Sign in with Google

Cybersecurity

A comprehensive curriculum covering the full breadth of cybersecurity, from foundational concepts in networking and operating systems through advanced offensive and defensive techniques. Learners progress from understanding core security principles and cryptography to hands-on skills in penetration testing, incident response, cloud security, and compliance. Designed to build a security-first mindset and the practical skills needed to protect modern infrastructure and applications.

5 pillars19 courses160 concepts~320h estimated
Explore with AI:ChatGPTClaudePerplexity

What you'll learn

Security Foundations

  • Networking Essentials for Security(9 concepts)
    • The OSI Reference Model
    • IPv4 Addressing & Subnetting
    • DNS Architecture & Security
    • TCP/IP Protocol Suite
    • IPv6 Fundamentals & Security Implications
    • DHCP & ARP Security Concerns
    • Common Network Protocols
    • Network Segmentation & VLANs
    • Packet Capture & Analysis
  • Security Principles & Concepts(14 concepts)
    • Confidentiality
    • Threat Actor Classification
    • Defense in Depth
    • Risk Identification & Asset Valuation
    • Integrity
    • Common Attack Vectors
    • Least Privilege & Separation of Duties
    • Qualitative & Quantitative Risk Analysis
    • Availability
    • The Cyber Kill Chain
    • Zero Trust Architecture
    • Risk Treatment Strategies
    • Balancing CIA Objectives
    • MITRE ATT&CK Framework
  • Operating System Security(6 concepts)
    • Linux File Permissions & Ownership
    • Windows Authentication & Active Directory
    • Mandatory Access Control: SELinux & AppArmor
    • Group Policy & Security Baselines
    • Linux Hardening & Service Management
    • Windows Event Logging & Auditing
  • Cryptography Fundamentals(9 concepts)
    • Symmetric Encryption Principles
    • Public Key Cryptography Principles
    • Cryptographic Hash Functions
    • Block Cipher Modes of Operation
    • RSA & Elliptic Curve Cryptography
    • Digital Signatures & Non-Repudiation
    • Stream Ciphers
    • Diffie-Hellman Key Exchange
    • Password Hashing & Key Derivation

Network Security

  • Applied Cryptography & PKI(9 concepts)
    • The TLS Handshake & Cipher Suites
    • Certificate Authority Hierarchy & Trust
    • The Quantum Computing Threat
    • TLS Vulnerabilities & Attacks
    • Certificate Lifecycle Management
    • Post-Quantum Cryptographic Algorithms
    • Secure TLS Configuration
    • Certificate Transparency & Pinning
    • Cryptographic Agility & Migration Planning
  • Wireless Network Security(8 concepts)
    • WEP to WPA: A History of Wireless Vulnerabilities
    • Evil Twin & Rogue Access Point Attacks
    • Bluetooth & BLE Security
    • WPA2 Security & the KRACK Attack
    • Deauthentication & RF Attacks
    • IoT Wireless Protocols & Risks
    • WPA3 & Simultaneous Authentication of Equals
    • Enterprise Wireless Security Architecture
  • Network Defense Architecture(9 concepts)
    • Firewall Types & Evolution
    • IDS vs IPS: Detection & Prevention
    • 802.1X & Network Access Control
    • Firewall Rule Design & Management
    • Signature-Based vs Anomaly-Based Detection
    • VPN Technologies: IPsec & SSL/TLS
    • DMZ & Security Zone Architecture
    • Writing & Tuning Detection Rules
    • Zero Trust Network Access

Application Security

  • Web Application Security(9 concepts)
    • Cross-Site Scripting Variants
    • Server-Side Request Forgery
    • Broken Authentication
    • XSS Filter Evasion & Advanced Payloads
    • XML External Entity Injection
    • Broken Access Control & Privilege Escalation
    • Cross-Site Request Forgery
    • Security Misconfiguration
    • JWT Security & Token-Based Authentication
  • Secure Coding Practices(9 concepts)
    • Injection Vulnerabilities
    • Server-Side Input Validation
    • Application Threat Modeling
    • Buffer Overflows & Memory Safety
    • Context-Sensitive Output Encoding
    • Static & Dynamic Analysis Tools
    • Insecure Deserialization & Object Injection
    • Content Security Policy
    • Software Composition Analysis & Supply Chain Security
  • Identity & Access Management(6 concepts)
    • OAuth 2.0 Authorization Framework
    • RBAC, ABAC & Policy-Based Access Control
    • OpenID Connect Authentication
    • Multi-Factor Authentication
    • SAML Federation
    • Privileged Access Management
  • API & Mobile Application Security(6 concepts)
    • API Authentication & Authorization
    • Mobile Application Attack Surface
    • API Rate Limiting & Abuse Prevention
    • Secure Mobile Data Storage
    • GraphQL Security Concerns
    • Mobile Network Security & Certificate Pinning

Offensive Security & Ethical Hacking

  • Penetration Testing Methodology(9 concepts)
    • Open Source Intelligence Gathering
    • Exploitation Frameworks & Tools
    • Privilege Escalation Techniques
    • Network Scanning & Service Enumeration
    • Password Attacks & Credential Exploitation
    • Lateral Movement & Pivoting
    • Vulnerability Assessment & Prioritization
    • Social Engineering & Phishing Assessments
    • Penetration Test Reporting
  • Red Team Operations(9 concepts)
    • Objective-Driven Red Team Planning
    • C2 Frameworks & Architecture
    • Purple Team Exercise Design
    • Threat Actor Emulation
    • Redirector Infrastructure & OPSEC
    • Detection Coverage Assessment
    • Rules of Engagement & Safety Controls
    • Persistence Mechanisms
    • Adversary Emulation Plans
  • Advanced Exploitation Techniques(9 concepts)
    • Stack-Based Buffer Overflow Exploitation
    • Kerberos Attack Techniques
    • Antivirus & EDR Evasion
    • Return-Oriented Programming
    • AD Privilege Escalation & Delegation Abuse
    • Network-Level Evasion
    • Modern Exploit Mitigations
    • Domain Dominance & Persistence
    • Living Off the Land Techniques

Defense, Operations & Compliance

  • Threat Intelligence(6 concepts)
    • Intelligence Collection & Processing
    • Adversary Tracking & Campaign Analysis
    • Intelligence Analysis Methods
    • Threat Hunting with Intelligence
    • Intelligence Products & Dissemination
    • Intelligence Sharing & ISACs
  • Cloud Security Architecture(9 concepts)
    • The Shared Responsibility Model
    • Cloud Network Security & Segmentation
    • Container Security
    • Cloud Identity & Access Management
    • Cloud Data Protection & Encryption
    • Kubernetes Security
    • Cloud Security Posture Management
    • Cloud Logging & Security Monitoring
    • Serverless Security
  • Incident Response & Digital Forensics(9 concepts)
    • The Incident Response Lifecycle
    • Evidence Collection & Chain of Custody
    • Static Malware Analysis
    • Incident Response Playbooks
    • Memory Forensics
    • Dynamic & Behavioral Analysis
    • Tabletop Exercises & Response Testing
    • Timeline Reconstruction & Analysis
    • Indicator Extraction & Threat Sharing
  • Governance, Risk & Compliance(9 concepts)
    • Security Policy Development
    • NIST Cybersecurity Framework
    • Privacy Engineering & Data Protection
    • Risk Communication & Business Alignment
    • ISO 27001 & SOC 2
    • Security Auditing & Assessment
    • Security Awareness & Culture
    • Industry Regulations: PCI DSS, HIPAA & GDPR
    • Security Program Management & Roadmapping
  • Security Operations Center(6 concepts)
    • SIEM Architecture & Data Sources
    • Alert Triage & Investigation Workflows
    • Log Normalization & Enrichment
    • SOC Metrics & Performance Measurement
    • Detection Engineering
    • Security Orchestration, Automation & Response

Explore more roadmaps

Philosophy
A comprehensive journey through the foundations of philosophical thought and rigorous reasoning. This curriculum guides learners from basic critical thinking skills through formal logic, ethics, epistemology, metaphysics, and the great philosophical traditions, culminating in the ability to construct and evaluate complex arguments, navigate ethical dilemmas, and engage meaningfully with the deepest questions about knowledge, reality, and human existence.
~340h
Personal Finance
A comprehensive, 3-pillar curriculum that takes learners from financial confusion to financial confidence. Covers the behavioral psychology of money, budgeting and debt systems, investing fundamentals, portfolio construction, retirement planning, real estate, tax optimization, insurance, estate planning, and the path to financial independence — the essential life skills that schools never taught but everyone needs.
~570h
Natural Science
A working understanding of the natural world — what science is, how matter and energy behave, how life persists and changes, and how Earth and the cosmos fit together. The trunk gives you a single coherent throughline across physics, chemistry, biology, and earth/space science; clusters dive into experimental design, mechanics, thermodynamics, electromagnetism, modern physics, genetics, ecology, and climate.
Psychology
A working understanding of psychology — what the science actually claims about how minds, brains, and behavior fit together. The trunk gives you the orientation a literate professional needs (how psychology knows what it knows, the brain behind behavior, learning, memory, decision-making, emotion, personality, social influence, development, pathology, and what therapy does); clusters dive into research methods, perception, cognition mechanics, social influence tactics, the field guide of disorders, applied behavioral science, and the psychology of everyday life.
Databases
A complete curriculum on databases — from the relational model and ACID through PostgreSQL internals, production operations, modeling patterns, and the modern data ecosystem (NoSQL, distributed SQL, warehouses, streaming, vectors). Built for working engineers who want database knowledge that survives any system they touch.
~360h
Economics
A working understanding of how economies actually behave — how scarcity drives choice, how markets allocate resources (and fail to), how money and policy steer the macroeconomy, and how trade, behavior, and institutions shape long-run prosperity. The trunk gives you the throughline a literate citizen needs; clusters dive into elasticity, market failures, consumer/producer theory, monetary and fiscal policy, trade policy, behavioral finance, and economic history.

Frequently asked questions

How long does the Cybersecurity roadmap take?
About 320 hours of focused learning. At Mochivia's 15-minutes-a-day pace that's roughly 42 months — and going deeper on some days shortens it. The roadmap is self-paced, so there's no deadline.
What does the Cybersecurity roadmap cover?
19 courses across 5 areas — Security Foundations, Network Security, Application Security, Offensive Security & Ethical Hacking, and more — broken into 160 bite-size concepts, each taught as an interactive lesson.
Do I need prior experience to start?
No. The roadmap starts from fundamentals and builds in prerequisite order — each concept unlocks the next, so you're never thrown into material you haven't been prepared for. If you already know the basics, a placement check skips you ahead.
Is the Cybersecurity roadmap free?
You can sign up free and start learning immediately. Mochivia's premium subscription unlocks unlimited daily lessons and the full roadmap depth.

Ready to start learning?

Sign up for free and start progressing through this roadmap with AI-powered lessons.

Get Started Free