{"repo":"securitycipher/penetration-testing-roadmap","free":true,"listed":false,"github":"https://github.com/securitycipher/penetration-testing-roadmap","clone":"git clone https://github.com/securitycipher/penetration-testing-roadmap.git","description":"Complete Roadmap for Penetration Testing","language":null,"stars":304,"topics":["bug-bounty","bugbounty","cybersecurity","owasp","penetration-testing","penetration-testing-tools","roadmap","sast","scanner","security"],"license":null,"category":"security-tools","readme_excerpt":"Penetration Testing Roadmap Last updated: July 2026 A structured learning path from zero to junior penetration tester - topics, tools, labs, certifications, and hands-on guides. Live roadmap: securitycipher.com/penetration-testing-roadmap Quick start 1. Read Intro.md for the recommended learning path and TL;DR 2. Work through phases: Foundations → Web → Infrastructure → Specialize → Labs & certs 3. Open any topic below for a short guide with tools, labs, and links 4. See FAQ.md for career and cert questions Learning path Phase Focus Time (part-time) ------- ------- ------------------ 1. Foundations Linux, networking, scripting, crypto basics 4-6 weeks 2. Web security HTTP, OWASP Top 10, Burp Suite, PortSwigger Academy 6-8 weeks 3. Infrastructure AD basics, cloud, wireless, recon 6-8 weeks 4. Specialize Web, cloud, mobile, API, or LLM track Ongoing 5. Prove it HTB, TryHackMe, certs (eJPT, Security+, OSCP) 3-6 months Full write-up: Intro.md Content index Getting started - Intro - FAQ Foundations - Operating System - Networking - Cryptography - Compliance Core security - Terminology - Vulnerabilities - Security Testing Approaches - Threat Modeling - Tools Web and application testing - OWASP Top 10 - API Security - Methodology - pentest phases, rules of engagement, reporting - Recon - OSINT, subdomains, JavaScript analysis Infrastructure and cloud - Active Directory - Cloud - Containers - Docker and Kubernetes - Mobile - Android and iOS testing Emerging areas - OWASP Top 10 LLM P","default_branch":null,"files":null,"tree":[],"storefront":"/r/securitycipher","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/securitycipher/penetration-testing-roadmap/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}