General Security
A List of Online IT and Security Training Resources
There is a TON of practical, online training and learning resources available. See for yourself below…
This awesome list of free training is also definitely worth checking out!
General Security
- Cybrary [FREE/PAID]
- Coursera [FREE/PAID]
- Khan Academy - Encryption [FREE]
- edX [FREE/PAID]
- Udemy [FREE/PAID]
- SANS Cyber Aces [FREE]
- Open Security Training [FREE]
- Future Learn - Introduction to Cyber Security [FREE]
- Phrack [FREE]
- Cal Poly Security Training Material [FREE]
- MIT Open Courseware - Network and Computer Security [FREE]
- DoD Cyber Exchange Public [FREE]
- Springboard [FREE]
- Immersive Labs - Students’ Digital Cyber Academy [FREE]
- Federal Virtual Training Environment (FedVTE) [FREE (for government personnel and veterans)
- NICCS [FREE]
- Pluralsight [PAID]
- Lynda [PAID] Other options here
- Certifications. In my experience - recruiters, hiring managers, other infosec pros (to some degree) and the infosec industry at large love certifications. Take for example, the CompTIA Security+ certification. The Securtiy+ is a great entry-level cert which can not only demonstrate that you are serious about getting into infosec but it also is a great introduction to a lot of the foundational infosec concepts you will need throughout your career. I think the return on investment in getting this cert is well worth it (I in-fact started out my infosec career with this cert so I can attest to its worthiness to some degree.) As you learn more (and with time/budget willing), begin to take a look at some other certification options as well.
Certifications
Certs. Love ‘em or hate ‘em, they can be helpful.
- CompTIA Security+ - Entry level certification but provides invaluable entry-level knowledge to the field of infosec.
- SANS - Fantastic cybersecurity training but very expensive.
- OSCP - Practical penetration testing training (and highly regarded certification in the industry).
- CISSP - Need to improve resume? This cert can often help.
- eLearnSecurity - Practical, hands-on infosec training. They have a great catalog of courses.
Web Application Security
- Web Security Academy [FREE]
- Intigrity Hackademy [FREE]
- Bugcrowd University [FREE]
- OWASP Education/Free Training [FREE]
- Google Hacking Databse [FREE]
Penetration Testing/Exploit Development
- Kali Linux Revealed [FREE]
- Holiday Hack Challenge [FREE]
- Hack The Box [FREE/PAID]
- IppSec - YouTube [FREE]
- Metasploit Unleashed [FREE]
- Cobalt Strike Training [FREE]
- CTF Time [FREE]
- VulnHub [FREE]
- Hackvent [FREE]
- Corelan Team [FREE]
- OverTheWire [FREE]
- PentesterLab [FREE/PAID]
- GreyCampus Ethical Hacking [FREE]
- Hack.me [FREE]
- Hack This Site [FREE]
- exploit.education [FREE]
- NYU OSIRIS Lab Recruit Challenges [FREE]
- Pentester Academy [PAID]
- Defend the Web [FREE]
- CTFlearn [FREE]
- Hacking-Lab [FREE]
- Game of Hacks [FREE]
- Root Me [FREE]
- XSS game [FREE]
- pwnable.kr [FREE]
- pwnable.tw [FREE]
- Crackmes [FREE]
- Google Gruyere [FREE]
Incident Response (Forensics, RE, Malware Analysis, etc…)
- Android App Reverse Engineering 101 [FREE]
- Vitali Kremez - Let’s Learn [FREE]
- Malware Unicorn Workshops [FREE]
- Azeria Labs [FREE]
- FLARE On Challenge [FREE]
- Reverse Engineering Course [FREE]
- Malware-Traffic-Analysis.net [FREE]
- DFIR Training [FREE]
- Special Mention: Awesome Malware Analysis [FREE]
Programming
- Rubyfu [FREE]
- codeacademy [FREE]
- Free Programming Books - Github [FREE]
- Project Euler [FREE]
- Eloquent JavaScript [FREE]
- The Python Tutorial [FREE]
- w3schools [FREE]
- Invent with Python [FREE/PAID]
- TwilioQuest [FREE]
Cloud
- A Cloud Guru [PAID]
- Linux Academy [PAID]
Cloud
The cloud is just someone else’s computer right? Well if you’re putting stuff on someone else’s computer you should probably learn to secure it even better.
- AWS - Heard of the cloud? AWS can give you your own chunk of the cloud to play in.
- Azure - Microsoft is also in the cloud game.
- Google Cloud - Not to be outdone, Google. Also in the cloud.
Networking
- NDG Online Courses & Labs [FREE/PAID]
Industrial Control Systems (ICS)
Vendor-Specific Training
- Getting Git Right [FREE]
- Splunk Training [FREE/PAID]