kavklaw@llm $ cat cert-roadmap.md
Entry-level through expert certs for offensive and defensive security. What each one covers, what it costs, and how to prep.
Skills matter more than certs. But certs validate what you know, get you past HR filters, and give you structured goals. Here are the certs that actually matter β what they test, what they cost, and how to prepare.
The standard entry-level security cert. Covers network security, threat management, cryptography, identity management, and risk assessment. Required for many DoD positions (8570 compliance). Multiple-choice + performance-based questions.
Covers ethical hacking methodology, footprinting, scanning, enumeration, system hacking, malware, sniffing, social engineering, DoS, session hijacking, web server/app attacks, and cloud security. HR departments love it; technical folks are less impressed β but it opens doors.
Hands-on blue team certification covering SIEM analysis, digital forensics, incident response, threat intelligence, phishing analysis, and network traffic analysis. Practical exam using real tools (Splunk, Wireshark, Volatility).
The cert that gets you hired as a pentester. Covers information gathering, vulnerability scanning, web app attacks, buffer overflows, privesc (Windows & Linux), Active Directory attacks, and client-side attacks. 23:45 hour proctored practical exam β you hack into machines and write a professional report.
HTB's flagship pentest cert. Full penetration testing lifecycle: recon, web exploitation, post-exploitation, lateral movement, Active Directory, and professional reporting. The exam is a multi-day simulated engagement against an enterprise network.
Beginner-friendly practical certification covering networking, web app security, host/network enumeration, and basic exploitation. Great stepping stone to OSCP. Hands-on browser-based exam in a live environment.
Covers OSINT, external/internal network pentest, Active Directory exploitation, and report writing. Unique two-phase exam: 5-day practical pentest followed by a 2-day report, then a 15-minute live debrief with TCM staff simulating a client meeting.
Advanced evasion techniques, custom exploit development, antivirus bypass, advanced Active Directory attacks, process injection, and shellcode development. Assumes OSCP-level proficiency. The exam requires chaining multiple advanced techniques across a simulated enterprise.
Red team operations with Cobalt Strike. Covers OPSEC, C2 infrastructure, lateral movement, domain dominance, data exfiltration, and Kerberos abuse (Golden/Silver tickets, delegation attacks). If you want to do red team work, this is the cert to get.
Deep Active Directory exploitation: cross-forest attacks, trust abuse, ADCS exploitation, constrained/unconstrained delegation, LAPS abuse, gMSA attacks, and advanced Kerberos techniques. Covers multi-domain and multi-forest environments.
Advanced web application security: white-box source code review, authentication bypass, deserialization attacks, type juggling, SSTI, advanced SQL injection, and custom exploit scripting. You get the source code and must find and exploit vulnerabilities in complex web apps.
Threat hunting, advanced SIEM operations, malware analysis, memory forensics, incident management, and vulnerability management. Builds on BTL1 with deeper technical analysis and harder scenarios.
Incident handling, attack techniques (from both attacker and defender perspectives), network forensics, password attacks, web app attacks, and evasion techniques. Based on SANS SEC504 β expensive but genuinely excellent training.
Windows digital forensics: browser forensics, email analysis, Windows artifact examination (registry, event logs, prefetch, shellbags, NTFS), USB forensics, cloud storage artifacts, and timeline analysis. The cert to get if you're doing Windows forensics.
Threat detection, security monitoring, vulnerability management, incident response, and compliance. A solid step up from Security+ before jumping into GCIH or BTL2. Performance-based questions test real analytical skills.
1. CompTIA Security+ β 2. eJPT β 3. OSCP or CPTS β 4. CRTO β 5. OSEP or CRTE
1. CompTIA Security+ β 2. BTL1 β 3. CySA+ β 4. GCIH β 5. BTL2 or GCFE
1. eJPT β 2. OSCP or CPTS β 3. OSWE β 4. BSCP (Burp Suite Certified Practitioner)
π‘ Pro tip: Certs prove knowledge; practice builds skill. Use the CTF writeups and learning path to get hands-on experience alongside your cert studies. The people who pass these exams on the first try are the ones who've spent hundreds of hours in labs.