Penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners
Penetration testing is one of the most interesting areas of cybersecurity.
It combines networking, Linux, Windows, programming, web technologies, vulnerability analysis, security testing and technical reporting.
But there is one major problem for beginners:
Many beginners start with Kali Linux, install several security tools and immediately jump into advanced tutorials.
That approach can create the illusion of progress without building the underlying knowledge needed to understand what the tools are actually doing.
A better approach is to build your skills in layers:
Computer Fundamentals
↓
Networking
↓
Linux + Windows
↓
Programming
↓
Web Technologies
↓
Security Fundamentals
↓
Nmap + Traffic Analysis
↓
Web Security
↓
Hands-on Labs
↓
Penetration Testing Methodology
↓
Specialization
↓
Reporting
↓
Portfolio
This guide explains that roadmap in detail.
What Is Penetration Testing?
Penetration testing, often called pentesting, is a structured form of security testing in which authorized testers evaluate whether weaknesses in a system can be used to compromise security under defined constraints.
NIST defines penetration testing as a methodology where assessors attempt to circumvent or defeat security features under specified constraints. NIST SP 800-115 also provides guidance for planning, conducting and evaluating technical security tests. (NIST Penetration Testing)
A simplified process is:
Authorization
↓
Scope
↓
Discovery
↓
Enumeration
↓
Vulnerability Analysis
↓
Controlled Validation
↓
Reporting
↓
Remediation
↓
Retesting
What Does a Penetration Tester Do?
A penetration tester may be responsible for:
- Understanding the authorized scope
- Discovering systems and services
- Analyzing applications
- Identifying vulnerabilities
- Validating selected findings
- Assessing potential impact
- Documenting evidence
- Writing security reports
- Providing remediation guidance
- Performing retesting after fixes
The exact responsibilities vary by organization and specialization.
Penetration Testing Roadmap at a Glance
| Stage | Main Focus |
|---|---|
| 1 | Computer fundamentals |
| 2 | Networking |
| 3 | Linux |
| 4 | Windows |
| 5 | Programming and scripting |
| 6 | Web technologies |
| 7 | Cybersecurity fundamentals |
| 8 | Security tools |
| 9 | Hands-on labs |
| 10 | Testing methodology |
| 11 | Specialization |
| 12 | Reporting and portfolio |
Stage 1: Learn Computer Fundamentals
Before learning penetration testing, understand how computers actually work.
Learn:
- CPU
- RAM
- Storage
- Operating systems
- Processes
- Files and directories
- Users and permissions
- Applications
- Client-server architecture
Questions to Understand
- What is a process?
- What is a service?
- How does an application communicate with another system?
- What is a user account?
- What are file permissions?
- What happens when a program starts?
You do not need to become a hardware engineer.
The goal is to understand the basic environment in which security problems occur.
Stage 2: Master Networking
Networking is one of the most important foundations for penetration testing.
Learn these concepts:
- IPv4
- IPv6 basics
- MAC addresses
- TCP
- UDP
- Ports
- DNS
- DHCP
- HTTP
- HTTPS
- Routing
- NAT
- Firewalls
- VPNs
- Subnetting
You should eventually be comfortable explaining:
User ↓ DNS ↓ IP Address ↓ Router ↓ TCP Connection ↓ Port ↓ Service ↓ Application
Without this knowledge, tools such as Nmap can become little more than a collection of commands.
Stage 3: Learn Linux
Linux is an important operating system for security learners.
Learn:
- Filesystem structure
- File permissions
- Users and groups
- Processes
- Services
- Networking
- Logs
- SSH
- Shell scripting
Essential Linux Commands
pwd ls cd mkdir cp mv rm cat less grep find chmod chown ps top ip ss curl ssh journalctl
Learning these commands will make later security tooling much easier.
Stage 4: Learn Windows
Penetration testing is not limited to Linux systems.
Many enterprise environments use Windows extensively.
Learn:
- Windows users and groups
- NTFS permissions
- Processes
- Services
- PowerShell
- Event Viewer
- Windows Defender
- Registry basics
- Authentication
- Active Directory fundamentals
Understanding Windows becomes especially important if you want to explore enterprise penetration testing.
Stage 5: Learn Programming and Scripting
You do not need to become an expert programmer before starting penetration testing.
However, scripting becomes extremely useful as your skills grow.
| Technology | Why Learn It? |
|---|---|
| Python | Automation, APIs, scripts and data processing |
| Bash | Linux automation |
| PowerShell | Windows administration and automation |
| SQL | Database and application security |
| JavaScript | Web application understanding |
For most beginners, Python + Bash + SQL + basic JavaScript is a useful combination.
Stage 6: Learn Web Technologies
If you want to test websites or APIs, you must first understand how they work.
Learn:
- HTML
- CSS basics
- JavaScript basics
- HTTP requests
- HTTP responses
- Headers
- Cookies
- Sessions
- Authentication
- Authorization
- REST APIs
- JSON
- Databases
A simplified web architecture looks like:
Browser ↓ Frontend ↓ API / HTTP ↓ Backend ↓ Database
Security testing becomes much easier when you understand each layer.
Stage 7: Learn Cybersecurity Fundamentals
Before studying specific vulnerabilities, understand the basic language of security.
Learn:
- Confidentiality
- Integrity
- Availability
- Authentication
- Authorization
- Accounting and logging
- Least privilege
- Defense in depth
- Threats
- Vulnerabilities
- Risk
Understand the CIA Triad
Confidentiality
/\
/ \
/ \
/ \
Integrity--Availability
These concepts provide the foundation for understanding why security weaknesses matter.
Stage 8: Learn Authentication and Authorization
This is particularly important for web and API security.
Authorization: What are you allowed to do?
Study:
- Passwords
- MFA
- Sessions
- Cookies
- Tokens
- Roles
- Permissions
- Access-control models
Many serious application-security problems involve incorrect authorization rather than simply weak passwords.
Stage 9: Learn Cryptography Basics
You do not need advanced mathematics to begin.
Understand:
- Encryption
- Decryption
- Symmetric cryptography
- Asymmetric cryptography
- Hashing
- Digital signatures
- Certificates
- Public/private keys
- TLS basics
You should be able to explain why passwords should be protected using appropriate password-hashing mechanisms rather than simple reversible encryption.
Stage 10: Learn Vulnerabilities
Now start studying common vulnerability classes.
Important areas include:
- Broken access control
- Injection
- Authentication failures
- Security misconfiguration
- Cryptographic failures
- Insecure design
- Outdated components
- Session-management weaknesses
- Server-side request issues
For web security, OWASP's Web Security Testing Guide provides a structured reference for application testing. OWASP currently lists version 4.2 as the latest released WSTG version while version 5.0 is under development. (OWASP WSTG)
Stage 11: Learn Nmap
Nmap is commonly used for network discovery and service identification.
Start with your local lab:
nmap 127.0.0.1
Then learn:
nmap -p 22,80,443 127.0.0.1 nmap -sV 127.0.0.1 nmap -p- 127.0.0.1 nmap -oA lab-scan 127.0.0.1
Learn what the results mean before adding more advanced options.
Stage 12: Learn Wireshark
Wireshark helps you inspect network traffic.
Learn:
- Packets
- Frames
- TCP handshakes
- UDP traffic
- DNS requests
- HTTP traffic
- TLS concepts
- Source and destination addresses
- Ports
Try capturing traffic generated by your own applications and understand what each packet represents.
Packet analysis is an excellent way to strengthen networking knowledge.
Stage 13: Learn Burp Suite
Burp Suite is widely used for web application security testing.
Start with:
- Proxy
- HTTP request/response inspection
- Repeating requests
- Modifying requests in a lab
- Understanding cookies
- Understanding authentication flows
Do not begin by trying to memorize every feature.
First understand:
Browser ↓ Burp Proxy ↓ Web Application ↓ Response ↓ Burp ↓ Browser
Once that flow is clear, the rest of the tool becomes easier to learn.
Stage 14: Study OWASP Web Security Testing
If web application security is your target, OWASP is one of the most useful learning resources available.
The current OWASP WSTG covers areas including:
- Information gathering
- Configuration testing
- Identity management
- Authentication testing
- Authorization testing
- Session management
- Input validation
- Error handling
- Cryptography
- Business logic
OWASP describes WSTG as a flexible methodology and technique reference rather than a rigid checklist. Its latest released version is currently 4.2, with 5.0 under development. (OWASP WSTG Introduction)
Stage 15: Learn Enumeration
Enumeration means gathering detailed information about identified systems and services.
Depending on the authorized target, you may study:
- Service versions
- Application technologies
- Authentication mechanisms
- Available endpoints
- Network relationships
- Security controls
The key is understanding what information is useful and why.
Stage 16: Learn Vulnerability Analysis
Once you understand a system, identify potential weaknesses.
Possible sources include:
- Manual analysis
- Automated scanners
- Configuration reviews
- Application behavior
- Source-code review, when available
- Known vulnerability information
Do not automatically treat scanner output as proof.
Always analyze the finding in context.
Stage 17: Learn Controlled Validation
A suspected vulnerability may need to be validated.
Validation should occur only when:
- The target is in scope
- The action is permitted
- The potential impact is understood
- The test is controlled
- Sensitive data is protected
The purpose is to establish whether a suspected weakness actually produces the reported security impact.
Stage 18: Learn Penetration Testing Methodology
Tools are not a methodology.
One recognized reference described by OWASP is the Penetration Testing Execution Standard (PTES), which organizes penetration testing into seven phases:
- Pre-engagement Interactions
- Intelligence Gathering
- Threat Modeling
- Vulnerability Analysis
- Exploitation
- Post Exploitation
- Reporting
OWASP's methodology overview also references NIST SP 800-115, PCI penetration-testing guidance and other testing methodologies. (OWASP Penetration Testing Methodologies)
These phases should be adapted to the engagement rather than treated as a universal script.
Stage 19: Learn Pre-Engagement
This phase establishes the rules of the assessment.
Understand:
- Scope
- Objectives
- Testing dates
- Authorized systems
- Excluded systems
- Permitted methods
- Prohibited methods
- Emergency contacts
- Reporting requirements
A professional penetration tester should be comfortable reading and following a scope document.
Stage 20: Learn Intelligence Gathering
Before deeper testing, understand the target.
This can include:
- Domains
- Subdomains
- IP addresses
- Technologies
- Applications
- Publicly available information
Always keep information gathering within the authorized scope.
Stage 21: Learn Threat Modeling
Threat modeling asks questions such as:
- What are the important assets?
- Who might attack them?
- What attack paths could exist?
- What security controls are present?
- What happens if a control fails?
Threat modeling gives penetration testing context.
Stage 22: Learn Post-Exploitation Concepts
At an advanced level, security testers may need to understand what could happen after an initial compromise.
Study concepts such as:
- Privilege boundaries
- Credential exposure
- Network segmentation
- Lateral movement concepts
- Persistence concepts
- Detection opportunities
Practice these concepts only inside explicitly authorized labs.
The goal is to understand potential business impact and defensive controls, not to gain access to unrelated systems.
Stage 23: Learn Reporting
Reporting is one of the most important professional skills.
A good report may contain:
Executive Summary Scope Methodology Limitations Findings Evidence Risk Impact Recommendations Retest Results Appendices
A technical person should be able to reproduce the issue from the information provided, while management should be able to understand the business significance.
What Should a Penetration Testing Finding Contain?
A practical finding structure is:
Title ↓ Affected Asset ↓ Description ↓ Evidence ↓ Impact ↓ Risk Context ↓ Recommendation ↓ References ↓ Retest Status
For example:
Finding: Insufficient Authorization Affected Asset: Authorized Test Application Description: A tested user role was able to access a resource outside its intended permission boundary. Impact: The issue may expose information intended for another role. Recommendation: Enforce server-side authorization checks for every protected resource and action. Retest: Verify that the restricted request is denied.
Stage 24: Learn Vulnerability Prioritization
Not every vulnerability deserves the same remediation priority.
Consider:
- Likelihood
- Technical severity
- Asset importance
- Exposure
- Exploitability
- Business impact
- Existing controls
This helps organizations decide where to spend limited remediation resources.
Stage 25: Build a Home Pentesting Lab
A lab is one of the best ways to learn penetration testing safely.
A basic setup could contain:
Host Computer
|
Virtualization
|
+------+----------------+
| |
Tester VM Target VM
| |
| Vulnerable App
| |
+-----------+-----------+
|
Isolated Lab
You can install Linux and Windows virtual machines and connect deliberately vulnerable applications to a controlled network.
How Much Hardware Do You Need?
You do not need an expensive server to begin.
A basic computer that can run one or more virtual machines can be enough for many beginner exercises.
As you progress, more RAM and storage can make virtualization easier.
For resource-constrained learners, start small:
- One Linux VM
- One target VM
- One isolated network
You can expand the lab later.
Stage 26: Build Projects
Projects turn knowledge into evidence.
Beginner Projects
- Local network inventory tool
- Python log analyzer
- File integrity monitor
- Security headers checker
- Hashing demonstration application
- Linux security checklist
Intermediate Projects
- Mini vulnerability-management dashboard
- Web security testing report
- Security log monitoring system
- Network monitoring dashboard
- Authentication monitoring tool
- Cloud configuration checker
Stage 27: Build Your Portfolio
A strong penetration-testing portfolio can include:
- GitHub projects
- Lab documentation
- Security reports
- Web-security write-ups
- CTF write-ups from permitted environments
- Python security scripts
- Network-analysis projects
- Remediation examples
For each project, use a consistent structure:
Problem Scope Environment Approach Tools Findings Impact Remediation Retest Lessons Learned
Stage 28: Choose a Specialization
Penetration testing is broad.
Eventually, choose an area to explore deeply.
Web Application Security
Focus on applications, APIs, authentication, authorization, sessions and business logic.
Network Penetration Testing
Focus on network services, segmentation, protocols and infrastructure.
Active Directory
Focus on Windows enterprise environments, identity and access relationships.
Cloud Security
Focus on cloud identities, permissions, configurations and exposed resources.
Mobile Security
Focus on mobile applications and backend communication.
Red Teaming
Focus on broader adversary simulation within carefully defined rules of engagement.
Web Pentesting Roadmap
HTTP ↓ HTML / JavaScript ↓ Cookies / Sessions ↓ Authentication ↓ Authorization ↓ APIs ↓ SQL / Databases ↓ OWASP ↓ Burp Suite ↓ Web Security Labs ↓ Reporting
OWASP's Web Security Testing Guide is particularly useful for this path. The project currently lists WSTG 4.2 as its latest released version while 5.0 is being developed. (OWASP WSTG)
Network Pentesting Roadmap
Networking ↓ TCP / UDP ↓ Ports ↓ Services ↓ Nmap ↓ Wireshark ↓ Enumeration ↓ Firewall Concepts ↓ Network Security ↓ Controlled Validation ↓ Reporting
Active Directory Learning Roadmap
Windows Fundamentals ↓ Users & Groups ↓ Domains ↓ Active Directory ↓ Kerberos Concepts ↓ LDAP Concepts ↓ Group Policies ↓ Permissions ↓ Enterprise Security ↓ Authorized AD Lab ↓ Reporting
Do not begin with advanced Active Directory attack techniques before understanding Windows and identity fundamentals.
Cloud Pentesting Roadmap
Cloud Fundamentals ↓ IAM ↓ Networking ↓ Storage ↓ Compute ↓ Logging ↓ Secrets ↓ Configuration ↓ Cloud Security Testing ↓ Reporting
Cloud testing requires additional attention to the provider's security-testing policies and the organization's authorization.
Certifications and Penetration Testing
Certifications can provide structure and may help demonstrate certain knowledge or hands-on capabilities.
Before selecting one, compare:
- Current syllabus
- Exam format
- Practical requirements
- Prerequisites
- Cost
- Renewal requirements
- Relationship to your target role
Do not choose a certification simply because somebody says it is "the best."
First identify the skills you need.
Skills vs Certifications
| Skill Evidence | Certification Evidence |
|---|---|
| Projects | Exam result |
| Lab reports | Credential |
| GitHub repositories | Certification body |
| Practical demonstrations | Structured learning path |
| Security write-ups | Formal assessment |
For a strong profile, skills and documented practice should support any certifications you earn.
A 12-Month Penetration Testing Study Plan
| Month | Focus |
|---|---|
| 1 | Computer fundamentals |
| 2 | Networking fundamentals |
| 3 | Linux |
| 4 | Windows + PowerShell |
| 5 | Python + SQL |
| 6 | HTTP + Web Technologies |
| 7 | Security fundamentals |
| 8 | Nmap + Wireshark |
| 9 | Web security + Burp Suite |
| 10 | Hands-on labs |
| 11 | Specialization + projects |
| 12 | Reporting + portfolio + interview preparation |
This is a flexible example. Your progress depends on your existing knowledge, available study time and amount of hands-on practice.
A Daily Penetration Testing Study Routine
A balanced routine could look like:
30 min → Theory 30 min → Networking / Linux 60 min → Hands-on Lab 30 min → Notes 30 min → Project
On busy days, even one focused practical session can be useful.
How to Practice Efficiently
Do not spend all your time watching tutorials.
Use a cycle such as:
Learn ↓ Practice ↓ Break ↓ Understand ↓ Fix ↓ Document ↓ Repeat
The "document" step is often ignored, but it becomes valuable when building a professional portfolio.
How to Take Notes
Create separate notes for:
- Networking
- Linux
- Windows
- Web security
- Nmap
- Wireshark
- Burp Suite
- OWASP
- Labs
- Reporting
For every new concept, write:
What is it? Why does it matter? How does it work? How can I detect it? How can it be fixed?
How to Measure Your Progress
Do not measure your progress only by the number of tools installed.
Instead, ask whether you can:
- Explain how a network works
- Interpret Nmap results
- Read HTTP requests
- Understand authentication
- Identify an authorization problem in a lab
- Analyze logs
- Write a Python automation script
- Explain the impact of a finding
- Recommend a remediation
- Write a professional report
Common Beginner Mistakes
1. Starting With Advanced Exploitation
Build fundamentals first.
2. Ignoring Networking
Network knowledge is foundational.
3. Learning Only Kali Linux
Kali is an environment, not a substitute for understanding Linux and security.
4. Memorizing Commands
Understand why and when to use a command.
5. Using Automated Scanners Without Verification
Scanner results can require manual validation.
6. Ignoring Reporting
Professional security work requires clear communication.
7. Practicing on Unauthorized Targets
This can create legal, contractual and operational problems.
8. Collecting Certifications Without Practical Work
Build real technical evidence alongside any certifications.
What Should You Avoid Learning First?
You do not need to begin with:
- Advanced exploit development
- Complex malware analysis
- Advanced reverse engineering
- Highly specialized hardware attacks
- Complex red-team infrastructure
These topics can come later.
Build a strong foundation first.
How to Build a Professional Pentesting Mindset
Instead of asking:
learn to ask:
This mindset encourages analysis before action.
Penetration Testing and Secure Development
Application security should not depend only on penetration testing after an application has been built.
OWASP's current testing framework emphasizes considering security throughout the software lifecycle, including definition, design, development, deployment, maintenance and operations. (OWASP Testing Framework)
A broader secure-development process can look like:
Requirements ↓ Threat Modeling ↓ Secure Design ↓ Secure Coding ↓ Code Review ↓ Security Testing ↓ Deployment ↓ Monitoring ↓ Penetration Testing ↓ Improvement
Penetration testing is therefore one part of a larger security program.
How a Penetration Tester Should Think About a Finding
A useful mental model is:
Weakness ↓ Can It Be Validated? ↓ What Access Does It Provide? ↓ What Resource Is Affected? ↓ What Is The Security Impact? ↓ How Should It Be Fixed?
This turns technical observations into actionable security findings.
Penetration Testing Portfolio Checklist
- □ Linux lab
- □ Windows lab
- □ Networking project
- □ Nmap project
- □ Wireshark analysis
- □ Web-security lab
- □ Burp Suite exercise
- □ Python automation project
- □ Vulnerability report
- □ Remediation example
- □ GitHub repository
- □ Technical write-up
Frequently Asked Questions
1. What should I learn first for penetration testing?
Start with computer fundamentals, networking, Linux and Windows basics. Then add programming, web technologies and security fundamentals.
2. Is Kali Linux enough to become a penetration tester?
No. Kali Linux provides a useful security-testing environment, but it does not replace networking, Linux, Windows, programming, web-security knowledge and hands-on practice.
3. Is networking important for penetration testing?
Yes. Networking is one of the most important foundations for understanding ports, services, protocols, firewalls and network behavior.
4. Do I need programming for penetration testing?
You do not need advanced programming immediately, but Python, Bash, PowerShell, SQL and JavaScript can become very useful as your skills develop.
5. Which programming language should I learn first?
Python is a practical starting point because it is useful for automation, scripting, APIs and data processing.
6. Should I learn web security?
Yes, especially if you are interested in websites and APIs. HTTP, authentication, authorization, sessions, databases and application architecture are important foundations.
7. Is Nmap enough for penetration testing?
No. Nmap is useful for discovery and service identification, but a penetration test requires planning, analysis, validation, reporting and remediation.
8. What is the difference between vulnerability assessment and penetration testing?
Vulnerability assessment generally focuses on finding potential weaknesses, while penetration testing can include controlled validation of selected weaknesses and their security impact.
9. Can I practice penetration testing on public websites?
Do not assume that public availability means authorization. Use your own systems, training platforms, deliberately vulnerable labs or systems where you have explicit permission.
10. How long does it take to learn penetration testing?
There is no universal timeline. Progress depends on your current technical knowledge, study time, hands-on practice and chosen specialization.
11. Do I need certifications?
Certification requirements vary by role and employer. Certifications can be useful, but they should complement practical knowledge and project experience.
12. Is reporting really important?
Yes. A professional tester needs to communicate findings, impact and remediation clearly. Technical testing without useful documentation has limited value to the organization.
13. What is the PTES methodology?
The Penetration Testing Execution Standard organizes penetration testing into seven phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting. OWASP references PTES in its penetration-testing methodology guidance. (OWASP PTES Reference)
14. What is OWASP WSTG?
The OWASP Web Security Testing Guide is a practical reference for testing web applications and web services. The project currently lists version 4.2 as the latest released version while version 5.0 is under development. (OWASP WSTG)
Final Thoughts
Penetration testing is not something you learn by installing a security distribution and memorizing commands.
A stronger roadmap is:
Build each layer before moving heavily into the next one.
NIST's technical security-testing guidance emphasizes planning, execution and evaluation, while OWASP's current testing resources emphasize adaptable methodologies, risk-based prioritization and a combination of automated and manual techniques. (NIST SP 800-115)
The biggest mistake beginners make is focusing on how to attack before understanding how the system works.
Reverse that order.
Learn the technology first, practice safely, document your findings, understand remediation and gradually specialize.
That gives you a much more useful foundation for a long-term penetration-testing career.
Recommended Reading on CodeWithAV
- Cybersecurity Roadmap for Beginners
- 50 Linux Commands for Cybersecurity Beginners
- Nmap Tutorial for Beginners
- What Is Ethical Hacking?
- What Is Penetration Testing?
- Ethical Hacking vs Cybersecurity
Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.
Official Resources
- NIST SP 800-115 — Technical Guide to Information Security Testing and Assessment
- NIST Cybersecurity Glossary — Penetration Testing
- OWASP Web Security Testing Guide
- OWASP WSTG — Current Documentation
- OWASP — Penetration Testing Methodologies
- Nmap Network Scanning — Official Guide
Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.