Field kit
Career paths
Cert & skill roadmaps
Week-by-week plans mapped to OpsField modules, labs, playbooks, and cheatsheets. Adjust hours to your life — consistency beats hero weeks.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
None — skills first
beginner
8 weeks · 6–10 hours~64h plannedBeginner foundations (no cert)
Build a safe home lab, learn networking and Linux, practice ethical recon and scanning on systems you own, and write your first findings. No exam pressure — competence and habits first.
Outcomes
- Isolated lab with snapshots and clear RoE for personal gear
- Comfortable Linux CLI and TCP/IP mental model
- Can inventory a home LAN and harden the router/IoT basics
- Can map a simple web app with proxy + directory discovery
- Write a short finding with risk and remediation
Weekly plan
Week 1
8h
Ethics, scope, and lab zero
- Read Rules of Engagement mindset; write a personal lab RoE
- Install hypervisor; create host-only network
- Deploy attacker VM (Kali/Parrot); take snapshots
- Practice note-taking template for every session
Week 2
8h
Networking fundamentals
- Study OSI/TCP-IP, ports, DNS, DHCP, NAT
- Use ip, ss, dig, curl daily on lab VMs
- Draw your home network; mark trusted vs IoT
- Capture a simple pcap and open it in Wireshark
Week 3
8h
Linux as daily driver
- File permissions, processes, services, logs
- SSH keys only; disable password auth on lab SSH
- Install and update tools via package manager
- Write a one-page Linux cheatsheet of your own
Week 4
8h
Home LAN discovery
- ARP/ping discovery on network you own
- Gentle nmap top-ports census; save -oA
- Identify cameras, NAS, phones, printers
- Start asset inventory spreadsheet
Week 5
8h
Router and IoT hardening
- Disable WPS and WAN admin if present
- Review UPnP forwards; remove surprises
- Segment guest/IoT if router supports it
- Change defaults on owned cameras; document RTSP risk
Week 6
8h
Web basics in a safe app
- Deploy DVWA or Juice Shop in lab only
- Configure browser proxy to Burp/ZAP
- Map site manually; run common.txt discovery
- Practice one OWASP category (e.g. access control)
Week 7
8h
Credentials and password hygiene
- Study hashing vs encryption; try hashcat on lab hashes only
- Understand why online brute force is dangerous
- Enable MFA on your own critical accounts
- Run password-policy lab playbook ethically
Week 8
8h
Reporting and purple awareness
- Write 2–3 findings from home lab work
- Include evidence, impact, likelihood, remediation
- Re-scan after fixes; note detection opportunities
- Plan next roadmap (eJPT / PNPT / defender path)
Exam / practice tips
- There is no exam — measure success by lab hygiene and written findings.
- If a topic feels shallow, extend the week rather than rushing forward.
- Keep a mistakes log; re-run failed labs after 48 hours.
- Share notes with a study peer for accountability, not for unauthorized testing.