This is the plan I’m actually following, not a wish list. Every phase has the HTB Academy modules (which are basically the CPTS syllabus in order), a few books to go deeper, some online reading, and boxes to practice on.

The loop that actually sticks: do one module, root 2 or 3 boxes on that topic, then write my own note about what worked. If I can’t explain it in a note, I didn’t really learn it.

How I use this page

  • Study a phase top to bottom. No skipping ahead to Active Directory when enumeration still feels shaky.
  • Only read a writeup after I’ve genuinely wrestled with the box myself. Reading the answer first is just lying to yourself.
  • Each topic’s note lands in its matching folder here (enumeration/, web/, and so on).

Phase 0: foundations (keep chipping at these the whole time)

You can’t hack what you don’t understand. These run in the background the entire journey.

  • Actually comfortable in a Linux terminal
  • Get the basics of TCP/IP, ports, DNS, and HTTP
  • Understand how a Windows domain hangs together (users, groups, auth)

Books:

  • The Linux Command Line by William Shotts (free PDF). The terminal until it’s muscle memory.
  • How Linux Works by Brian Ward. What’s really going on under the shell.
  • Computer Networking: A Top-Down Approach by Kurose and Ross. Solid networking base.
  • TCP/IP Illustrated, Vol. 1 by W. Richard Stevens. Reference for when the packets actually matter.

Phase 1: recon and enumeration

  • Academy: Network Enumeration with Nmap
  • Academy: Footprinting
  • Academy: Information Gathering, Web Edition
  • Wrote my enumeration/methodology.md note
  • Rooted 3+ enumeration-heavy easy boxes

Books:

  • Nmap Network Scanning by Gordon “Fyodor” Lyon. Written by the guy who made Nmap. It’s the only scanning book you need.
  • Open Source Intelligence Techniques by Michael Bazzell. For the footprinting and OSINT side.

Online:

  • HackTricks, the “Pentesting Methodology” page and the per-port pages. Keep it open.
  • 0xdf writeups. Read the enumeration part of any easy box just to absorb the rhythm.

Phase 2: web attacks

This is where most footholds live, so it gets the most love. I went heavy here on purpose.

  • Academy: Web Requests
  • Academy: Using Web Proxies (Burp Suite)
  • Academy: Attacking Web Applications with Ffuf
  • Academy: SQL Injection Fundamentals and SQLMap Essentials
  • Academy: Cross-Site Scripting (XSS)
  • Academy: File Inclusion
  • Academy: File Upload Attacks
  • Academy: Command Injections
  • Academy: Web Attacks (IDOR, XXE, and friends)
  • Academy: Login Brute Forcing
  • Ground through the PortSwigger labs for each bug class
  • Wrote my web/ notes per vuln type

Books:

  • The Web Application Hacker’s Handbook by Stuttard and Pinto. The bible. Dense, but it’s all there.
  • Bug Bounty Bootcamp by Vickie Li. Modern, practical, and easy to get going with.
  • Real-World Bug Hunting by Peter Yaworski. Real disclosed reports that show how bugs actually get found.
  • The Tangled Web by Michal Zalewski. How browsers really behave, which makes XSS and CSP click.
  • OWASP Testing Guide and the OWASP Top 10. Free, and the industry-standard checklist.

Online (the best web resource out there, full stop):

  • PortSwigger Web Security Academy. Free, hands-on labs for every web bug. Do all of them.
  • HackTricks, the “Pentesting Web” pages.

Phase 3: foothold, shells, and password attacks

Turning an enum finding or a web bug into a real shell, and cracking whatever you scoop up.

  • Academy: Shells and Payloads
  • Academy: Password Attacks
  • Academy: Cracking Passwords with Hashcat
  • Wrote my foothold/ and password-attacks/ notes

Books:

  • The Hacker Playbook 3 by Peter Kim. Ties all the phases together into one attack flow.
  • Hash Crack by Joshua Picolet. A handy hashcat and john reference.
  • Red Team Field Manual (RTFM) by Ben Clark. Command cheat book to keep next to you while you work.

Online:

  • GTFOBins for Linux and LOLBAS for Windows. Living-off-the-land binaries you’ll use constantly.
  • The Hashcat wiki for modes and rules.

Phase 4: Linux privilege escalation

  • Academy: Linux Privilege Escalation
  • Wrote my privesc-linux/ note
  • Rooted 5+ Linux boxes

Books:

  • The Linux Command Line by Shotts. Go back and really chew on the permissions and processes chapters.
  • Linux Basics for Hackers by OccupyTheWeb. Practical Linux with a security slant.

Online:

  • g0tmi1k, “Basic Linux Privilege Escalation.” The classic article everyone cuts their teeth on.
  • HackTricks Linux privesc checklist.
  • Tools worth knowing: linpeas, pspy, linux-exploit-suggester.

Phase 5: Windows privilege escalation

  • Academy: Windows Privilege Escalation
  • Wrote my privesc-windows/ note
  • Popped SYSTEM on 5+ Windows boxes

Books:

  • Windows Internals, Part 1 by Russinovich and co. Deep. Use it as a reference, don’t read it cover to cover.
  • The Hacker Playbook 3, the Windows chapters.

Online:

  • HackTricks Windows local privesc checklist.
  • Tools worth knowing: winPEAS, PowerUp, Seatbelt.

Phase 6: Active Directory

This is the meat of the CPTS exam and the Pro Labs. After web, give this the most time.

  • Academy: Introduction to Active Directory
  • Academy: Active Directory Enumeration and Attacks
  • Learned BloodHound front to back
  • Wrote my active-directory/ notes
  • Finished Pro Lab: Dante, then Zephyr

Books:

  • The Hacker Playbook 3, the AD attack chapters.
  • Pentesting Azure Applications by Matt Burrough, if you drift into cloud AD.

Online:

  • adsecurity.org by Sean Metcalf. Deep, deep AD attack writeups.
  • HackTricks “Active Directory Methodology.”
  • The BloodHound docs, plus the “Certified Pre-Owned” paper on AD CS attacks from SpecterOps.
  • harmj0y’s blog for the foundational AD tradecraft.

Phase 7: pivoting, tunneling, and port forwarding

  • Academy: Pivoting, Tunneling and Port Forwarding
  • Wrote my pivoting/ note
  • Practiced on a multi-host Pro Lab

Online:

  • Ligolo-ng docs. Newer and honestly the easiest to reason about.
  • chisel and sshuttle docs.
  • HackTricks “Tunneling and Port Forwarding.”

Phase 8: documentation and reporting

The boring-sounding skill that actually turns a hobbyist into someone who gets paid. Write a report for every single box.

  • Academy: Documentation and Reporting
  • Wrote a full report for at least one box
  • Built my own report template

Online:

  • PTES (Penetration Testing Execution Standard).
  • TCM Security’s free sample pentest report.
  • Read one real public pentest report to steal the structure.

Programming: the languages you really need

Nobody’s asking you to be a software engineer. But you have to be able to read a script, tweak it, and bang out your own when nothing off the shelf fits. Here’s the order I’d learn them in.

1. Bash, non-negotiable (Linux glue)

Automating enum, chaining tools, one-liners on a target.

  • The Linux Command Line by William Shotts (free)
  • Learn Bash the Hard Way by Ian Miell

2. Python, non-negotiable (tooling and exploits)

Editing public exploits, writing quick scripts, automating the grind.

  • Automate the Boring Stuff with Python by Al Sweigart (free). Start here.
  • Black Hat Python by Seitz and Arnold. Offensive tooling.
  • Violent Python by TJ O’Connor. Security scripting projects.

3. PowerShell, non-negotiable (Windows and AD)

Enumeration and post-exploitation on Windows.

  • Learn PowerShell in a Month of Lunches by Don Jones
  • PowerShell for Sysadmins by Adam Bertram

4. SQL, so SQL injection actually makes sense

  • Any solid primer, like SQL in 10 Minutes by Ben Forta
  • Then throw it at the PortSwigger SQLi labs

5. JavaScript and HTML, for the web side (XSS, app logic)

  • Eloquent JavaScript by Marijn Haverbeke (free)
  • Enough HTML and DOM to see what an app is doing

6. C, to read exploits and get memory corruption

  • The C Programming Language by Kernighan and Ritchie (K&R)
  • Hacking: The Art of Exploitation by Jon Erickson. This is the one that ties C, assembly, and exploitation into a single lightbulb moment. Save it for once the basics are solid.

Optional, down the road

  • Go. Tons of modern offensive tooling is written in it, so it’s nice to read.
  • Ruby. Metasploit modules are Ruby, only worth it if you’re editing them.
  • PHP. Handy when you’re reading web app source during a box.

Bare minimum to be dangerous: Bash, Python, and PowerShell. Pick up SQL and JS once you hit the web phase. Leave C and Art of Exploitation for when nothing else scares you anymore.

Boxes to practice on

  • TJ Null’s OSCP prep list. Curated HTB machines sorted by topic. This is the go-to.
  • HTB Starting Point. Guided and gentle, do this before anything else.
  • Filter HTB by tag or OS so the box matches whatever phase you’re on.
  • Once the phases are done: Pro Labs. Dante for range, Zephyr for AD, then the scarier ones.

This page is alive. I tick boxes and add books as I go.