kavklaw@llm ~ /certifications

kavklaw@llm $ cat cert-roadmap.md

Certification Roadmap

Entry-level through expert certs for offensive and defensive security. What each one covers, what it costs, and how to prep.

Skills matter more than certs. But certs validate what you know, get you past HR filters, and give you structured goals. Here are the certs that actually matter β€” what they test, what they cost, and how to prepare.

Entry Level

🟒 Foundation Certifications

CompTIA Security+

CompTIA Β· SY0-701

The standard entry-level security cert. Covers network security, threat management, cryptography, identity management, and risk assessment. Required for many DoD positions (8570 compliance). Multiple-choice + performance-based questions.

πŸ’° ~$404 exam πŸ“Š Beginner-Intermediate πŸ“ 90 min, ~90 questions
Preparation: Professor Messer (free videos), Jason Dion practice exams, CompTIA CertMaster. On our site: Networking & Nmap guides cover scanning fundamentals, cheat sheets for quick reference.

CEH β€” Certified Ethical Hacker

EC-Council Β· v13

Covers ethical hacking methodology, footprinting, scanning, enumeration, system hacking, malware, sniffing, social engineering, DoS, session hijacking, web server/app attacks, and cloud security. HR departments love it; technical folks are less impressed β€” but it opens doors.

πŸ’° ~$1,199 (exam only) / $2,199 (with training) πŸ“Š Beginner-Intermediate πŸ“ 4 hrs, 125 MCQ + practical
Preparation: EC-Council iLabs, Matt Walker's "CEH All-in-One" book, TryHackMe learning paths. On our site: CTF writeups demonstrate real attack methodology that maps to CEH domains.

BTL1 β€” Blue Team Level 1

Security Blue Team

Hands-on blue team certification covering SIEM analysis, digital forensics, incident response, threat intelligence, phishing analysis, and network traffic analysis. Practical exam using real tools (Splunk, Wireshark, Volatility).

πŸ’° ~$499 (training + exam) πŸ“Š Beginner-Intermediate πŸ–₯️ 24-hr practical exam
Preparation: Security Blue Team's own training, LetsDefend, CyberDefenders. On our site: Wireshark & log analysis guides, incident response cheat sheet.
β–Ό β–Ό β–Ό
Intermediate

πŸ”΅ Offensive Security Certifications

OSCP β€” Offensive Security Certified Professional

OffSec Β· PEN-200

The cert that gets you hired as a pentester. Covers information gathering, vulnerability scanning, web app attacks, buffer overflows, privesc (Windows & Linux), Active Directory attacks, and client-side attacks. 23:45 hour proctored practical exam β€” you hack into machines and write a professional report.

πŸ’° $1,749 (90-day lab + exam) πŸ“Š Intermediate-Hard πŸ–₯️ 23:45 hr practical + report
Preparation: TJ Null's OSCP-like HTB list, Proving Grounds Practice, OffSec PEN-200 labs (75+ machines). On our site: HTB writeups (Flustered, Sink) cover real OSCP-style attack chains. Privilege escalation and reverse shell cheat sheets are essential study material.

CPTS β€” Certified Penetration Testing Specialist

Hack The Box

HTB's flagship pentest cert. Full penetration testing lifecycle: recon, web exploitation, post-exploitation, lateral movement, Active Directory, and professional reporting. The exam is a multi-day simulated engagement against an enterprise network.

πŸ’° ~$490 (with HTB Academy subscription) πŸ“Š Intermediate-Hard πŸ–₯️ 10-day practical + report
Preparation: HTB Academy "Penetration Tester" job-role path (28 modules), HTB Prolabs (Dante, Offshore). On our site: Every CTF writeup follows the same methodology CPTS tests. Learning path structures your study.

eJPT β€” eLearnSecurity Junior Penetration Tester

INE Security

Beginner-friendly practical certification covering networking, web app security, host/network enumeration, and basic exploitation. Great stepping stone to OSCP. Hands-on browser-based exam in a live environment.

πŸ’° ~$249 (exam) / $749 (with training) πŸ“Š Beginner-Intermediate πŸ–₯️ 48-hr practical (browser-based)
Preparation: INE's free Starter Pass, TryHackMe "Jr Penetration Tester" path, basic HTB machines. On our site: Nmap, Burp Suite, and Metasploit guides cover the core tools tested.

PNPT β€” Practical Network Penetration Tester

TCM Security

Covers OSINT, external/internal network pentest, Active Directory exploitation, and report writing. Unique two-phase exam: 5-day practical pentest followed by a 2-day report, then a 15-minute live debrief with TCM staff simulating a client meeting.

πŸ’° ~$399 (exam) / $999 (courses + exam) πŸ“Š Intermediate πŸ–₯️ 5-day practical + report + debrief
Preparation: TCM Academy courses (PEH, Linux Privesc, AD), Heath Adams' YouTube content. On our site: Hercules writeup covers AD/LDAP/Kerberos attack methodology. Active Directory guide for enumeration techniques.
β–Ό β–Ό β–Ό
Advanced

πŸ”΄ Expert-Level Certifications

OSEP β€” Offensive Security Experienced Penetration Tester

OffSec Β· PEN-300

Advanced evasion techniques, custom exploit development, antivirus bypass, advanced Active Directory attacks, process injection, and shellcode development. Assumes OSCP-level proficiency. The exam requires chaining multiple advanced techniques across a simulated enterprise.

πŸ’° $1,749 (with lab access) πŸ“Š Hard-Expert πŸ–₯️ 47:45 hr practical + report
Preparation: OSCP first, then PEN-300 course material, Sektor7 malware dev courses, RastaMouse's CRTO. On our site: Sink's HTTP smuggling and Hercules' LDAP injection demonstrate the kind of creative exploitation OSEP demands.

CRTO β€” Certified Red Team Operator

Zero-Point Security (RastaMouse)

Red team operations with Cobalt Strike. Covers OPSEC, C2 infrastructure, lateral movement, domain dominance, data exfiltration, and Kerberos abuse (Golden/Silver tickets, delegation attacks). If you want to do red team work, this is the cert to get.

πŸ’° ~$505 (course + exam) πŸ“Š Hard πŸ–₯️ 48-hr practical (Snap Labs)
Preparation: OSCP or equivalent first, Red Team Ops course by RastaMouse, HTB Prolabs (RastaLabs, Cybernetics). On our site: Hercules' Kerberos delegation path directly maps to CRTO exam objectives.

CRTE β€” Certified Red Team Expert

Altered Security (Nikhil Mittal)

Deep Active Directory exploitation: cross-forest attacks, trust abuse, ADCS exploitation, constrained/unconstrained delegation, LAPS abuse, gMSA attacks, and advanced Kerberos techniques. Covers multi-domain and multi-forest environments.

πŸ’° ~$299 (course + exam) πŸ“Š Hard-Expert πŸ–₯️ 48-hr practical
Preparation: CRTO or OSCP with AD experience, Altered Security's Windows Red Team labs, SpecterOps BloodHound documentation. On our site: Hercules writeup covers LDAP injection and Kerberos delegation β€” core CRTE topics.

OSWE β€” Offensive Security Web Expert

OffSec Β· WEB-300

Advanced web application security: white-box source code review, authentication bypass, deserialization attacks, type juggling, SSTI, advanced SQL injection, and custom exploit scripting. You get the source code and must find and exploit vulnerabilities in complex web apps.

πŸ’° $1,749 (with lab access) πŸ“Š Hard-Expert πŸ–₯️ 47:45 hr practical + report
Preparation: PortSwigger Web Security Academy (free), WEB-300 course, code review practice on GitHub projects. On our site: Flustered's SSTI exploitation and Burp Suite & SQLMap guides build the web exploitation muscle OSWE demands.
β–Ό β–Ό β–Ό
Blue Team

πŸ›‘οΈ Defensive Security Certifications

BTL2 β€” Blue Team Level 2

Security Blue Team

Threat hunting, advanced SIEM operations, malware analysis, memory forensics, incident management, and vulnerability management. Builds on BTL1 with deeper technical analysis and harder scenarios.

πŸ’° ~$799 (training + exam) πŸ“Š Intermediate-Hard πŸ–₯️ Multi-day practical
Preparation: BTL1 first, CyberDefenders challenges, SANS webcasts, BlueTeamLabs Online. On our site: Wireshark, log analysis, and forensics guides build the analytical skills needed.

GCIH β€” GIAC Certified Incident Handler

SANS / GIAC Β· SEC504

Incident handling, attack techniques (from both attacker and defender perspectives), network forensics, password attacks, web app attacks, and evasion techniques. Based on SANS SEC504 β€” expensive but genuinely excellent training.

πŸ’° ~$2,499 (exam) / $8,525+ (with SANS training) πŸ“Š Intermediate-Hard πŸ“ 4-5 hrs, 106 questions (open book)
Preparation: SANS SEC504 course (expensive but excellent), practice with SANS CyberRanges, index your course materials. On our site: CTF writeups demonstrate the attack techniques GCIH tests you on from the defender's perspective.

GCFE β€” GIAC Certified Forensic Examiner

SANS / GIAC Β· FOR500

Windows digital forensics: browser forensics, email analysis, Windows artifact examination (registry, event logs, prefetch, shellbags, NTFS), USB forensics, cloud storage artifacts, and timeline analysis. The cert to get if you're doing Windows forensics.

πŸ’° ~$2,499 (exam) / $8,525+ (with SANS training) πŸ“Š Intermediate-Hard πŸ“ 4-5 hrs, 115 questions (open book)
Preparation: SANS FOR500 course, Eric Zimmerman's free forensic tools, DFIR practice images from AboutDFIR. On our site: Forensics and log analysis guides cover foundational investigation techniques.

CySA+ β€” CompTIA Cybersecurity Analyst

CompTIA Β· CS0-003

Threat detection, security monitoring, vulnerability management, incident response, and compliance. A solid step up from Security+ before jumping into GCIH or BTL2. Performance-based questions test real analytical skills.

πŸ’° ~$404 exam πŸ“Š Intermediate πŸ“ 165 min, ~85 questions
Preparation: Security+ first, Jason Dion's CySA+ course, CompTIA CertMaster Labs. On our site: Incident response & threat hunting cheat sheets, SIEM and log analysis guides.

πŸ—ΊοΈ Recommended Certification Paths

πŸ—‘οΈ Offensive / Red Team Path

1. CompTIA Security+ β†’ 2. eJPT β†’ 3. OSCP or CPTS β†’ 4. CRTO β†’ 5. OSEP or CRTE

πŸ›‘οΈ Defensive / Blue Team Path

1. CompTIA Security+ β†’ 2. BTL1 β†’ 3. CySA+ β†’ 4. GCIH β†’ 5. BTL2 or GCFE

🌐 Web Application Specialist Path

1. eJPT β†’ 2. OSCP or CPTS β†’ 3. OSWE β†’ 4. BSCP (Burp Suite Certified Practitioner)

πŸ’‘ Pro tip: Certs prove knowledge; practice builds skill. Use the CTF writeups and learning path to get hands-on experience alongside your cert studies. The people who pass these exams on the first try are the ones who've spent hundreds of hours in labs.