penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration testing is one of the most interesting areas of cybersecurity.

It combines networking, Linux, Windows, programming, web technologies, vulnerability analysis, security testing and technical reporting.

But there is one major problem for beginners:

What should I learn first, and what should I learn next?

Many beginners start with Kali Linux, install several security tools and immediately jump into advanced tutorials.

That approach can create the illusion of progress without building the underlying knowledge needed to understand what the tools are actually doing.

A better approach is to build your skills in layers:

Computer Fundamentals
        ↓
Networking
        ↓
Linux + Windows
        ↓
Programming
        ↓
Web Technologies
        ↓
Security Fundamentals
        ↓
Nmap + Traffic Analysis
        ↓
Web Security
        ↓
Hands-on Labs
        ↓
Penetration Testing Methodology
        ↓
Specialization
        ↓
Reporting
        ↓
Portfolio

This guide explains that roadmap in detail.

Important: Penetration testing must be authorized. Practice only on systems you own, deliberately vulnerable labs, training environments, bug-bounty targets explicitly within scope, or systems covered by written permission.

What Is Penetration Testing?

Penetration testing, often called pentesting, is a structured form of security testing in which authorized testers evaluate whether weaknesses in a system can be used to compromise security under defined constraints.

NIST defines penetration testing as a methodology where assessors attempt to circumvent or defeat security features under specified constraints. NIST SP 800-115 also provides guidance for planning, conducting and evaluating technical security tests. (NIST Penetration Testing)

A simplified process is:

Authorization
      ↓
Scope
      ↓
Discovery
      ↓
Enumeration
      ↓
Vulnerability Analysis
      ↓
Controlled Validation
      ↓
Reporting
      ↓
Remediation
      ↓
Retesting

What Does a Penetration Tester Do?

A penetration tester may be responsible for:

  • Understanding the authorized scope
  • Discovering systems and services
  • Analyzing applications
  • Identifying vulnerabilities
  • Validating selected findings
  • Assessing potential impact
  • Documenting evidence
  • Writing security reports
  • Providing remediation guidance
  • Performing retesting after fixes

The exact responsibilities vary by organization and specialization.


Penetration Testing Roadmap at a Glance

Stage Main Focus
1Computer fundamentals
2Networking
3Linux
4Windows
5Programming and scripting
6Web technologies
7Cybersecurity fundamentals
8Security tools
9Hands-on labs
10Testing methodology
11Specialization
12Reporting and portfolio

Stage 1: Learn Computer Fundamentals

Before learning penetration testing, understand how computers actually work.

Learn:

  • CPU
  • RAM
  • Storage
  • Operating systems
  • Processes
  • Files and directories
  • Users and permissions
  • Applications
  • Client-server architecture

Questions to Understand

  • What is a process?
  • What is a service?
  • How does an application communicate with another system?
  • What is a user account?
  • What are file permissions?
  • What happens when a program starts?

You do not need to become a hardware engineer.

The goal is to understand the basic environment in which security problems occur.


Stage 2: Master Networking

Networking is one of the most important foundations for penetration testing.

Learn these concepts:

  • IPv4
  • IPv6 basics
  • MAC addresses
  • TCP
  • UDP
  • Ports
  • DNS
  • DHCP
  • HTTP
  • HTTPS
  • Routing
  • NAT
  • Firewalls
  • VPNs
  • Subnetting

You should eventually be comfortable explaining:

User
 ↓
DNS
 ↓
IP Address
 ↓
Router
 ↓
TCP Connection
 ↓
Port
 ↓
Service
 ↓
Application

Without this knowledge, tools such as Nmap can become little more than a collection of commands.


Stage 3: Learn Linux

Linux is an important operating system for security learners.

Learn:

  • Filesystem structure
  • File permissions
  • Users and groups
  • Processes
  • Services
  • Networking
  • Logs
  • SSH
  • Shell scripting

Essential Linux Commands

pwd
ls
cd
mkdir
cp
mv
rm
cat
less
grep
find
chmod
chown
ps
top
ip
ss
curl
ssh
journalctl

Learning these commands will make later security tooling much easier.


Stage 4: Learn Windows

Penetration testing is not limited to Linux systems.

Many enterprise environments use Windows extensively.

Learn:

  • Windows users and groups
  • NTFS permissions
  • Processes
  • Services
  • PowerShell
  • Event Viewer
  • Windows Defender
  • Registry basics
  • Authentication
  • Active Directory fundamentals

Understanding Windows becomes especially important if you want to explore enterprise penetration testing.


Stage 5: Learn Programming and Scripting

You do not need to become an expert programmer before starting penetration testing.

However, scripting becomes extremely useful as your skills grow.

Technology Why Learn It?
PythonAutomation, APIs, scripts and data processing
BashLinux automation
PowerShellWindows administration and automation
SQLDatabase and application security
JavaScriptWeb application understanding

For most beginners, Python + Bash + SQL + basic JavaScript is a useful combination.


Stage 6: Learn Web Technologies

If you want to test websites or APIs, you must first understand how they work.

Learn:

  • HTML
  • CSS basics
  • JavaScript basics
  • HTTP requests
  • HTTP responses
  • Headers
  • Cookies
  • Sessions
  • Authentication
  • Authorization
  • REST APIs
  • JSON
  • Databases

A simplified web architecture looks like:

Browser
   ↓
Frontend
   ↓
API / HTTP
   ↓
Backend
   ↓
Database

Security testing becomes much easier when you understand each layer.


Stage 7: Learn Cybersecurity Fundamentals

Before studying specific vulnerabilities, understand the basic language of security.

Learn:

  • Confidentiality
  • Integrity
  • Availability
  • Authentication
  • Authorization
  • Accounting and logging
  • Least privilege
  • Defense in depth
  • Threats
  • Vulnerabilities
  • Risk

Understand the CIA Triad

Confidentiality
       /\
      /  \
     /    \
    /      \
Integrity--Availability

These concepts provide the foundation for understanding why security weaknesses matter.


Stage 8: Learn Authentication and Authorization

This is particularly important for web and API security.

Authentication: Who are you?

Authorization: What are you allowed to do?

Study:

  • Passwords
  • MFA
  • Sessions
  • Cookies
  • Tokens
  • Roles
  • Permissions
  • Access-control models

Many serious application-security problems involve incorrect authorization rather than simply weak passwords.


Stage 9: Learn Cryptography Basics

You do not need advanced mathematics to begin.

Understand:

  • Encryption
  • Decryption
  • Symmetric cryptography
  • Asymmetric cryptography
  • Hashing
  • Digital signatures
  • Certificates
  • Public/private keys
  • TLS basics

You should be able to explain why passwords should be protected using appropriate password-hashing mechanisms rather than simple reversible encryption.


Stage 10: Learn Vulnerabilities

Now start studying common vulnerability classes.

Important areas include:

  • Broken access control
  • Injection
  • Authentication failures
  • Security misconfiguration
  • Cryptographic failures
  • Insecure design
  • Outdated components
  • Session-management weaknesses
  • Server-side request issues

For web security, OWASP's Web Security Testing Guide provides a structured reference for application testing. OWASP currently lists version 4.2 as the latest released WSTG version while version 5.0 is under development. (OWASP WSTG)


Stage 11: Learn Nmap

Nmap is commonly used for network discovery and service identification.

Start with your local lab:

nmap 127.0.0.1

Then learn:

nmap -p 22,80,443 127.0.0.1

nmap -sV 127.0.0.1

nmap -p- 127.0.0.1

nmap -oA lab-scan 127.0.0.1

Learn what the results mean before adding more advanced options.


Stage 12: Learn Wireshark

Wireshark helps you inspect network traffic.

Learn:

  • Packets
  • Frames
  • TCP handshakes
  • UDP traffic
  • DNS requests
  • HTTP traffic
  • TLS concepts
  • Source and destination addresses
  • Ports

Try capturing traffic generated by your own applications and understand what each packet represents.

Packet analysis is an excellent way to strengthen networking knowledge.


Stage 13: Learn Burp Suite

Burp Suite is widely used for web application security testing.

Start with:

  • Proxy
  • HTTP request/response inspection
  • Repeating requests
  • Modifying requests in a lab
  • Understanding cookies
  • Understanding authentication flows

Do not begin by trying to memorize every feature.

First understand:

Browser
   ↓
Burp Proxy
   ↓
Web Application
   ↓
Response
   ↓
Burp
   ↓
Browser

Once that flow is clear, the rest of the tool becomes easier to learn.


Stage 14: Study OWASP Web Security Testing

If web application security is your target, OWASP is one of the most useful learning resources available.

The current OWASP WSTG covers areas including:

  • Information gathering
  • Configuration testing
  • Identity management
  • Authentication testing
  • Authorization testing
  • Session management
  • Input validation
  • Error handling
  • Cryptography
  • Business logic

OWASP describes WSTG as a flexible methodology and technique reference rather than a rigid checklist. Its latest released version is currently 4.2, with 5.0 under development. (OWASP WSTG Introduction)


Stage 15: Learn Enumeration

Enumeration means gathering detailed information about identified systems and services.

Depending on the authorized target, you may study:

  • Service versions
  • Application technologies
  • Authentication mechanisms
  • Available endpoints
  • Network relationships
  • Security controls

The key is understanding what information is useful and why.


Stage 16: Learn Vulnerability Analysis

Once you understand a system, identify potential weaknesses.

Possible sources include:

  • Manual analysis
  • Automated scanners
  • Configuration reviews
  • Application behavior
  • Source-code review, when available
  • Known vulnerability information

Do not automatically treat scanner output as proof.

Always analyze the finding in context.


Stage 17: Learn Controlled Validation

A suspected vulnerability may need to be validated.

Validation should occur only when:

  • The target is in scope
  • The action is permitted
  • The potential impact is understood
  • The test is controlled
  • Sensitive data is protected

The purpose is to establish whether a suspected weakness actually produces the reported security impact.


Stage 18: Learn Penetration Testing Methodology

Tools are not a methodology.

One recognized reference described by OWASP is the Penetration Testing Execution Standard (PTES), which organizes penetration testing into seven phases:

  1. Pre-engagement Interactions
  2. Intelligence Gathering
  3. Threat Modeling
  4. Vulnerability Analysis
  5. Exploitation
  6. Post Exploitation
  7. Reporting

OWASP's methodology overview also references NIST SP 800-115, PCI penetration-testing guidance and other testing methodologies. (OWASP Penetration Testing Methodologies)

These phases should be adapted to the engagement rather than treated as a universal script.


Stage 19: Learn Pre-Engagement

This phase establishes the rules of the assessment.

Understand:

  • Scope
  • Objectives
  • Testing dates
  • Authorized systems
  • Excluded systems
  • Permitted methods
  • Prohibited methods
  • Emergency contacts
  • Reporting requirements

A professional penetration tester should be comfortable reading and following a scope document.


Stage 20: Learn Intelligence Gathering

Before deeper testing, understand the target.

This can include:

  • Domains
  • Subdomains
  • IP addresses
  • Technologies
  • Applications
  • Publicly available information

Always keep information gathering within the authorized scope.


Stage 21: Learn Threat Modeling

Threat modeling asks questions such as:

  • What are the important assets?
  • Who might attack them?
  • What attack paths could exist?
  • What security controls are present?
  • What happens if a control fails?

Threat modeling gives penetration testing context.


Stage 22: Learn Post-Exploitation Concepts

At an advanced level, security testers may need to understand what could happen after an initial compromise.

Study concepts such as:

  • Privilege boundaries
  • Credential exposure
  • Network segmentation
  • Lateral movement concepts
  • Persistence concepts
  • Detection opportunities

Practice these concepts only inside explicitly authorized labs.

The goal is to understand potential business impact and defensive controls, not to gain access to unrelated systems.


Stage 23: Learn Reporting

Reporting is one of the most important professional skills.

A good report may contain:

Executive Summary
Scope
Methodology
Limitations
Findings
Evidence
Risk
Impact
Recommendations
Retest Results
Appendices

A technical person should be able to reproduce the issue from the information provided, while management should be able to understand the business significance.


What Should a Penetration Testing Finding Contain?

A practical finding structure is:

Title
↓
Affected Asset
↓
Description
↓
Evidence
↓
Impact
↓
Risk Context
↓
Recommendation
↓
References
↓
Retest Status

For example:

Finding:
Insufficient Authorization

Affected Asset:
Authorized Test Application

Description:
A tested user role was able to access a resource
outside its intended permission boundary.

Impact:
The issue may expose information intended for
another role.

Recommendation:
Enforce server-side authorization checks for
every protected resource and action.

Retest:
Verify that the restricted request is denied.

Stage 24: Learn Vulnerability Prioritization

Not every vulnerability deserves the same remediation priority.

Consider:

  • Likelihood
  • Technical severity
  • Asset importance
  • Exposure
  • Exploitability
  • Business impact
  • Existing controls

This helps organizations decide where to spend limited remediation resources.


Stage 25: Build a Home Pentesting Lab

A lab is one of the best ways to learn penetration testing safely.

A basic setup could contain:

Host Computer
       |
   Virtualization
       |
+------+----------------+
|                       |
Tester VM            Target VM
|                       |
|                Vulnerable App
|                       |
+-----------+-----------+
            |
       Isolated Lab

You can install Linux and Windows virtual machines and connect deliberately vulnerable applications to a controlled network.


How Much Hardware Do You Need?

You do not need an expensive server to begin.

A basic computer that can run one or more virtual machines can be enough for many beginner exercises.

As you progress, more RAM and storage can make virtualization easier.

For resource-constrained learners, start small:

  • One Linux VM
  • One target VM
  • One isolated network

You can expand the lab later.


Stage 26: Build Projects

Projects turn knowledge into evidence.

Beginner Projects

  • Local network inventory tool
  • Python log analyzer
  • File integrity monitor
  • Security headers checker
  • Hashing demonstration application
  • Linux security checklist

Intermediate Projects

  • Mini vulnerability-management dashboard
  • Web security testing report
  • Security log monitoring system
  • Network monitoring dashboard
  • Authentication monitoring tool
  • Cloud configuration checker

Stage 27: Build Your Portfolio

A strong penetration-testing portfolio can include:

  • GitHub projects
  • Lab documentation
  • Security reports
  • Web-security write-ups
  • CTF write-ups from permitted environments
  • Python security scripts
  • Network-analysis projects
  • Remediation examples

For each project, use a consistent structure:

Problem
Scope
Environment
Approach
Tools
Findings
Impact
Remediation
Retest
Lessons Learned

Stage 28: Choose a Specialization

Penetration testing is broad.

Eventually, choose an area to explore deeply.

Web Application Security

Focus on applications, APIs, authentication, authorization, sessions and business logic.

Network Penetration Testing

Focus on network services, segmentation, protocols and infrastructure.

Active Directory

Focus on Windows enterprise environments, identity and access relationships.

Cloud Security

Focus on cloud identities, permissions, configurations and exposed resources.

Mobile Security

Focus on mobile applications and backend communication.

Red Teaming

Focus on broader adversary simulation within carefully defined rules of engagement.


Web Pentesting Roadmap

HTTP
 ↓
HTML / JavaScript
 ↓
Cookies / Sessions
 ↓
Authentication
 ↓
Authorization
 ↓
APIs
 ↓
SQL / Databases
 ↓
OWASP
 ↓
Burp Suite
 ↓
Web Security Labs
 ↓
Reporting

OWASP's Web Security Testing Guide is particularly useful for this path. The project currently lists WSTG 4.2 as its latest released version while 5.0 is being developed. (OWASP WSTG)


Network Pentesting Roadmap

Networking
 ↓
TCP / UDP
 ↓
Ports
 ↓
Services
 ↓
Nmap
 ↓
Wireshark
 ↓
Enumeration
 ↓
Firewall Concepts
 ↓
Network Security
 ↓
Controlled Validation
 ↓
Reporting

Active Directory Learning Roadmap

Windows Fundamentals
 ↓
Users & Groups
 ↓
Domains
 ↓
Active Directory
 ↓
Kerberos Concepts
 ↓
LDAP Concepts
 ↓
Group Policies
 ↓
Permissions
 ↓
Enterprise Security
 ↓
Authorized AD Lab
 ↓
Reporting

Do not begin with advanced Active Directory attack techniques before understanding Windows and identity fundamentals.


Cloud Pentesting Roadmap

Cloud Fundamentals
 ↓
IAM
 ↓
Networking
 ↓
Storage
 ↓
Compute
 ↓
Logging
 ↓
Secrets
 ↓
Configuration
 ↓
Cloud Security Testing
 ↓
Reporting

Cloud testing requires additional attention to the provider's security-testing policies and the organization's authorization.


Certifications and Penetration Testing

Certifications can provide structure and may help demonstrate certain knowledge or hands-on capabilities.

Before selecting one, compare:

  • Current syllabus
  • Exam format
  • Practical requirements
  • Prerequisites
  • Cost
  • Renewal requirements
  • Relationship to your target role

Do not choose a certification simply because somebody says it is "the best."

First identify the skills you need.


Skills vs Certifications

Skill Evidence Certification Evidence
ProjectsExam result
Lab reportsCredential
GitHub repositoriesCertification body
Practical demonstrationsStructured learning path
Security write-upsFormal assessment

For a strong profile, skills and documented practice should support any certifications you earn.


A 12-Month Penetration Testing Study Plan

Month Focus
1Computer fundamentals
2Networking fundamentals
3Linux
4Windows + PowerShell
5Python + SQL
6HTTP + Web Technologies
7Security fundamentals
8Nmap + Wireshark
9Web security + Burp Suite
10Hands-on labs
11Specialization + projects
12Reporting + portfolio + interview preparation

This is a flexible example. Your progress depends on your existing knowledge, available study time and amount of hands-on practice.


A Daily Penetration Testing Study Routine

A balanced routine could look like:

30 min → Theory
30 min → Networking / Linux
60 min → Hands-on Lab
30 min → Notes
30 min → Project

On busy days, even one focused practical session can be useful.


How to Practice Efficiently

Do not spend all your time watching tutorials.

Use a cycle such as:

Learn
 ↓
Practice
 ↓
Break
 ↓
Understand
 ↓
Fix
 ↓
Document
 ↓
Repeat

The "document" step is often ignored, but it becomes valuable when building a professional portfolio.


How to Take Notes

Create separate notes for:

  • Networking
  • Linux
  • Windows
  • Web security
  • Nmap
  • Wireshark
  • Burp Suite
  • OWASP
  • Labs
  • Reporting

For every new concept, write:

What is it?
Why does it matter?
How does it work?
How can I detect it?
How can it be fixed?

How to Measure Your Progress

Do not measure your progress only by the number of tools installed.

Instead, ask whether you can:

  • Explain how a network works
  • Interpret Nmap results
  • Read HTTP requests
  • Understand authentication
  • Identify an authorization problem in a lab
  • Analyze logs
  • Write a Python automation script
  • Explain the impact of a finding
  • Recommend a remediation
  • Write a professional report

Common Beginner Mistakes

1. Starting With Advanced Exploitation

Build fundamentals first.

2. Ignoring Networking

Network knowledge is foundational.

3. Learning Only Kali Linux

Kali is an environment, not a substitute for understanding Linux and security.

4. Memorizing Commands

Understand why and when to use a command.

5. Using Automated Scanners Without Verification

Scanner results can require manual validation.

6. Ignoring Reporting

Professional security work requires clear communication.

7. Practicing on Unauthorized Targets

This can create legal, contractual and operational problems.

8. Collecting Certifications Without Practical Work

Build real technical evidence alongside any certifications.


What Should You Avoid Learning First?

You do not need to begin with:

  • Advanced exploit development
  • Complex malware analysis
  • Advanced reverse engineering
  • Highly specialized hardware attacks
  • Complex red-team infrastructure

These topics can come later.

Build a strong foundation first.


How to Build a Professional Pentesting Mindset

Instead of asking:

"Which exploit should I run?"

learn to ask:

"What is the system supposed to do, what security control protects it, and can I demonstrate a weakness within the authorized scope?"

This mindset encourages analysis before action.


Penetration Testing and Secure Development

Application security should not depend only on penetration testing after an application has been built.

OWASP's current testing framework emphasizes considering security throughout the software lifecycle, including definition, design, development, deployment, maintenance and operations. (OWASP Testing Framework)

A broader secure-development process can look like:

Requirements
 ↓
Threat Modeling
 ↓
Secure Design
 ↓
Secure Coding
 ↓
Code Review
 ↓
Security Testing
 ↓
Deployment
 ↓
Monitoring
 ↓
Penetration Testing
 ↓
Improvement

Penetration testing is therefore one part of a larger security program.


How a Penetration Tester Should Think About a Finding

A useful mental model is:

Weakness
   ↓
Can It Be Validated?
   ↓
What Access Does It Provide?
   ↓
What Resource Is Affected?
   ↓
What Is The Security Impact?
   ↓
How Should It Be Fixed?

This turns technical observations into actionable security findings.


Penetration Testing Portfolio Checklist

  • □ Linux lab
  • □ Windows lab
  • □ Networking project
  • □ Nmap project
  • □ Wireshark analysis
  • □ Web-security lab
  • □ Burp Suite exercise
  • □ Python automation project
  • □ Vulnerability report
  • □ Remediation example
  • □ GitHub repository
  • □ Technical write-up

Frequently Asked Questions

1. What should I learn first for penetration testing?

Start with computer fundamentals, networking, Linux and Windows basics. Then add programming, web technologies and security fundamentals.

2. Is Kali Linux enough to become a penetration tester?

No. Kali Linux provides a useful security-testing environment, but it does not replace networking, Linux, Windows, programming, web-security knowledge and hands-on practice.

3. Is networking important for penetration testing?

Yes. Networking is one of the most important foundations for understanding ports, services, protocols, firewalls and network behavior.

4. Do I need programming for penetration testing?

You do not need advanced programming immediately, but Python, Bash, PowerShell, SQL and JavaScript can become very useful as your skills develop.

5. Which programming language should I learn first?

Python is a practical starting point because it is useful for automation, scripting, APIs and data processing.

6. Should I learn web security?

Yes, especially if you are interested in websites and APIs. HTTP, authentication, authorization, sessions, databases and application architecture are important foundations.

7. Is Nmap enough for penetration testing?

No. Nmap is useful for discovery and service identification, but a penetration test requires planning, analysis, validation, reporting and remediation.

8. What is the difference between vulnerability assessment and penetration testing?

Vulnerability assessment generally focuses on finding potential weaknesses, while penetration testing can include controlled validation of selected weaknesses and their security impact.

9. Can I practice penetration testing on public websites?

Do not assume that public availability means authorization. Use your own systems, training platforms, deliberately vulnerable labs or systems where you have explicit permission.

10. How long does it take to learn penetration testing?

There is no universal timeline. Progress depends on your current technical knowledge, study time, hands-on practice and chosen specialization.

11. Do I need certifications?

Certification requirements vary by role and employer. Certifications can be useful, but they should complement practical knowledge and project experience.

12. Is reporting really important?

Yes. A professional tester needs to communicate findings, impact and remediation clearly. Technical testing without useful documentation has limited value to the organization.

13. What is the PTES methodology?

The Penetration Testing Execution Standard organizes penetration testing into seven phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting. OWASP references PTES in its penetration-testing methodology guidance. (OWASP PTES Reference)

14. What is OWASP WSTG?

The OWASP Web Security Testing Guide is a practical reference for testing web applications and web services. The project currently lists version 4.2 as the latest released version while version 5.0 is under development. (OWASP WSTG)


Final Thoughts

Penetration testing is not something you learn by installing a security distribution and memorizing commands.

A stronger roadmap is:

Computers → Networking → Linux → Windows → Programming → Web → Security → Tools → Labs → Methodology → Reporting → Specialization

Build each layer before moving heavily into the next one.

NIST's technical security-testing guidance emphasizes planning, execution and evaluation, while OWASP's current testing resources emphasize adaptable methodologies, risk-based prioritization and a combination of automated and manual techniques. (NIST SP 800-115)

The biggest mistake beginners make is focusing on how to attack before understanding how the system works.

Reverse that order.

Learn the technology first, practice safely, document your findings, understand remediation and gradually specialize.

That gives you a much more useful foundation for a long-term penetration-testing career.

Remember: Authorization is part of the technical process, not an optional detail. Always know exactly what you are allowed to test before performing security testing.

Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.