CPTS Study Roadmap
This is the plan I’m actually following, not a wish list. Every phase has the HTB Academy modules (which are basically the CPTS syllabus in order), a few books to go deeper, some online reading, and boxes to practice on.
The loop that actually sticks: do one module, root 2 or 3 boxes on that topic, then write my own note about what worked. If I can’t explain it in a note, I didn’t really learn it.
How I use this page
- Study a phase top to bottom. No skipping ahead to Active Directory when enumeration still feels shaky.
- Only read a writeup after I’ve genuinely wrestled with the box myself. Reading the answer first is just lying to yourself.
- Each topic’s note lands in its matching folder here (
enumeration/,web/, and so on).
Phase 0: foundations (keep chipping at these the whole time)
You can’t hack what you don’t understand. These run in the background the entire journey.
- Actually comfortable in a Linux terminal
- Get the basics of TCP/IP, ports, DNS, and HTTP
- Understand how a Windows domain hangs together (users, groups, auth)
Books:
- The Linux Command Line by William Shotts (free PDF). The terminal until it’s muscle memory.
- How Linux Works by Brian Ward. What’s really going on under the shell.
- Computer Networking: A Top-Down Approach by Kurose and Ross. Solid networking base.
- TCP/IP Illustrated, Vol. 1 by W. Richard Stevens. Reference for when the packets actually matter.
Phase 1: recon and enumeration
- Academy: Network Enumeration with Nmap
- Academy: Footprinting
- Academy: Information Gathering, Web Edition
- Wrote my
enumeration/methodology.mdnote - Rooted 3+ enumeration-heavy easy boxes
Books:
- Nmap Network Scanning by Gordon “Fyodor” Lyon. Written by the guy who made Nmap. It’s the only scanning book you need.
- Open Source Intelligence Techniques by Michael Bazzell. For the footprinting and OSINT side.
Online:
- HackTricks, the “Pentesting Methodology” page and the per-port pages. Keep it open.
- 0xdf writeups. Read the enumeration part of any easy box just to absorb the rhythm.
Phase 2: web attacks
This is where most footholds live, so it gets the most love. I went heavy here on purpose.
- Academy: Web Requests
- Academy: Using Web Proxies (Burp Suite)
- Academy: Attacking Web Applications with Ffuf
- Academy: SQL Injection Fundamentals and SQLMap Essentials
- Academy: Cross-Site Scripting (XSS)
- Academy: File Inclusion
- Academy: File Upload Attacks
- Academy: Command Injections
- Academy: Web Attacks (IDOR, XXE, and friends)
- Academy: Login Brute Forcing
- Ground through the PortSwigger labs for each bug class
- Wrote my
web/notes per vuln type
Books:
- The Web Application Hacker’s Handbook by Stuttard and Pinto. The bible. Dense, but it’s all there.
- Bug Bounty Bootcamp by Vickie Li. Modern, practical, and easy to get going with.
- Real-World Bug Hunting by Peter Yaworski. Real disclosed reports that show how bugs actually get found.
- The Tangled Web by Michal Zalewski. How browsers really behave, which makes XSS and CSP click.
- OWASP Testing Guide and the OWASP Top 10. Free, and the industry-standard checklist.
Online (the best web resource out there, full stop):
- PortSwigger Web Security Academy. Free, hands-on labs for every web bug. Do all of them.
- HackTricks, the “Pentesting Web” pages.
Phase 3: foothold, shells, and password attacks
Turning an enum finding or a web bug into a real shell, and cracking whatever you scoop up.
- Academy: Shells and Payloads
- Academy: Password Attacks
- Academy: Cracking Passwords with Hashcat
- Wrote my
foothold/andpassword-attacks/notes
Books:
- The Hacker Playbook 3 by Peter Kim. Ties all the phases together into one attack flow.
- Hash Crack by Joshua Picolet. A handy hashcat and john reference.
- Red Team Field Manual (RTFM) by Ben Clark. Command cheat book to keep next to you while you work.
Online:
- GTFOBins for Linux and LOLBAS for Windows. Living-off-the-land binaries you’ll use constantly.
- The Hashcat wiki for modes and rules.
Phase 4: Linux privilege escalation
- Academy: Linux Privilege Escalation
- Wrote my
privesc-linux/note - Rooted 5+ Linux boxes
Books:
- The Linux Command Line by Shotts. Go back and really chew on the permissions and processes chapters.
- Linux Basics for Hackers by OccupyTheWeb. Practical Linux with a security slant.
Online:
- g0tmi1k, “Basic Linux Privilege Escalation.” The classic article everyone cuts their teeth on.
- HackTricks Linux privesc checklist.
- Tools worth knowing:
linpeas,pspy,linux-exploit-suggester.
Phase 5: Windows privilege escalation
- Academy: Windows Privilege Escalation
- Wrote my
privesc-windows/note - Popped SYSTEM on 5+ Windows boxes
Books:
- Windows Internals, Part 1 by Russinovich and co. Deep. Use it as a reference, don’t read it cover to cover.
- The Hacker Playbook 3, the Windows chapters.
Online:
- HackTricks Windows local privesc checklist.
- Tools worth knowing:
winPEAS,PowerUp,Seatbelt.
Phase 6: Active Directory
This is the meat of the CPTS exam and the Pro Labs. After web, give this the most time.
- Academy: Introduction to Active Directory
- Academy: Active Directory Enumeration and Attacks
- Learned BloodHound front to back
- Wrote my
active-directory/notes - Finished Pro Lab: Dante, then Zephyr
Books:
- The Hacker Playbook 3, the AD attack chapters.
- Pentesting Azure Applications by Matt Burrough, if you drift into cloud AD.
Online:
- adsecurity.org by Sean Metcalf. Deep, deep AD attack writeups.
- HackTricks “Active Directory Methodology.”
- The BloodHound docs, plus the “Certified Pre-Owned” paper on AD CS attacks from SpecterOps.
- harmj0y’s blog for the foundational AD tradecraft.
Phase 7: pivoting, tunneling, and port forwarding
- Academy: Pivoting, Tunneling and Port Forwarding
- Wrote my
pivoting/note - Practiced on a multi-host Pro Lab
Online:
- Ligolo-ng docs. Newer and honestly the easiest to reason about.
- chisel and sshuttle docs.
- HackTricks “Tunneling and Port Forwarding.”
Phase 8: documentation and reporting
The boring-sounding skill that actually turns a hobbyist into someone who gets paid. Write a report for every single box.
- Academy: Documentation and Reporting
- Wrote a full report for at least one box
- Built my own report template
Online:
- PTES (Penetration Testing Execution Standard).
- TCM Security’s free sample pentest report.
- Read one real public pentest report to steal the structure.
Programming: the languages you really need
Nobody’s asking you to be a software engineer. But you have to be able to read a script, tweak it, and bang out your own when nothing off the shelf fits. Here’s the order I’d learn them in.
1. Bash, non-negotiable (Linux glue)
Automating enum, chaining tools, one-liners on a target.
- The Linux Command Line by William Shotts (free)
- Learn Bash the Hard Way by Ian Miell
2. Python, non-negotiable (tooling and exploits)
Editing public exploits, writing quick scripts, automating the grind.
- Automate the Boring Stuff with Python by Al Sweigart (free). Start here.
- Black Hat Python by Seitz and Arnold. Offensive tooling.
- Violent Python by TJ O’Connor. Security scripting projects.
3. PowerShell, non-negotiable (Windows and AD)
Enumeration and post-exploitation on Windows.
- Learn PowerShell in a Month of Lunches by Don Jones
- PowerShell for Sysadmins by Adam Bertram
4. SQL, so SQL injection actually makes sense
- Any solid primer, like SQL in 10 Minutes by Ben Forta
- Then throw it at the PortSwigger SQLi labs
5. JavaScript and HTML, for the web side (XSS, app logic)
- Eloquent JavaScript by Marijn Haverbeke (free)
- Enough HTML and DOM to see what an app is doing
6. C, to read exploits and get memory corruption
- The C Programming Language by Kernighan and Ritchie (K&R)
- Hacking: The Art of Exploitation by Jon Erickson. This is the one that ties C, assembly, and exploitation into a single lightbulb moment. Save it for once the basics are solid.
Optional, down the road
- Go. Tons of modern offensive tooling is written in it, so it’s nice to read.
- Ruby. Metasploit modules are Ruby, only worth it if you’re editing them.
- PHP. Handy when you’re reading web app source during a box.
Bare minimum to be dangerous: Bash, Python, and PowerShell. Pick up SQL and JS once you hit the web phase. Leave C and Art of Exploitation for when nothing else scares you anymore.
Boxes to practice on
- TJ Null’s OSCP prep list. Curated HTB machines sorted by topic. This is the go-to.
- HTB Starting Point. Guided and gentle, do this before anything else.
- Filter HTB by tag or OS so the box matches whatever phase you’re on.
- Once the phases are done: Pro Labs. Dante for range, Zephyr for AD, then the scarier ones.
This page is alive. I tick boxes and add books as I go.