CYBERSECURITY LEARNING ROADMAP
7 Hands-On Platforms to Build Real-World Cybersecurity Skills
These platforms provide hands-on practice that can complement classroom learning and self-study. They combine guided lessons with real labs, so instead of just reading about security concepts, you apply them directly. None of them guarantee a job or a certification — what they give you is genuine, practical repetition, which is what actually builds skill over time.
1. TryHackMe
TryHackMe
Best for
The most beginner-friendly, structured starting point on this list. TryHackMe teaches through short, guided "rooms" that mix reading material with hands-on virtual machines, so you're never left guessing what to do next.
Main areas
- Networking and Linux fundamentals
- Offensive security / penetration testing
- SOC and defensive security (SOC Level 1 path)
- Web application security
- Active Directory attacks, digital forensics, malware basics
What you can practice
- Basic Linux and networking commands in a browser-based VM
- Reconnaissance and scanning with tools like Nmap
- Web vulnerability exploitation in guided labs
- SIEM-style log analysis and SOC triage (SOC Level 1 path)
- Building a public profile that tracks completed rooms and paths
Free or paid
Freemium. TryHackMe's official free-rooms page confirms 650+ rooms are free to access with no payment, covering beginner through advanced topics, plus 1 hour of daily browser-based "AttackBox" VM time. The early rooms inside structured paths (Complete Beginner, Pre Security, Cyber Security 101, Jr Penetration Tester, SOC Level 1) are also free to start. Premium (paid) unlocks full paths end-to-end, unlimited AttackBox time, and certificates of completion.
Start here
Create a free account and begin with the Complete Beginner Path or Pre Security Path — both start with free rooms and assume no prior background.
Official resources
Why it is useful
TryHackMe removes the biggest barrier for beginners: not knowing where to start. Every room tells you exactly what to do, which makes it the gentlest on-ramp into hands-on cybersecurity practice on this list, whether your interest leans offensive or defensive.
Recommended for
Complete beginners, career-changers, and anyone who wants heavy guidance before moving to less structured platforms.
2. Hack The Box / HTB Academy
Hack The Box (HTB Labs) & HTB Academy
Best for
Learners who have outgrown the most basic guided rooms and want a structured, module-based curriculum (Academy) before testing themselves against realistic, mostly unguided machines (Labs).
Main areas
- Penetration testing methodology
- Linux and networking fundamentals
- Active Directory attacks
- Web application security
- Advanced offensive security and some defensive/enterprise scenarios (higher tiers)
What you can practice
- Foundational Linux, networking, and web-request concepts (Tier 0 modules)
- Interactive, spawn-on-demand targets tied directly to each lesson
- Progressive skill-building from Tier 0 (absolute beginner) to Tier IV (expert)
- Independent enumeration and exploitation against realistic machines (Labs)
Free or paid
Freemium, with a somewhat complex pricing structure. HTB Academy uses a "Cubes" currency: every new account starts with free Cubes, and all Tier 0 modules effectively cost nothing because you're refunded the Cubes on completion — so genuine beginner content is free. Higher tiers (I–IV) require either purchasing Cubes or an Academy subscription (a student plan and paid annual plans exist). HTB Labs is a separate product with its own free tier (a limited selection of active machines) and a paid VIP+ tier for full access to the machine library and official write-ups.
Start here — and should a beginner start with Academy first?
Yes. Because HTB Labs is intentionally "sink or swim" with little built-in guidance, most beginners get more value starting with HTB Academy's free Tier 0 modules (Linux Fundamentals, Introduction to Networking, Web Requests) before attempting HTB Labs machines.
Official resources
Why it is useful
Academy gives you a genuine curriculum with hints and interactive targets built directly into the lessons, which is rare at this level of realism. Labs then lets you apply that knowledge under more realistic, less forgiving conditions — closer to what independent penetration testing actually feels like.
Recommended for
Learners who've finished the basics elsewhere (e.g., TryHackMe's early rooms) and want a deeper, more industry-aligned curriculum, eventually progressing to Labs for realistic practice.
3. PortSwigger Web Security Academy
PortSwigger Web Security Academy
Best for
Anyone who wants to specialize specifically in web application security. Built by the makers of Burp Suite, this is widely regarded as one of the most thorough web-security curricula available, and it is entirely free.
Main areas
- Web application vulnerabilities (SQL injection, XSS, SSRF, XXE, and more)
- Authentication and access-control flaws
- API testing and request smuggling
- Burp Suite usage
- Modern web security research topics, continuously updated
What you can practice
- Exploiting real vulnerability classes in safe, purpose-built labs
- Using Burp Suite (the free Community Edition is enough for most labs)
- Working through labs ordered from easy to hard within each topic
- Tracking your progress against a live leaderboard
Free or paid
Completely free. PortSwigger's own materials state the Academy is free of charge, with no paid tier for the learning content itself; Burp Suite Community Edition (also free) is sufficient to complete the large majority of labs. PortSwigger sells a professional edition of Burp Suite separately, but that is a security tool product, not a requirement for the Academy's free training content.
Start here
Begin with the "Getting started" material and the site's topic index, then progress through Cross-Site Scripting and SQL Injection before moving to more advanced topics like SSRF and request smuggling — PortSwigger's own labs are already ordered easy to hard within each topic.
Official resources
Why it is useful
It's built and maintained by the same team behind Burp Suite and led by the author of "The Web Application Hacker's Handbook," so the content reflects real, current vulnerability research rather than generic tutorials — and it costs nothing to access.
Recommended for
Anyone targeting web application security, bug bounty hunting, or application penetration testing specifically.
4. Let'sDefend
Let'sDefend
Best for
People specifically targeting a Security Operations Center (SOC) analyst role, who want to practice inside a simulated SOC environment investigating realistic alerts, rather than attacking systems.
Main areas
- SOC fundamentals and analyst workflow
- SIEM-style alert investigation
- Phishing email analysis
- Malware analysis fundamentals
- Incident response, network and Windows/Linux fundamentals for defenders
What you can practice
- Investigating real, simulated SOC alerts (limited number per month on the free tier)
- Phishing email triage
- MITRE ATT&CK-mapped investigation basics
- Windows and Linux fundamentals from a defender's perspective
Free or paid
Freemium. The Basic tier is always free and includes free courses, challenges, quizzes, and 15 SOC alerts to investigate per month. The paid VIP and VIP+ tiers unlock the full SOC Analyst and Incident Responder learning paths, additional alerts, hands-on labs, and skill assessments. Students get an automatic discount when signing up with a ".edu" email.
Start here
Sign up with a free Basic account and start the SOC Fundamentals course, which explains how a SOC works and which tools analysts use — the platform's own description calls it "a very good start for beginners."
Official resources
Why it is useful
Very few free platforms put you inside an actual simulated SOC dashboard investigating alerts the way a Tier 1 analyst would. That practical framing is exactly what hiring managers for SOC roles want to see evidence of.
Recommended for
Beginners specifically aiming at SOC analyst or blue team entry-level roles rather than offensive security.
5. CyberDefenders
CyberDefenders
Best for
Blue team and DFIR (Digital Forensics and Incident Response) practice through investigation-style challenges built on real breach data. It's more independent and less guided than TryHackMe or Let'sDefend, so it works best once you already have some fundamentals.
Main areas
- Digital forensics and incident response (DFIR)
- Threat hunting and threat intelligence
- Malware analysis
- Network and packet analysis, memory forensics
What you can practice
- Investigating real-world-style breach scenarios end to end
- Mapping findings to the MITRE ATT&CK framework and specific CVEs
- Working with forensic and network-analysis tools inside browser-accessible labs
- Developing a persistent, methodical investigative mindset rather than following step-by-step instructions
Free or paid
Freemium. CyberDefenders offers a free tier of Blue Team Labs ("Getting Started" beginner content plus community Discord support) alongside a paid "BlueYard Pro" subscription for the full, continuously updated lab library. Separately, the platform offers the Certified CyberDefender (CCD) — a one-time-payment certification program with its own dedicated labs and a 48-hour practical exam, distinct from the subscription-based labs.
Start here
Use the free "Getting Started" category inside Blue Team Labs. Because the platform provides less structured hand-holding than some others on this list, it's most effective as a second step — after you already understand basic networking, logs, and Windows/Linux fundamentals — rather than as your very first cybersecurity resource.
Official resources
Why it is useful
The investigations are modeled on real breaches rather than artificial puzzles, so the skills you build — evidence correlation, timeline reconstruction, tool-based analysis — transfer directly to real DFIR and threat-hunting work.
Recommended for
Learners with some foundational SOC/networking knowledge who want to specialize in forensics, threat hunting, or incident response.
6. KC7
KC7 (Cyber Detective Game)
Best for
Learning to think like a threat intelligence analyst or investigator through story-driven, log-analysis "cases," rather than through traditional lessons. KC7 was created by security professionals (including a Microsoft senior threat intelligence analyst) specifically to make this style of thinking accessible to complete beginners.
Main areas
- Cyber investigations and threat intelligence
- Log analysis and querying with KQL (Kusto Query Language)
- Attack investigation and threat hunting
- Analytical, evidence-based reasoning
What you can practice
- Writing KQL queries to search and filter security data
- Piecing together a full attack narrative from scattered log evidence
- Using tools like VirusTotal and CyberChef inside realistic investigation scenarios
- Building the habit of following evidence rather than guessing
Free or paid
Completely free. KC7's own FAQ states plainly that all modules are free to access — "we believe everyone should have the opportunity to learn cybersecurity skills." There is no paid tier for individuals; you just create an account (via Google or Microsoft sign-in) and start.
Start here
Complete the short "How to Play KC7" module first (about 10 minutes, no experience required), then move into the beginner-labeled investigation modules such as VirusTotal Fundamentals.
Official resources
Why it is useful
KC7 does not hand you theory slides — every module is framed as a mystery you investigate using real data and querying skills, which builds the analytical, "why does this evidence matter" mindset that threat intelligence and SOC work actually requires, rather than just memorized facts.
Recommended for
Complete beginners curious about threat intelligence, investigation, or analytical/blue-team roles, and anyone who prefers learning through structured "cases" over reading documentation.
7. TCM Security
TCM Security Academy
Best for
Practical, no-filler video courses covering ethical hacking, OSINT, SOC operations, and more, with an affordable path to industry certifications that are scenario-based rather than multiple-choice.
Main areas
- Practical ethical hacking and penetration testing
- OSINT (open-source intelligence)
- SOC / security operations fundamentals
- Web application hacking, bug bounty basics
- IT and Linux fundamentals for career-changers
What you can practice
- Foundational IT, Linux, and programming skills (free tier)
- Reconnaissance, scanning, exploitation basics, and Active Directory attacks (Practical Ethical Hacking course)
- OSINT investigation techniques
- Report writing — a skill most other platforms on this list don't teach directly
Free or paid — clearly separated
Completely free content: TCM Security Academy has a dedicated free tier (25+ hours) with four full courses — Practical Help Desk, Programming 100: Fundamentals, Linux 100: Fundamentals, and Soft Skills for the Job Market — plus a separate free version of the flagship Practical Ethical Hacking course (a 12-hour introductory cut of the full paid course) and a free OSINT Fundamentals course on YouTube. No credit card is required for any of this.
Paid content: The complete, longer version of Practical Ethical Hacking, most specialized courses, an "All-Access" monthly/annual membership for unlimited course access, and TCM's practical certifications (e.g., Practical Junior Penetration Tester (PJPT), Practical Network Penetration Tester (PNPT), Practical SOC Analyst Associate (PSAA)) are paid, along with optional live instructor-led training classes.
Start here
Enroll in the free tier first (no card required), then move to the free introductory Practical Ethical Hacking course before deciding whether to invest in the complete paid course or a certification.
Official resources
Why it is useful
TCM's courses are built and taught by working practitioners with a strong focus on what's actually needed on the job — including the often-skipped skill of writing a professional penetration test report — and the certification exams are hands-on rather than multiple choice.
Recommended for
Career-changers who want a structured, affordable video-course path into offensive security or SOC roles, and anyone ready to work toward a practical, resume-relevant certification.
WHICH PLATFORM SHOULD YOU START WITH?
This is a goal-based guide, not a ranking of "best" to "worst." Different platforms simply suit different goals.
| Your Goal | Suggested Platform | Why |
|---|---|---|
| Complete beginner | TryHackMe | Most guided, zero prerequisites, free rooms cover fundamentals step by step. |
| Penetration testing | HTB Academy → HTB Labs | Academy builds structured technical skill; Labs then tests it against realistic, less-guided targets. |
| Web application security | PortSwigger Web Security Academy | Completely free, deep, continuously updated, and built by the makers of Burp Suite. |
| SOC analyst | Let'sDefend | Puts you directly inside a simulated SOC investigating real alerts, the core SOC analyst task. |
| Blue team | CyberDefenders | Realistic, breach-derived investigation challenges once you have basic fundamentals. |
| Digital forensics | CyberDefenders | DFIR-focused labs mapped to real breach data and MITRE ATT&CK. |
| Threat intelligence | KC7 | Purpose-built around investigative, evidence-based analytical thinking using real querying tools. |
| OSINT | TCM Security (OSINT Fundamentals) | Free, dedicated OSINT course focused on investigative and research methodology. |
BEGINNER ROADMAPS
Roadmap 1 — Complete Beginner
Roadmap 2 — Penetration Testing
Roadmap 3 — SOC / Blue Team
Roadmap 4 — Web Security
Roadmap 5 — Threat Intelligence / Investigation
FREE STARTER PACK
Every resource below is verified as free (or has a genuinely free tier) directly from the platform's own site.
What you learn: absolute cybersecurity fundamentals, no prerequisites. Difficulty: Beginner. Link: tryhackme.com/path/outline/beginner
What you learn: Linux Fundamentals, Introduction to Networking, Web Requests. Difficulty: Beginner. Link: academy.hackthebox.com
What you learn: every major web vulnerability class, with hands-on labs. Difficulty: Beginner to Professional (100% free at every level). Link: portswigger.net/web-security
What you learn: how a SOC works and which tools analysts use, plus 15 free alerts/month to investigate. Difficulty: Beginner. Link: letsdefend.io
What you learn: introductory blue team / DFIR investigation skills. Difficulty: Beginner. Link: cyberdefenders.org/blue-team-labs
What you learn: investigative thinking and KQL basics. Difficulty: Beginner (entire platform is free). Link: kc7cyber.com
What you learn: IT/Linux fundamentals, soft skills, and an intro to ethical hacking. Difficulty: Beginner. Link: academy.tcm-sec.com/p/learn-penetration-testing-free
DON'T TRY TO LEARN EVERYTHING AT ONCE
Cybersecurity covers wildly different disciplines — offensive testing, malware analysis, SOC monitoring, OSINT, forensics — and each has its own tools, mindset, and learning curve. Jumping between them every few days means you never build enough depth in any one area to retain what you learned, and progress feels slow even though you're "studying" constantly.
Choosing one track first lets you build a foundation you can actually stand on. Once you're comfortable there, branching out into a second area becomes much easier, because you already understand core concepts like networking, logs, and common attacker behavior that carry over into every specialization.
Documenting what you did (even briefly, in a notes app or personal blog) is what turns a completed lab into a skill you'll actually remember and can talk about later.
30-DAY STARTER PLAN
Based on roughly 45–90 minutes per day. Adjust the pace to your own schedule — consistency matters more than speed.
Work through TryHackMe's Complete Beginner Path and the start of the Pre Security Path (free rooms). Focus on understanding networking basics, the terminal, and how the web works — don't rush past concepts you don't fully understand yet.
Start HTB Academy's free Tier 0 modules (Linux Fundamentals, Introduction to Networking, Web Requests) alongside a few more TryHackMe rooms in the topic that interests you most so far (offensive vs. defensive).
Pick one track based on the goal-based table above. If web security appeals to you, begin PortSwigger's Web Security Academy. If SOC/blue team appeals to you, start Let'sDefend's SOC Fundamentals course and CyberDefenders' Getting Started labs. If investigation/threat intel appeals to you, start KC7's beginner modules.
Go deeper into your chosen platform from Days 15–21. Complete at least 2–3 more labs or modules in that track, and write a short summary (even just a few paragraphs) for each one — what the scenario was, what you did, and what you learned. If you're leaning offensive, consider starting TCM Security's free introductory Practical Ethical Hacking course as a next step after Day 30.
OFFICIAL RESOURCE DIRECTORY
TryHackMe
Main site: https://tryhackme.com/
- Free rooms: https://tryhackme.com/free-rooms
- Complete Beginner Path: https://tryhackme.com/path/outline/beginner
- Pre Security Path: https://tryhackme.com/path/outline/presecurity
- SOC Level 1 Path: https://tryhackme.com/path/outline/soclevel1
Hack The Box / HTB Academy
Main site: https://www.hackthebox.com/
- HTB Academy: https://academy.hackthebox.com/
- Academy FAQ (Cubes): https://academy.hackthebox.com/faq
- HTB Labs pricing: https://www.hackthebox.com/pricing
PortSwigger Web Security Academy
Main site: https://portswigger.net/web-security
- All labs: https://portswigger.net/web-security/all-labs
- Learning paths: https://portswigger.net/web-security/learning-paths
Let'sDefend
Main site: https://letsdefend.io/
- SOC Analyst career path: https://letsdefend.io/soc-analyst-career
- Pricing: https://app.letsdefend.io/vip
CyberDefenders
Main site: https://cyberdefenders.org/
- Blue Team Labs: https://cyberdefenders.org/blue-team-labs/
- Labs overview: https://cyberdefenders.org/labs
KC7
Main site: https://www.kc7cyber.com/
- How to Play KC7: https://kc7cyber.com/module/how-to-play-kc7-1663
- Documentation: https://docs.kc7cyber.com/getting-started/what-is-kc7
TCM Security
Main site: https://tcm-sec.com/
- Free penetration testing resources: https://academy.tcm-sec.com/p/learn-penetration-testing-free
- Free tier announcement: https://tcm-sec.com/free-tier-launch/
- Certifications: https://certifications.tcm-sec.com/
SOURCES CHECKED
- tryhackme.com, tryhackme.com/free-rooms, tryhackme.com/pricing
- academy.hackthebox.com, hackthebox.com/pricing, help.hackthebox.com
- portswigger.net/web-security, portswigger.net/web-security/credits
- letsdefend.io, app.letsdefend.io/vip
- cyberdefenders.org, cyberdefenders.org/blue-team-labs
- kc7cyber.com, docs.kc7cyber.com
- tcm-sec.com, certifications.tcm-sec.com, academy.tcm-sec.com