting real vulnerability classes in safe, purpose-built labs
  • Using Burp Suite (the free Community Edition is enough for most labs)
  • Working through labs ordered from easy to hard within each topic
  • Tracking your progress against a live leaderboard

Free or paid

Completely free. PortSwigger's own materials state the Academy is free of charge, with no paid tier for the learning content itself; Burp Suite Community Edition (also free) is sufficient to complete the large majority of labs. PortSwigger sells a professional edition of Burp Suite separately, but that is a security tool product, not a requirement for the Academy's free training content.

Start here

Begin with the "Getting started" material and the site's topic index, then progress through Cross-Site Scripting and SQL Injection before moving to more advanced topics like SSRF and request smuggling — PortSwigger's own labs are already ordered easy to hard within each topic.

Official resources

Why it is useful

It's built and maintained by the same team behind Burp Suite and led by the author of "The Web Application Hacker's Handbook," so the content reflects real, current vulnerability research rather than generic tutorials — and it costs nothing to access.

Recommended for

Anyone targeting web application security, bug bounty hunting, or application penetration testing specifically.

4. Let'sDefend

Platform 4 of 7

Let'sDefend

Beginner-friendly SOC training Free + Paid (Freemium)
Recent development: Let'sDefend's own website states it has signed an agreement to be acquired by Hack The Box. The platform is still operating and accepting new students as of this guide's writing, but it's worth knowing the ownership is changing, since future pricing or structure could shift.

Best for

People specifically targeting a Security Operations Center (SOC) analyst role, who want to practice inside a simulated SOC environment investigating realistic alerts, rather than attacking systems.

Main areas

  • SOC fundamentals and analyst workflow
  • SIEM-style alert investigation
  • Phishing email analysis
  • Malware analysis fundamentals
  • Incident response, network and Windows/Linux fundamentals for defenders

What you can practice

  • Investigating real, simulated SOC alerts (limited number per month on the free tier)
  • Phishing email triage
  • MITRE ATT&CK-mapped investigation basics
  • Windows and Linux fundamentals from a defender's perspective

Free or paid

Freemium. The Basic tier is always free and includes free courses, challenges, quizzes, and 15 SOC alerts to investigate per month. The paid VIP and VIP+ tiers unlock the full SOC Analyst and Incident Responder learning paths, additional alerts, hands-on labs, and skill assessments. Students get an automatic discount when signing up with a ".edu" email.

Start here

Sign up with a free Basic account and start the SOC Fundamentals course, which explains how a SOC works and which tools analysts use — the platform's own description calls it "a very good start for beginners."

Official resources

Why it is useful

Very few free platforms put you inside an actual simulated SOC dashboard investigating alerts the way a Tier 1 analyst would. That practical framing is exactly what hiring managers for SOC roles want to see evidence of.

Recommended for

Beginners specifically aiming at SOC analyst or blue team entry-level roles rather than offensive security.

5. CyberDefenders

Platform 5 of 7

CyberDefenders

Beginner-friendly to Advanced (less hand-holding) Free + Paid (Freemium)

Best for

Blue team and DFIR (Digital Forensics and Incident Response) practice through investigation-style challenges built on real breach data. It's more independent and less guided than TryHackMe or Let'sDefend, so it works best once you already have some fundamentals.

Main areas

  • Digital forensics and incident response (DFIR)
  • Threat hunting and threat intelligence
  • Malware analysis
  • Network and packet analysis, memory forensics

What you can practice

  • Investigating real-world-style breach scenarios end to end
  • Mapping findings to the MITRE ATT&CK framework and specific CVEs
  • Working with forensic and network-analysis tools inside browser-accessible labs
  • Developing a persistent, methodical investigative mindset rather than following step-by-step instructions

Free or paid

Freemium. CyberDefenders offers a free tier of Blue Team Labs ("Getting Started" beginner content plus community Discord support) alongside a paid "BlueYard Pro" subscription for the full, continuously updated lab library. Separately, the platform offers the Certified CyberDefender (CCD) — a one-time-payment certification program with its own dedicated labs and a 48-hour practical exam, distinct from the subscription-based labs.

Start here

Use the free "Getting Started" category inside Blue Team Labs. Because the platform provides less structured hand-holding than some others on this list, it's most effective as a second step — after you already understand basic networking, logs, and Windows/Linux fundamentals — rather than as your very first cybersecurity resource.

Official resources

Why it is useful

The investigations are modeled on real breaches rather than artificial puzzles, so the skills you build — evidence correlation, timeline reconstruction, tool-based analysis — transfer directly to real DFIR and threat-hunting work.

Recommended for

Learners with some foundational SOC/networking knowledge who want to specialize in forensics, threat hunting, or incident response.

6. KC7

Platform 6 of 7

KC7 (Cyber Detective Game)

Beginner-friendly, scales to Intermediate Completely Free

Best for

Learning to think like a threat intelligence analyst or investigator through story-driven, log-analysis "cases," rather than through traditional lessons. KC7 was created by security professionals (including a Microsoft senior threat intelligence analyst) specifically to make this style of thinking accessible to complete beginners.

Main areas

  • Cyber investigations and threat intelligence
  • Log analysis and querying with KQL (Kusto Query Language)
  • Attack investigation and threat hunting
  • Analytical, evidence-based reasoning

What you can practice

  • Writing KQL queries to search and filter security data
  • Piecing together a full attack narrative from scattered log evidence
  • Using tools like VirusTotal and CyberChef inside realistic investigation scenarios
  • Building the habit of following evidence rather than guessing

Free or paid

Completely free. KC7's own FAQ states plainly that all modules are free to access — "we believe everyone should have the opportunity to learn cybersecurity skills." There is no paid tier for individuals; you just create an account (via Google or Microsoft sign-in) and start.

Start here

Complete the short "How to Play KC7" module first (about 10 minutes, no experience required), then move into the beginner-labeled investigation modules such as VirusTotal Fundamentals.

Official resources

Why it is useful

KC7 does not hand you theory slides — every module is framed as a mystery you investigate using real data and querying skills, which builds the analytical, "why does this evidence matter" mindset that threat intelligence and SOC work actually requires, rather than just memorized facts.

Recommended for

Complete beginners curious about threat intelligence, investigation, or analytical/blue-team roles, and anyone who prefers learning through structured "cases" over reading documentation.

7. TCM Security

Platform 7 of 7

TCM Security Academy

Beginner → Professional certifications Free + Paid (Freemium)

Best for

Practical, no-filler video courses covering ethical hacking, OSINT, SOC operations, and more, with an affordable path to industry certifications that are scenario-based rather than multiple-choice.

Main areas

  • Practical ethical hacking and penetration testing
  • OSINT (open-source intelligence)
  • SOC / security operations fundamentals
  • Web application hacking, bug bounty basics
  • IT and Linux fundamentals for career-changers

What you can practice

  • Foundational IT, Linux, and programming skills (free tier)
  • Reconnaissance, scanning, exploitation basics, and Active Directory attacks (Practical Ethical Hacking course)
  • OSINT investigation techniques
  • Report writing — a skill most other platforms on this list don't teach directly

Free or paid — clearly separated

Completely free content: TCM Security Academy has a dedicated free tier (25+ hours) with four full courses — Practical Help Desk, Programming 100: Fundamentals, Linux 100: Fundamentals, and Soft Skills for the Job Market — plus a separate free version of the flagship Practical Ethical Hacking course (a 12-hour introductory cut of the full paid course) and a free OSINT Fundamentals course on YouTube. No credit card is required for any of this.

Paid content: The complete, longer version of Practical Ethical Hacking, most specialized courses, an "All-Access" monthly/annual membership for unlimited course access, and TCM's practical certifications (e.g., Practical Junior Penetration Tester (PJPT), Practical Network Penetration Tester (PNPT), Practical SOC Analyst Associate (PSAA)) are paid, along with optional live instructor-led training classes.

Start here

Enroll in the free tier first (no card required), then move to the free introductory Practical Ethical Hacking course before deciding whether to invest in the complete paid course or a certification.

Official resources

Why it is useful

TCM's courses are built and taught by working practitioners with a strong focus on what's actually needed on the job — including the often-skipped skill of writing a professional penetration test report — and the certification exams are hands-on rather than multiple choice.

Recommended for

Career-changers who want a structured, affordable video-course path into offensive security or SOC roles, and anyone ready to work toward a practical, resume-relevant certification.

WHICH PLATFORM SHOULD YOU START WITH?

This is a goal-based guide, not a ranking of "best" to "worst." Different platforms simply suit different goals.

Your GoalSuggested PlatformWhy
Complete beginnerTryHackMeMost guided, zero prerequisites, free rooms cover fundamentals step by step.
Penetration testingHTB Academy → HTB LabsAcademy builds structured technical skill; Labs then tests it against realistic, less-guided targets.
Web application securityPortSwigger Web Security AcademyCompletely free, deep, continuously updated, and built by the makers of Burp Suite.
SOC analystLet'sDefendPuts you directly inside a simulated SOC investigating real alerts, the core SOC analyst task.
Blue teamCyberDefendersRealistic, breach-derived investigation challenges once you have basic fundamentals.
Digital forensicsCyberDefendersDFIR-focused labs mapped to real breach data and MITRE ATT&CK.
Threat intelligenceKC7Purpose-built around investigative, evidence-based analytical thinking using real querying tools.
OSINTTCM Security (OSINT Fundamentals)Free, dedicated OSINT course focused on investigative and research methodology.

BEGINNER ROADMAPS

Roadmap 1 — Complete Beginner

Learn first
Basic networking, terminal/Linux commands, and how the web works.
Where to practice
TryHackMe — Complete Beginner Path and Pre Security Path (free rooms).
Learn next
Introductory security concepts: common attack types, basic cryptography, simple recon.
Skill checkpoint before moving on
You can comfortably navigate a Linux terminal, explain how DNS and HTTP work, and complete a full beginner room without hints.

Roadmap 2 — Penetration Testing

Learn first
Networking and Linux fundamentals (TryHackMe Pre Security Path).
Where to practice
HTB Academy Tier 0 modules (Linux Fundamentals, Intro to Networking, Web Requests) — free via the Cubes system.
Learn next
Enumeration and scanning methodology, then web exploitation basics via TryHackMe's Jr Penetration Tester Path.
Skill checkpoint
You can enumerate a target, identify a vulnerability, and exploit it in a guided lab without step-by-step hints.
Then
Move to HTB Labs' easier retired machines and start practicing report writing (TCM Security's Practical Ethical Hacking free course covers documentation).

Roadmap 3 — SOC / Blue Team

Learn first
Security fundamentals and how a SOC operates — Let'sDefend's free SOC Fundamentals course.
Where to practice
TryHackMe SOC Level 1 Path (free intro rooms) for logs, SIEM concepts, and endpoint monitoring basics.
Learn next
Detection and investigation — Let'sDefend's free monthly SOC alerts (15/month on Basic).
Skill checkpoint
You can triage a simulated alert, decide if it's a true or false positive, and document your reasoning.
Then
Progress to CyberDefenders' free "Getting Started" Blue Team Labs for deeper DFIR-style investigation.

Roadmap 4 — Web Security

Learn first
How HTTP requests, cookies, and basic web architecture work.
Where to practice
PortSwigger Web Security Academy, starting with Cross-Site Scripting, then SQL Injection.
Learn next
Authentication and access-control flaws, then SSRF and API-specific vulnerabilities, in PortSwigger's own recommended lab order (easy → hard within each topic).
Skill checkpoint
You can independently identify and exploit a vulnerability class using Burp Suite Community Edition without following a walkthrough.
Complementary resource
TCM Security's OSINT Fundamentals and web-hacking material for a broader offensive skillset alongside pure web-app testing.

Roadmap 5 — Threat Intelligence / Investigation

Learn first
Basic log structure and how analysts query security data.
Where to practice
KC7 — start with "How to Play KC7," then progress through beginner-labeled investigation modules using KQL.
Learn next
Pivoting across data sets, correlating indicators, and using tools like VirusTotal inside realistic KC7 cases.
Skill checkpoint
You can independently reconstruct an attack timeline from raw log evidence and explain your reasoning.
Then
Move into CyberDefenders' threat-hunting and threat-intelligence labs for more advanced, real-breach-based investigation.

FREE STARTER PACK

Every resource below is verified as free (or has a genuinely free tier) directly from the platform's own site.

Complete Beginner Path
TryHackMe

What you learn: absolute cybersecurity fundamentals, no prerequisites. Difficulty: Beginner. Link: tryhackme.com/path/outline/beginner

HTB Academy Tier 0 Modules
Hack The Box

What you learn: Linux Fundamentals, Introduction to Networking, Web Requests. Difficulty: Beginner. Link: academy.hackthebox.com

Full Web Security Academy Curriculum
PortSwigger

What you learn: every major web vulnerability class, with hands-on labs. Difficulty: Beginner to Professional (100% free at every level). Link: portswigger.net/web-security

SOC Fundamentals Course
Let'sDefend

What you learn: how a SOC works and which tools analysts use, plus 15 free alerts/month to investigate. Difficulty: Beginner. Link: letsdefend.io

Getting Started Blue Team Labs
CyberDefenders

What you learn: introductory blue team / DFIR investigation skills. Difficulty: Beginner. Link: cyberdefenders.org/blue-team-labs

How to Play KC7 + beginner modules
KC7

What you learn: investigative thinking and KQL basics. Difficulty: Beginner (entire platform is free). Link: kc7cyber.com

TCM Security Academy Free Tier + Free Practical Ethical Hacking
TCM Security

What you learn: IT/Linux fundamentals, soft skills, and an intro to ethical hacking. Difficulty: Beginner. Link: academy.tcm-sec.com/p/learn-penetration-testing-free

DON'T TRY TO LEARN EVERYTHING AT ONCE

Cybersecurity covers wildly different disciplines — offensive testing, malware analysis, SOC monitoring, OSINT, forensics — and each has its own tools, mindset, and learning curve. Jumping between them every few days means you never build enough depth in any one area to retain what you learned, and progress feels slow even though you're "studying" constantly.

Choosing one track first lets you build a foundation you can actually stand on. Once you're comfortable there, branching out into a second area becomes much easier, because you already understand core concepts like networking, logs, and common attacker behavior that carry over into every specialization.

Learn → Practice → Document → Repeat → Move Forward

Documenting what you did (even briefly, in a notes app or personal blog) is what turns a completed lab into a skill you'll actually remember and can talk about later.

30-DAY STARTER PLAN

Based on roughly 45–90 minutes per day. Adjust the pace to your own schedule — consistency matters more than speed.

Days 1–7: Fundamentals

Work through TryHackMe's Complete Beginner Path and the start of the Pre Security Path (free rooms). Focus on understanding networking basics, the terminal, and how the web works — don't rush past concepts you don't fully understand yet.

Days 8–14: Hands-on beginner labs

Start HTB Academy's free Tier 0 modules (Linux Fundamentals, Introduction to Networking, Web Requests) alongside a few more TryHackMe rooms in the topic that interests you most so far (offensive vs. defensive).

Days 15–21: Choose a specialization

Pick one track based on the goal-based table above. If web security appeals to you, begin PortSwigger's Web Security Academy. If SOC/blue team appeals to you, start Let'sDefend's SOC Fundamentals course and CyberDefenders' Getting Started labs. If investigation/threat intel appeals to you, start KC7's beginner modules.

Days 22–30: Practical investigation/lab work + documentation

Go deeper into your chosen platform from Days 15–21. Complete at least 2–3 more labs or modules in that track, and write a short summary (even just a few paragraphs) for each one — what the scenario was, what you did, and what you learned. If you're leaning offensive, consider starting TCM Security's free introductory Practical Ethical Hacking course as a next step after Day 30.

OFFICIAL RESOURCE DIRECTORY

SOURCES CHECKED