FREE Path To Become An Ethical Hacker (2024 Roadmap)

413.54k views3617 WordsCopy TextShare
The Infosec Academy
Companion Guide with links to all resources: https://theinfosecacademy.com/hacking-lab-companion-gui...
Video Transcript:
so you want to be a hacker so did I I got a Bachelor's degree in cyber security I got certifications and I even taught 13 000 boot camps at a respected University but I wouldn't recommend that you take any of those paths no there is a path that you can take to become a hacker without spending a single dollar to be a hacker you have to have certain characteristics you have to have the Hacker's mindset a hacker's mindset is one of perseverance and creativity hackers don't give up they are perseverant dedicated people who once they
set their mind on a task they don't give up till they accomplish it and this is something you have to develop you also have to be creative someone who comes up with unique solutions to existing and unique problems do you settle for the status quo or are you always looking for a way to be more efficient more effective do things better or even just to break things those are traits you must have as a hacker and you need to be someone who can teach yourself things or know how to learn things quickly but don't worry
even if you weren't inherently born with these characteristics like some people you can learn them over time you can teach yourself to have a hacker's mindset when I started my journey to become a hacker I didn't have money to spend I couldn't go buy fancy boot camps or big certifications so I want to give you some resources to help you along your journey to become an ethical hacker But first you need to think about this as a journey a marathon not a Sprint this is something that takes time it takes dedication and it takes devotion
but with perseverance and the right mindset anyone who wants to can become a hacker so as we talk about this journey keep in mind that where you start on this journey it's going to vary based on your expertise and your knowledge are you someone who already Works in it maybe you're a network engineer help desk and you have some knowledge maybe you skip ahead in this journey if you're someone new to computers with very little knowledge maybe you start at the beginning it's all up to you but what I want to tell you are the
important things you need to know to be a good hacker based on my experience and the experience of my peers in the industry number one is you have to know computer basis you have to know your way around found a computer the parts of the computer and how computers work if we were to talk about certifications which were not because you have to pay for them obviously this would be what you would find in the CompTIA a plus certification so to learn computer Basics I would recommend that you start with Professor Messer on YouTube he
has a CompTIA a plus course that will walk you through all the basics and teach you everything you need to know about computers operating systems and how they work personally though I find Professor messer's video to be a little dry and I like something a little more exciting a little more engaging which is where my next recommendation of Paul Browning's YouTube channel comes in he also has a CompTIA a plus course on YouTube that's very very good very thorough and a little bit more engaging than Professor messers now we are talking about free but if
you want to spend just a little bit of money for about 29 on udemy you can get the a plus course by Mike Myers I really like Mike Myers teaching style his excitement the examples he uses and how interactive his teaching style is so if you were to spend a little money 29 for his course is a great place to spend it okay next up is networking have you ever heard of the OSI model do you know how IP addresses work what is Mac what is art what is DNS if you don't know these you
need to go back to network this is one of those Core Concepts that you have to know to be a hacker you see hackers are people who already have basic knowledge about things and then they want to go a step further and they want to start investigating and poking and prodding so you have to have these fundamentals and The Core Concepts before you can go on to hacking it and breaking it so when we're talking about networking we're talking about the kinds of things that you would find in a CCNA certification or a network plus
from CompTIA so you could pursue free training on both of those certifications and not actually sit the certification and still get the knowledge from it so again here Professor Messer has a network plus course on YouTube that is free and so does the Paul Browning YouTube channel we talked about if you were going to go that route I like Paul Browning's again a little bit more than Professor messers but because it's a little bit more engaging and it's a little less dry than Professor messers but watch both both are going to give you a lot
of knowledge then there is the Google bits and bytes course of networking this is a course that they Google has put together about networking and they host it through Coursera now this is part of a degree that Google has put together and you do have to pay a subscription on Coursera to have access to that however you can audit this course for completely for free still get all the knowledge out of it and not have to pay and finally there's the Cisco training Cisco has the network Academy parts of which have recently moved to skills
for all website also run by Cisco so some of their courses are still left on network Academy and some are on this new skills for all site they're networking essential course which has moved to the skills for all site is very very good and very very thorough in learning networking fundamentals all right next up is you have to learn Linux so many servers so many systems today use Linux and you as an ethical hacker are probably going to end up using a Linux operating system so you need to learn Linux in my opinion is the
best way to learn Linux is to get down and dirty with it if you have a spare computer put the Linux operating system on it start with something like Ubuntu that has a GUI a graphical user interface and start using that on a daily basis as you go start learning command line try to do everything you could do on a GUI via command line to start learning the ropes of the operating system you could do the same thing using virtualbox you could install a Linux virtual machine on your computer to start getting practice now aside
from the down and dirty there are a few free resources that are great places to start learning Linux one of the places I started was over the wire Bandit this is a website with a series of challenges that you can go through to start learning the Linux operating system they start easy and they progressively increase in complexity As you move along and start solving these challenges it's a great way to learn Hands-On the next resource is the red hat interactive Labs these are online Labs that you can learn and you have a console there in
the labs to start getting Hands-On practice using Linux they walk you through challenges and help you learn the ropes of the Linux operating system if you want to go a step further you could get your own Virtual Lab through the red hat Labs as a service and if you do a 60-day trial you would have 60 days of free access to these labs and then you could cancel before that 60 days is up and have two months to learn Linux for free and here again Cisco's Network Academy has a course on Linux Essentials that is
also a great place to get some Hands-On knowledge and to get started with learning Linux all right so now you know computer Basics you're learning Linux and you've learned a little bit about Network it's time to get your foundations and security late this isn't hacking per se you could start learning about hacking sure but these are Security Essentials basics of cyber security that you need to know to become an ethical hacker one of my favorite places for learning security is try hack me this is an online site with lots and lots of labs and rooms
and Hands-On practice to help you learn all aspects of security I love their learning approach they start simple they gradually increase the complexity they'll walk you through an exercise have you fill in questions and then they'll leave you on your own on other ones and give you hints I personally think it's a great approach to learning security that's not completely hand-holding but it's not completely dumping you either it's this Middle Ground of walking you through as well as gradually giving you more and more to do on your own and this is that one place I
would highly recommend you spend a little money for 16 a month you can get access to their full platform have your own private lab you get your Cal Linux machine you get access to all of the training all of their labs and all of their rooms where you can start practicing security there's Linux Labs here there's Windows here Windows security cryptography web security web Basics there's all kinds of things you can learn in try hack me again this is one of my favorite platforms and the place I would highly recommend spend a little money for
16 a month the prices of two meals at McDonald's you can get far in your ethical hacking Journey the next resource is Pico CTF this is a website with a ton of challenge style learning modules there's all kinds of things you can learn about web security about cryptography and many other paths yes there are some hacking mixed into this but it's also a great place you can start with the basics and the essentials and it's a thought-provoking method of learning it's not as much hand-holding or teaching a try hacking does in our early parts of
their modules but you can generally find walk-throughs or hints that will help you learn these things again as a hacker you need to be a self-taught and self motivated and doing something like pico CTF is going to help you learn research how can you quickly learn what you need to learn to solve these challenges another resource is the attack IQ Academy over the last few years I've taken several other courses and I really like the training that you can get there for completely free another resource is blue team Labs online now while this is a
blue team and you might not think it has anything to do with hacking understanding proper defense is going to help you as a hacker you have to understand what the defense is doing to know how to break it and how to bypass it and that's where blue teams online this free resource for learning blue team Essentials is a great resource for doing just that and Here Again The Cisco networking Academy has several courses on cyber security and cyber security essentials that are going to be very good free resources these are Big courses that teach you
a lot about security and are definitely worth checking out all right the next thing you need to learn in your hacking journey is coding and scripting no you don't have to be an expert programmer frankly I wouldn't classify myself as an expert programmer but you need to learn programming Basics and you really have to know how to read code especially if you're downloading scripts or you're downloading exploits you have to know how to read that code be sure it's safe and know how to run it and understand what it's doing to Be an Effective hacker
so you do need a little bit of coding and scripting experience and it'll help you automate if you can write scripts to automate tasks as a hacker it'll save you a ton of time and energy and frustration so to learn programming where should you start there are a ton of programming languages there's a ton of ways to program I would say start with python it comes up over and over again in cyber security it's one of the easiest languages to learn and it's completely free you can get everything you need to Learn Python without spinning
anything and it's just popular among hackers check out Cisco networking Academy's python Essentials course this is a course that will help you learn python Basics there are YouTube courses on this the Cyber Mentor he has a great YouTube video course to teach you python Basics free codecam this is a non-profit organization completely free that helps people learn coding and programming skills they have several courses on different aspects of python and inside of their cyber security course they have a module on python for hackers which focuses on the parts of python that would be useful for
hacker that deal with networking or packet analysis or packet capturing again those parts that would be the most useful for a hacker and in addition to python I would highly recommend you learn Powershell a huge percentage of businesses today use Microsoft Windows they use active directory and knowing Powershell and knowing Powershell scripting Powershell programming whatever you want to call it is going to help you in these environments if you choose to go with that type of pen testing when I wanted to learn Powershell I went to Microsoft the Microsoft Virtual Academy has a huge series
on Powershell they'll take you from the basics all the way up to scripting and even better it's taught by the man who created Powershell himself it's a great course for learning Powershell alright the next thing you need to learn in your hacking journey is the cloud there's no question organizations are depending on the cloud more and more for their infrastructure for their platforms and you need to understand these Cloud providers Azure AWS Google how they work what's unique about them if you're going to hack them effectively the AWS security certification training is a great place
to start learning AWS they also have similar free courses on AWS Essentials in different aspects of AWS they're all free they are the training geared towards certifications but you don't have to sit the test or take the certifications the same thing in Azure they have free training on Azure security Azure fundamentals you can go watch those videos take the training you could even do a trial of azure or AWS and get free access to their resources for a period of time Google also has a Google Cloud skills boost that's going to teach you Cloud fundamentals
again totally for free all right and now we get to the hacking part if you're jumping right in here good for you if you've worked up to this point good for YouTube it's time to get your hands down already and start learning actual hacking again here try hack me is going to be the place to start they have excellent modules excellent training even on their free tier to help you learn hacking and like I've already mentioned I would highly recommend you spend the 16 a month to get the pro tier you're going to get access
to more Labs you're going to get faster lab computers VPN access into their labs and you get access to some private rooms as they call them where you get these total environments where you can just practice and learn about hacking active directory websites and several other room types these are great places to start putting your knowledge to the test another site similar to try hack me but with let's focus on the training part more on the practice is hack the Box you get access to a lot of lab devices that you can hack against and
learn hacking now if you upgrade and you pay a little bit here also you get access to expired devices and the reason this is beneficial is all of the live devices hack the Box ask that everyone who does them not talk about however expired boxes p people start doing write-ups they'll walk you through the process of the steps you should have taken to hack that box and while I wouldn't recommend that you totally go follow these walkthroughs but if you're stuck you could go read The Next Step maybe and get ideas for where to take
this next and continue learning as you go but those are features you only get when you pay again here it's not that much and after try hack me this is the second place I would recommend spending a little bit of money because of the value that you could get from it there are a lot of good blogs on ethical hacking two of my favorite are hackers arise he has tons and tons of great walkthroughs on hacking scenarios and how to hack different things like Wi-Fi and windows and various hacking attacks the other one is GB
hackers they also have some very good walkthroughs of hacking scenarios and different hacking projects those are only two there are many many more alright the next resource is burp Suite Academy burp Suite makes one of the most common tools for web app packing and web app penetration testing they have an academy which is by far the go-to place to learn web app hacking and web app security it's totally free but if you want it after you complete the training you could get the burp Suite certification we won't discuss that because of course we're talking about
free resources but burp Suite Academy is a go-to place to learn web security and web app hacking another good place for web app hacking is hacker 101 by hacker one hacker one is a bug Bounty website where companies will allow hackers to find vulnerabilities and disclose them for prizes for cash rewards and while doing bug bounties is a good place to practice your hacking skills as you learn them they have some good training as well hacker 101 of course geared towards web app bug bounty hunters or those interested in getting into it again this is
a great place to learn web app Basics web app hacking and all about websites how they work so you understand the back end this is something very important to hacking in general in all areas you need to understand how it works and how it's intended to work so you know how to break it and that's where hacker 101 comes in to give be those basics in that background on web apps and web app security Now if you have a computer with some resources capable of running virtual machines check out Von Hub this is a website
with a bunch of vulnerable boxes virtual machines that you can download you can download them run them on your own system and you can hack against them you don't need internet to do this it's all local and there are a ton of walkthroughs for phone Hub boxes and like we talked about with hack the box you can use these walkthroughs to help you along your learning process and finally YouTube channels there are a ton of YouTube videos to teach you hacking two of my favorite are the Cyber Mentor he has complete free courses 15 hours
and longer to teach you ethical hacking to teach you the basics of hacking and to get you ready to move on to more advanced concepts next is hacker sport hackersploit does a ton of walkthroughs on phone Hub on hack the Box Andy has some great hacking videos that you should check out now there are many many more YouTube channels dedicated to hacking go check them all Fallout go watch as many as you want those are just two of my favorite and there you have it that is a complete road map to get you from no
computer knowledge all the way to an ethical hacker and once you have the basics of hacking down you can choose your expertise maybe you want to move on to apis or iot hacking or scada hacking or maybe you want to delve deeper into web app hacking or active directory and networks there are plenty of forks in the road you can take or specializations you can go down once you learn basic hacking to Niche down your skills and make yourself more valuable and for higher paying jobs did I miss a resource that you like let me
know in the comments below and please subscribe and hit the Bell notification to support the channel
Copyright © 2024. Made with ♥ in London by YTScribe.com