Cyberlian Study Guide
Complete curriculum roadmap — 60 lessons from foundations to expert
1 Foundations
Core concepts, Linux basics, CIA triad, ethical hacking intro.
- D1Introduction to Cybersecurity
- D2Linux Setup & Command Line Basics
- D6Cybersecurity Fundamentals (CIA, AAA)
- D7Introduction to Ethical Hacking
2 Networking & Linux
OSI/TCP‑IP, protocols, Python, OSINT, advanced Linux & Python.
- D3Networking Fundamentals (OSI & TCP/IP)
- D4Network Protocols (HTTP, DNS, DHCP, ARP)
- D5Python for Cybersecurity (Basics)
- D8Reconnaissance & OSINT
- D31Advanced Linux for Security
- D33Advanced Python for Security (Scapy, Requests)
3 Web Security Basics
OWASP Top 10, Burp Suite, web fundamentals, cookies, sessions.
- D9Network Scanning with Nmap
- D10Web Application Basics & OWASP Top 10
- D11Introduction to Burp Suite
- D12Web Fundamentals: Cookies, Sessions, Crypto & Headers
4 Web Attacks Deep Dive
SQLi, XSS, CSRF, IDOR, JWT, OAuth, SSRF, XXE, SSTI, LFI/RFI, and advanced web attacks.
- D13Authentication Bypass & Session Hijacking
- D14IDOR (Insecure Direct Object References)
- D15JWT Attacks
- D16OAuth Misconfiguration & Open Redirect
- D17SQL Injection (SQLi) – Basics
- D18SQL Injection (SQLi) – Advanced
- D19XSS – Reflected & Stored
- D20XSS – DOM‑Based
- D21Cross‑Site Request Forgery (CSRF)
- D22Command Injection
- D23File Upload Vulnerabilities
- D24SSRF (Server‑Side Request Forgery)
- D25XXE (XML External Entity) Injection
- D26Insecure Deserialization
- D27SSTI (Server‑Side Template Injection)
- D28LFI & RFI (Local/Remote File Inclusion)
- D40Advanced Web Fuzzing (FFUF, Wordlists)
- D41GraphQL & NoSQL Injection
- D42HTTP Request Smuggling
- D43Race Conditions & Business Logic Flaws
- D44Insecure Deserialization – Advanced
- D45SSTI – Advanced
5 System & Network Exploitation
Privilege escalation, lateral movement, password cracking, AD, wireless.
- D29Wireless Attacks (Wi‑Fi Basics)
- D32Advanced Networking (VLAN, Routing, IPv6)
- D34Windows Security Fundamentals
- D35Privilege Escalation – Linux
- D36Privilege Escalation – Windows
- D37Lateral Movement & Persistence
- D38Password Attacks & Cracking
- D39Active Directory Attacks (Kerberoasting, BloodHound)
- D48Network Exploitation (ARP, DNS, VLAN Hopping)
- D49Wireless Advanced (WPA/WPA2, Evil Twin)
6 Advanced Web & API Security
API security, cloud (AWS/Azure/GCP), containers, CI/CD pipelines.
- D30API Security Vulnerabilities
- D52Cloud Security – AWS/Azure/GCP
- D53Container & Kubernetes Security
- D54CI/CD Pipeline Security
- D55API Security – Advanced (GraphQL, gRPC)
7 Mobile & IoT
Android, iOS, and IoT security assessments.
- D50Mobile Security – Android
- D51Mobile Security – iOS
8 Malware & Reverse Engineering
Advanced malware analysis, reverse engineering with Ghidra, IDA, Radare2.
- D56Advanced Malware Analysis
- D57Reverse Engineering (Ghidra, IDA, Radare2)
9 Exploit Development
Buffer overflows, ROP, Windows exploitation, advanced network exploitation.
- D46Exploit Dev Basics (Buffer Overflow, ROP)
- D47Windows Exploitation (SEH, DEP, ASLR Bypass)
10 Threat Hunting & Final Simulation
Threat hunting, SIEM/log analysis, full Red Team vs Blue Team simulation.
- D58Threat Hunting & Detection Engineering
- D59SIEM & Log Analysis (Elastic Stack, Splunk)
- D60Red Team vs Blue Team (Full Attack Simulation)
Study Tips
Pomodoro
25 min study / 5 min break. Retain more, burn out less.
Hands‑On
Code along, run tools, test exploits – practical learning.
AI Mentor
Ask questions and get step‑by‑step help from Cyberlian AI.
Cheat Sheets
Summarise key commands and techniques after each lesson.
Community
Discuss with other learners on Discord and Telegram.
Consistency
2 lessons per day = complete all in 30 days.
Recommended Resources
The Web Application Hacker's Handbook
Penetration Testing: A Hands‑On Introduction
OWASP Top 10
HackTheBox / TryHackMe
Recommended Schedule
Week 1
Foundations & Linux
D1–D8
Week 2
Networking & Python
D9–D16
Week 3
Web Attacks (Basics)
D17–D24
Week 4
Web Attacks (Advanced)
D25–D30
Week 5
System & Network
D31–D39
Week 6
Advanced & Cloud
D40–D49
Week 7
Mobile, Malware, RE
D50–D57
Week 8
Threat Hunting & Simulation
D58–D60 + Review