Live progress — updated as the path unfolds

Zero to OSCP.
Every step documented.

The path doesn't start at OSCP. It starts at the fundamentals — building the mental model, the Linux fluency, the networking baseline — before touching a single exploit. Four milestones. One goal.

Overall path progress 0% complete

PHASE 0

Fundamentals

PHASE 1

eJPT

PHASE 2

TCM PEH

PHASE 3

HTB WebApp

GOAL

OSCP

Phase 00 — Foundation

TryHackMe &
HackTheBox Fundamentals

[ UPCOMING ]

Before touching real tools, the fundamentals have to be solid. Linux command line, basic networking (TCP/IP, DNS, HTTP), how web applications work, and the mindset shift from user to attacker. TryHackMe's learning paths cover this ground in a structured way. HackTheBox Starting Point machines provide the first live targets. This phase is not skippable — it's the reason OSCP candidates fail when they rush the cert.

TryHackMe HackTheBox Linux Fundamentals Networking Basics Web App Basics Kali Linux
Core tools introduced: nmap · netcat · gobuster · burpsuite (community) · metasploit (basics)

Phase 01 — First Certification

eJPT
eLearnSecurity Junior Penetration Tester

[ UPCOMING ]

The eJPT is the first real exam — a hands-on, practical assessment that validates the fundamentals. No multiple choice. You get a network, you get objectives, you have 72 hours. It's cheap (~$200), beginner-friendly, and creates the first line on the résumé. TCM Security's free PEH course is the recommended prep. Passing eJPT means the foundation is solid enough to move into more aggressive territory.

eJPT Cert TCM Security (free) INE Starter Pass Network Fundamentals Host Discovery Basic Exploitation
Core tools: nmap · metasploit · wireshark · hydra · john the ripper

Phase 02 — Intermediate

TCM Security
Practical Ethical Hacking

[ UPCOMING ]

TCM Security's Practical Ethical Hacking course is where the methodology locks in. Active Directory attacks, privilege escalation, post-exploitation, pivoting, and report writing. Heath Adams (The Cyber Mentor) built this course specifically for people heading to OSCP — it bridges the gap between "I can hack CTF boxes" and "I understand how real internal networks fall." The PNPT certification that comes with it is one of the best practical certs in the field.

PNPT Cert TCM Security Active Directory Privilege Escalation Post-Exploitation Report Writing
Core tools: bloodhound · impacket · crackmapexec · mimikatz · linpeas · winpeas

Phase 03 — Web Application

HackTheBox
Bug Bounty Hunter Certification

[ UPCOMING ]

OSCP now includes web application attacks as a significant component of its exam. The HTB Bug Bounty Hunter certification covers the web attack surface systematically — SQLi, XSS, SSRF, XXE, authentication bypasses, and the methodology real bug bounty hunters use. This phase runs parallel to or after TCM PEH depending on comfort level. The PortSwigger Web Security Academy is the free supplement that goes deeper on individual vulnerability classes.

HTB CBBH PortSwigger Academy SQLi XSS SSRF / XXE Auth Bypasses API Testing
Core tools: burpsuite pro · ffuf · sqlmap · nikto · wfuzz

The Goal

OSCP

[ THE GOAL ]

Offensive Security Certified Professional. The industry benchmark. 24-hour hands-on exam. You either pop the boxes or you don't. No partial credit. No multiple choice. Everything on this path exists to make that 24 hours survivable.

OffSec PEN-200 PWK Course Lab Network 24hr Exam
Prerequisites: Everything above. All of it.

[ Study Bundle ]

The notes from every phase.
All in one guide.

Original study notes · Cheat sheets · Resource list · Lab roadmap

[ Guide ] One-time · $19 · Instant download