HTB
HACK THE BOX

PENTESTING ROADMAP

FOR THE ABSOLUTE BEGINNER // ZERO EXPERIENCE REQUIRED

01
Foundation
START HERE — HTB ACADEMY
Before touching a single machine, build your foundation. HTB Academy is structured, free-tier friendly, and purpose-built for this. Your friend should spend 2–4 weeks here minimum before anything else.
Learning Path: Pre-Security
FREE · Best first step
Learning Path: SOC Analyst
TIER I–II · Blue team base
Learning Path: Penetration Tester
VIP+ · Ultimate goal
// PRO TIP
The Pre-Security path is completely free and covers networking, web basics, and Linux. Tell your friend to do this entire path first — no skipping.
02
Linux
LEARN THE OS // LINUX FUNDAMENTALS
Every pentest lives on Linux. Your friend needs to get comfortable in the terminal before they can do anything meaningful. These modules build real command-line fluency.
Linux Fundamentals
FREE · Essential
Introduction to Bash Scripting
TIER I · Automation basics
File Transfers
TIER I · Core skill
// PRO TIP
Install Kali Linux or Parrot OS in VirtualBox and follow along in a real terminal while doing Academy. Reading ≠ doing.
03
Networking
UNDERSTAND THE NETWORK
Pentesting is fundamentally about understanding how networks and protocols work — and then exploiting the gaps. These modules give the mental model needed to think like an attacker.
Networking Fundamentals
FREE · IP, TCP/UDP, DNS
Intro to Network Traffic Analysis
TIER II · Wireshark basics
Nmap
TIER I · #1 recon tool
// PRO TIP
Nmap is the first tool every pentester learns. Tell your friend to run it against everything in their lab until it becomes second nature.
04
Web Security
WEB APP HACKING BASICS
The majority of real-world pentesting involves web applications. These modules introduce the OWASP Top 10 vulnerabilities and the tools used to find them. This is where it gets fun.
Web Requests
FREE · HTTP/cURL basics
Introduction to Web Applications
FREE · How the web works
SQL Injection Fundamentals
TIER II · Classic vuln
Cross-Site Scripting (XSS)
TIER II · OWASP Top 10
Using Web Proxies (Burp Suite)
TIER II · Essential tool
File Inclusion
TIER II · LFI/RFI attacks
05
Active Exploitation
EXPLOITATION & POST-EXPLOITATION
Now things get serious. These modules cover the full attack chain — finding vulnerabilities, exploiting them, and escalating privileges once you're in. Metasploit is your Swiss army knife here.
Metasploit Framework
TIER II · Core exploit tool
Linux Privilege Escalation
TIER III · Must-know
Windows Privilege Escalation
TIER III · Must-know
Password Attacks
TIER III · Cracking & spraying
Active Directory Enumeration & Attacks
TIER IV · Enterprise gold
// PRO TIP
Linux and Windows PrivEsc are tested on every intermediate+ machine. Your friend should practice these until the methodology is muscle memory.
06
Machines & CTF
HIT THE MACHINES // PRACTICE FOR REAL
After Phase 3–5, start doing retired machines with writeup access. This is where the real learning happens — putting it all together. Starting Point machines are designed exactly for this transition.
Starting Point Tier 0
FREE · Guided, very easy
Starting Point Tier 1
FREE · Easy machines
Starting Point Tier 2
VIP · Medium difficulty
Retired Easy Machines
VIP · Use writeups
// THE GOLDEN RULE
Stuck for 30+ mins? Look at a writeup. There's no shame in it. The goal is learning the methodology, not suffering alone. Read the writeup, understand every step, then try the next machine without it.
Meow
Linux
VERY EASY
Fawn
Linux
VERY EASY
Dancing
Windows
VERY EASY
Redeemer
Linux
VERY EASY
Lame
Linux
EASY
Jerry
Windows
EASY
Blue
Windows
EASY
Nibbles
Linux
EASY