Tier I

Operational Foundations

The bedrock every security engineer must master
PHASE // 01 Verified & Live

Networking & Traffic Analysis

OSI/TCP-IP models, packet structures, binary subnetting, ARP spoofing mechanics, DNS resolution hierarchy, and live Wireshark packet inspection.

Arsenal / Tools:
Wireshark tcpdump CIDR Scapy ARP
Read Phase Notes
PHASE // 02 In Production

Linux Internals & Scripting

Filesystem hierarchy, process management (`/proc`), SUID/SGID permissions, systemd services, automated Bash tooling, and regex stream filtering.

Arsenal / Tools:
Bash grep / sed / awk systemctl strace OverTheWire
PHASE // 03 Queued

Windows Architecture & PowerShell

NTFS permissions, Registry forensics, SAM/LSASS process security, Windows Event Logs, and offensive/defensive PowerShell scripting.

Arsenal / Tools:
PowerShell Sysinternals ProcMon EventViewer
Tier II

Offensive & Defensive Core

Real-world attack chains, detection engineering, and incident triage
PHASE // 04 Queued

Web Security & API Exploitation

OWASP Top 10 deep dive: SQLi, Blind XSS, SSRF, IDORs, broken access control, JWT tampering, and automated API fuzzing with Burp Suite.

Arsenal / Tools:
Burp Suite Pro OWASP ZAP sqlmap ffuf PortSwigger
PHASE // 05 Queued

Network Pentesting & Active Directory

Reconnaissance, service scanning, Kerberoasting, AS-REP Roasting, Pass-the-Hash, BloodHound attack path auditing, and domain dominance.

Arsenal / Tools:
BloodHound Mimikatz Impacket Nmap CrackMapExec
PHASE // 06 Queued

SOC Operations & SIEM Engineering

Log aggregation, correlation rules, Sigma detection logic, Splunk SPL queries, Suricata IDS/IPS alerting, and proactive threat hunting.

Arsenal / Tools:
Splunk Elasticsearch Sigma YARA Wazuh
PHASE // 07 Queued

Digital Forensics & Incident Response

Disk imaging, RAM memory dumps with Volatility, MFT/Prefetch/Shimcache artifact recovery, lateral movement reconstruction, and containment.

Arsenal / Tools:
Volatility 3 Autopsy FTK Imager KAPE Eric Zimmerman
Tier III

Advanced Specializations

Cloud infrastructure, reverse engineering, and next-gen threats
PHASE // 08 Queued

Cloud Security & DevSecOps

AWS/Azure IAM privilege escalation, S3 bucket misconfigurations, Docker container breakouts, Kubernetes RBAC hardening, and CI/CD secret scanning.

Arsenal / Tools:
Pacu ScoutSuite Trivy Prowler Docker Bench
PHASE // 09 Queued

Malware Analysis & Reverse Engineering

Static disassembly with Ghidra, dynamic stepping with x64dbg, PE header structure analysis, anti-debugging bypasses, and sandbox detonation.

Arsenal / Tools:
Ghidra x64dbg PEview ANY.RUN Cuckoo
PHASE // 10 Queued

AI Red Teaming & Threat Intelligence

LLM prompt injection, jailbreaking, agentic data exfiltration, MITRE ATT&CK framework mapping, and Cyber Threat Intelligence (CTI) feeds.

Arsenal / Tools:
Garak PyRIT MISP MITRE ATT&CK OpenCTI

Practitioner Lab Arsenal

Reading notes without breaking code is useless. These are the verified, hands-on platforms where you build muscle memory.

OverTheWire Linux & Web

Bandit and Natas war-games. The non-negotiable rite of passage for mastering the Linux command line, pipes, and raw SSH mechanics.

overthewire.org
PortSwigger Academy Web Security

The gold standard for Burp Suite, SQLi, SSRF, and modern web exploitation. 100% free interactive vulnerable labs.

portswigger.net
Hack The Box Enterprise Pentest

Real-world vulnerable machines, Active Directory domains, and CTF challenges. Transition from beginner to professional pentester.

hackthebox.com
Malware-Traffic-Analysis Packet Forensics

Real infected network capture files (.pcap) to practice Wireshark filtering, malware beaconing identification, and credential theft triage.

malware-traffic-analysis.net
Blue Team Labs Online SOC & DFIR

Gamified defensive platform for log analysis, digital forensics, incident response, and threat hunting investigations.

blueteamlabs.online
TryHackMe Guided Labs

Structured step-by-step rooms covering networking, privilege escalation, Windows event analysis, and defensive forensics.

tryhackme.com

The 4 Practitioner Rules

RULE 01
Understand The Wire First

Never use an automated scanner or tool if you don't know the exact packets it transmits across the wire.

RULE 02
Break It In The Lab

Reading theory creates illusions of competence. Reproduce every vulnerability in an isolated virtual machine.

RULE 03
Offense & Defense Are One

You cannot properly defend what you cannot exploit, and you cannot stealthily exploit what you cannot detect.

RULE 04
Document Like An Auditor

Professional security engineers write clean, reproducible technical reports with verifiable proof of concepts.