Cybersecurity
A comprehensive curriculum covering the full breadth of cybersecurity, from foundational concepts in networking and operating systems through advanced offensive and defensive techniques. Learners progress from understanding core security principles and cryptography to hands-on skills in penetration testing, incident response, cloud security, and compliance. Designed to build a security-first mindset and the practical skills needed to protect modern infrastructure and applications.
5 pillars19 courses160 concepts~320h estimated
What you'll learn
Security Foundations
Networking Essentials for Security(9 concepts)
- The OSI Reference Model
- IPv4 Addressing & Subnetting
- DNS Architecture & Security
- TCP/IP Protocol Suite
- IPv6 Fundamentals & Security Implications
- DHCP & ARP Security Concerns
- Common Network Protocols
- Network Segmentation & VLANs
- Packet Capture & Analysis
Security Principles & Concepts(14 concepts)
- Confidentiality
- Threat Actor Classification
- Defense in Depth
- Risk Identification & Asset Valuation
- Integrity
- Common Attack Vectors
- Least Privilege & Separation of Duties
- Qualitative & Quantitative Risk Analysis
- Availability
- The Cyber Kill Chain
- Zero Trust Architecture
- Risk Treatment Strategies
- Balancing CIA Objectives
- MITRE ATT&CK Framework
Operating System Security(6 concepts)
- Linux File Permissions & Ownership
- Windows Authentication & Active Directory
- Mandatory Access Control: SELinux & AppArmor
- Group Policy & Security Baselines
- Linux Hardening & Service Management
- Windows Event Logging & Auditing
Cryptography Fundamentals(9 concepts)
- Symmetric Encryption Principles
- Public Key Cryptography Principles
- Cryptographic Hash Functions
- Block Cipher Modes of Operation
- RSA & Elliptic Curve Cryptography
- Digital Signatures & Non-Repudiation
- Stream Ciphers
- Diffie-Hellman Key Exchange
- Password Hashing & Key Derivation
Network Security
Applied Cryptography & PKI(9 concepts)
- The TLS Handshake & Cipher Suites
- Certificate Authority Hierarchy & Trust
- The Quantum Computing Threat
- TLS Vulnerabilities & Attacks
- Certificate Lifecycle Management
- Post-Quantum Cryptographic Algorithms
- Secure TLS Configuration
- Certificate Transparency & Pinning
- Cryptographic Agility & Migration Planning
Wireless Network Security(8 concepts)
- WEP to WPA: A History of Wireless Vulnerabilities
- Evil Twin & Rogue Access Point Attacks
- Bluetooth & BLE Security
- WPA2 Security & the KRACK Attack
- Deauthentication & RF Attacks
- IoT Wireless Protocols & Risks
- WPA3 & Simultaneous Authentication of Equals
- Enterprise Wireless Security Architecture
Network Defense Architecture(9 concepts)
- Firewall Types & Evolution
- IDS vs IPS: Detection & Prevention
- 802.1X & Network Access Control
- Firewall Rule Design & Management
- Signature-Based vs Anomaly-Based Detection
- VPN Technologies: IPsec & SSL/TLS
- DMZ & Security Zone Architecture
- Writing & Tuning Detection Rules
- Zero Trust Network Access
Application Security
Web Application Security(9 concepts)
- Cross-Site Scripting Variants
- Server-Side Request Forgery
- Broken Authentication
- XSS Filter Evasion & Advanced Payloads
- XML External Entity Injection
- Broken Access Control & Privilege Escalation
- Cross-Site Request Forgery
- Security Misconfiguration
- JWT Security & Token-Based Authentication
Secure Coding Practices(9 concepts)
- Injection Vulnerabilities
- Server-Side Input Validation
- Application Threat Modeling
- Buffer Overflows & Memory Safety
- Context-Sensitive Output Encoding
- Static & Dynamic Analysis Tools
- Insecure Deserialization & Object Injection
- Content Security Policy
- Software Composition Analysis & Supply Chain Security
Identity & Access Management(6 concepts)
- OAuth 2.0 Authorization Framework
- RBAC, ABAC & Policy-Based Access Control
- OpenID Connect Authentication
- Multi-Factor Authentication
- SAML Federation
- Privileged Access Management
API & Mobile Application Security(6 concepts)
- API Authentication & Authorization
- Mobile Application Attack Surface
- API Rate Limiting & Abuse Prevention
- Secure Mobile Data Storage
- GraphQL Security Concerns
- Mobile Network Security & Certificate Pinning
Offensive Security & Ethical Hacking
Penetration Testing Methodology(9 concepts)
- Open Source Intelligence Gathering
- Exploitation Frameworks & Tools
- Privilege Escalation Techniques
- Network Scanning & Service Enumeration
- Password Attacks & Credential Exploitation
- Lateral Movement & Pivoting
- Vulnerability Assessment & Prioritization
- Social Engineering & Phishing Assessments
- Penetration Test Reporting
Red Team Operations(9 concepts)
- Objective-Driven Red Team Planning
- C2 Frameworks & Architecture
- Purple Team Exercise Design
- Threat Actor Emulation
- Redirector Infrastructure & OPSEC
- Detection Coverage Assessment
- Rules of Engagement & Safety Controls
- Persistence Mechanisms
- Adversary Emulation Plans
Advanced Exploitation Techniques(9 concepts)
- Stack-Based Buffer Overflow Exploitation
- Kerberos Attack Techniques
- Antivirus & EDR Evasion
- Return-Oriented Programming
- AD Privilege Escalation & Delegation Abuse
- Network-Level Evasion
- Modern Exploit Mitigations
- Domain Dominance & Persistence
- Living Off the Land Techniques
Defense, Operations & Compliance
Threat Intelligence(6 concepts)
- Intelligence Collection & Processing
- Adversary Tracking & Campaign Analysis
- Intelligence Analysis Methods
- Threat Hunting with Intelligence
- Intelligence Products & Dissemination
- Intelligence Sharing & ISACs
Cloud Security Architecture(9 concepts)
- The Shared Responsibility Model
- Cloud Network Security & Segmentation
- Container Security
- Cloud Identity & Access Management
- Cloud Data Protection & Encryption
- Kubernetes Security
- Cloud Security Posture Management
- Cloud Logging & Security Monitoring
- Serverless Security
Incident Response & Digital Forensics(9 concepts)
- The Incident Response Lifecycle
- Evidence Collection & Chain of Custody
- Static Malware Analysis
- Incident Response Playbooks
- Memory Forensics
- Dynamic & Behavioral Analysis
- Tabletop Exercises & Response Testing
- Timeline Reconstruction & Analysis
- Indicator Extraction & Threat Sharing
Governance, Risk & Compliance(9 concepts)
- Security Policy Development
- NIST Cybersecurity Framework
- Privacy Engineering & Data Protection
- Risk Communication & Business Alignment
- ISO 27001 & SOC 2
- Security Auditing & Assessment
- Security Awareness & Culture
- Industry Regulations: PCI DSS, HIPAA & GDPR
- Security Program Management & Roadmapping
Security Operations Center(6 concepts)
- SIEM Architecture & Data Sources
- Alert Triage & Investigation Workflows
- Log Normalization & Enrichment
- SOC Metrics & Performance Measurement
- Detection Engineering
- Security Orchestration, Automation & Response
Explore more roadmaps
Philosophy
A comprehensive journey through the foundations of philosophical thought and rigorous reasoning. This curriculum guides learners from basic critical thinking skills through formal logic, ethics, epistemology, metaphysics, and the great philosophical traditions, culminating in the ability to construct and evaluate complex arguments, navigate ethical dilemmas, and engage meaningfully with the deepest questions about knowledge, reality, and human existence.
~340h
Personal Finance
A comprehensive, 3-pillar curriculum that takes learners from financial confusion to financial confidence. Covers the behavioral psychology of money, budgeting and debt systems, investing fundamentals, portfolio construction, retirement planning, real estate, tax optimization, insurance, estate planning, and the path to financial independence — the essential life skills that schools never taught but everyone needs.
~570h
Natural Science
A working understanding of the natural world — what science is, how matter and energy behave, how life persists and changes, and how Earth and the cosmos fit together. The trunk gives you a single coherent throughline across physics, chemistry, biology, and earth/space science; clusters dive into experimental design, mechanics, thermodynamics, electromagnetism, modern physics, genetics, ecology, and climate.
Psychology
A working understanding of psychology — what the science actually claims about how minds, brains, and behavior fit together. The trunk gives you the orientation a literate professional needs (how psychology knows what it knows, the brain behind behavior, learning, memory, decision-making, emotion, personality, social influence, development, pathology, and what therapy does); clusters dive into research methods, perception, cognition mechanics, social influence tactics, the field guide of disorders, applied behavioral science, and the psychology of everyday life.
Databases
A complete curriculum on databases — from the relational model and ACID through PostgreSQL internals, production operations, modeling patterns, and the modern data ecosystem (NoSQL, distributed SQL, warehouses, streaming, vectors). Built for working engineers who want database knowledge that survives any system they touch.
~360h
Economics
A working understanding of how economies actually behave — how scarcity drives choice, how markets allocate resources (and fail to), how money and policy steer the macroeconomy, and how trade, behavior, and institutions shape long-run prosperity. The trunk gives you the throughline a literate citizen needs; clusters dive into elasticity, market failures, consumer/producer theory, monetary and fiscal policy, trade policy, behavioral finance, and economic history.
Frequently asked questions
How long does the Cybersecurity roadmap take?
About 320 hours of focused learning. At Mochivia's 15-minutes-a-day pace that's roughly 42 months — and going deeper on some days shortens it. The roadmap is self-paced, so there's no deadline.
What does the Cybersecurity roadmap cover?
19 courses across 5 areas — Security Foundations, Network Security, Application Security, Offensive Security & Ethical Hacking, and more — broken into 160 bite-size concepts, each taught as an interactive lesson.
Do I need prior experience to start?
No. The roadmap starts from fundamentals and builds in prerequisite order — each concept unlocks the next, so you're never thrown into material you haven't been prepared for. If you already know the basics, a placement check skips you ahead.
Is the Cybersecurity roadmap free?
You can sign up free and start learning immediately. Mochivia's premium subscription unlocks unlimited daily lessons and the full roadmap depth.
Ready to start learning?
Sign up for free and start progressing through this roadmap with AI-powered lessons.
Get Started Free