Pentest Cyber Roadmap

Your comprehensive guide to mastering penetration testing and red team operations

Curated by RFS - Security Researcher

About RFS

Security Researcher in Unified Communications, Signals Intelligence, and Red Team Operations

Certifications & Expertise:

eJPT
eCPPTv2
CRTP
ADCS CESP
HTB DANTE
HTB Cybernetics
Fortinet NS1/NS2
CCNA
IMS/SIP/VoLTE
Nokia Systems

Partners & Resources

๐Ÿ›ฃ๏ธ RFS Pentesting & Red Team Roadmap

๐Ÿ”„ CI/CD Security

Advanced
  • Pipeline Security Fundamentals
  • Secrets Management & OIDC
  • Container & Image Security
  • Security Testing Integration (SAST/DAST/SCA)
  • Infrastructure as Code Security
  • Supply Chain Attack Prevention
  • Pipeline Monitoring & Detection
  • Incident Response & Recovery
  • CI/CD Security Lab
  • GitHub Actions Security

๐Ÿ”ง GitHub Actions Security

Advanced
  • GitHub Actions Architecture
  • Workflow Security & Permissions
  • Workflow Injection Prevention
  • Secrets Management & OIDC
  • Action Hardening & Pinning
  • Supply Chain Security
  • Runner Security & Isolation
  • Monitoring & Compliance
  • CI/CD Security Roadmap

๐Ÿ“… Learning Timeline

Months 1-3: Foundation Building

Master networking fundamentals, Linux/Windows basics, and core security concepts. Begin with eJPT preparation.

Months 4-6: Web Security Focus

Deep dive into web application security, OWASP Top 10, and manual testing techniques.

Months 7-12: Advanced Exploitation

System exploitation, Active Directory attacks, and eCPPTv2 certification preparation.

Year 2: Specialization

Focus on unified communications, red team operations, and SIGINT capabilities. Pursue CRTP and specialized certifications.

Year 3+: Expert Level

Advanced red team techniques, custom tool development, and research in emerging technologies.

๐Ÿ“‹ Content Index

Comprehensive resources and materials organized by skill level and domain:

Quick Internal Links

All Levels

CI/CD Security ยท GitHub Actions Security ยท AD Modules ยท Recon Modules ยท CI/CD Lab

Network Security Fundamentals

Beginner

Essential networking concepts, protocols, and security principles for penetration testing.

Web Application Testing Guide

Intermediate

Complete methodology for web application security assessment and vulnerability exploitation.

Active Directory Attack Vectors

Advanced

Comprehensive guide to AD enumeration, exploitation, and post-exploitation techniques.

Red Team Playbooks

Expert

Tactical guides for red team operations, C2 deployment, and persistence mechanisms.

Unified Communications Security

Expert

Specialized content on VoIP, SIP, IMS, and telecommunications security testing.

SIGINT & RF Analysis

Expert

Signal intelligence gathering, RF analysis, and wireless protocol interception techniques.

Tools & Resources

All Levels

Comprehensive collection of penetration testing tools, references, and learning materials.

Certification Prep Materials

Intermediate

Study guides and practice materials for eJPT, eCPPTv2, CRTP, and other security certifications.

Lab Environments & CTFs

Beginner

Hands-on practice environments, realistic cyber ranges, and expert-designed labs.

CI/CD Security Lab

Advanced

Hands-on pipeline security: secrets scanning, OIDC federation, testing gates, SBOM and provenance.

๐Ÿ“ง Stay Updated with Cyber Roadmaps

Get exclusive cybersecurity insights, new roadmap updates, and expert tips delivered to your inbox weekly!

๐Ÿ“š

Weekly Insights

Latest cybersecurity trends and techniques

๐ŸŽฏ

Roadmap Updates

New content and certification guides

๐Ÿ”’

Privacy First

No spam, unsubscribe anytime

๐Ÿ’š Support This Free Resource

Help us keep this cybersecurity roadmap free and growing by using our affiliate links below. You get the same great services while supporting the project!

๐ŸŽ“ TryHackMe

Perfect for beginners

Start Learning

๐Ÿš€ HackTheBox

Advanced challenges

Join Labs

โ˜๏ธ Digital Ocean

Build your labs

Get $200 Credit

๐Ÿ† INE Training

Get certified

Start Training

๐Ÿ“„ VisualCV

Sharpen your resume

Create Resume

Thank you for supporting this free cybersecurity learning platform! ๐Ÿ™