Overview
This roadmap supports the eJPT v2 course with hands-on labs on TryHackMe and PortSwigger, organized into 4 sections that follow the structure of the course: information gathering and scanning, auditing and monitoring, host and network attacks, and web application attacks.
This roadmap was prepared by Amr Abdel Hamide for Netriders Academy. Pair it with my eJPTv2 Study Notes for the theory behind each topic. Every link opens the lab directly.
| Total labs | 125 |
| TryHackMe | 91 |
| PortSwigger Web Security Academy | 34 |
| Sections | 4 |
Note: TryHackMe occasionally moves rooms between free and paid. If you find a lab that is locked, let me know and I will update the list.
Section Map
| # | Section | Focus | Labs |
|---|---|---|---|
| 01 | Information Gathering & Vulnerability Scanning | Passive/active recon, OSINT, and Nmap | 13 |
| 02 | Auditing and Monitoring | Vulnerability scanners, risk, and detection frameworks | 8 |
| 03 | System & Network Host-Based Attacks | Networking, privilege escalation, Metasploit, and boot2root machines | 55 |
| 04 | Web Application Attacks | Web fundamentals, SQL injection, and XSS | 49 |
Suggested Learning Path
- Start with the basics: Information Gathering & Vulnerability Scanning
- Understand monitoring and auditing: Auditing and Monitoring
- Host and network track: System & Network Host-Based Attacks. Work through Networking & Basics first, then Privilege Escalation, Metasploit, and Basic Exploitation before moving on to the wider CTF collection.
- Web application track: Web Application Attacks. Complete Web Basics and TryHackMe SQL injection before starting PortSwigger.
The host/network track and the web track are independent, so you can study them in either order or alternate between them.
PortSwigger difficulty levels: Apprentice -> Practitioner -> Expert. If you are new to a topic, complete the Apprentice labs in each subsection before attempting the harder ones.
01. Information Gathering & Vulnerability Scanning
Focus: Passive/active recon, OSINT, and Nmap
Labs: 13
The starting point of every assessment: gathering information about the target passively and actively, using OSINT tools like Shodan and Google Dorking, and mastering Nmap and RustScan for host and service discovery.
Reconnaissance
| # | Lab | Platform |
|---|---|---|
| 1 | Passive Reconnaissance | TryHackMe |
| 2 | Active Reconnaissance | TryHackMe |
| 3 | Red Team Recon | TryHackMe |
Nmap & Port Scanning
| # | Lab | Platform |
|---|---|---|
| 4 | Nmap: Live Host Discovery | TryHackMe |
| 5 | Nmap: Basic Port Scans | TryHackMe |
| 6 | Nmap: Advanced Port Scans | TryHackMe |
| 7 | Further Nmap | TryHackMe |
| 8 | Nmap | TryHackMe |
| 9 | RustScan | TryHackMe |
OSINT
| # | Lab | Platform |
|---|---|---|
| 10 | Shodan.io | TryHackMe |
| 11 | Google Dorking | TryHackMe |
| 12 | Web OSINT | TryHackMe |
| 13 | Searchlight OSINT | TryHackMe |
02. Auditing and Monitoring
Focus: Vulnerability scanners, risk, and detection frameworks
Labs: 8
Understanding how systems are audited and monitored: security principles and risk management, vulnerability scanning with Nessus and OpenVAS, and detection frameworks like MITRE ATT&CK and Yara.
| # | Lab | Platform |
|---|---|---|
| 1 | Auditing and Monitoring | TryHackMe |
| 2 | Risk Management | TryHackMe |
| 3 | Vulnerability Scanner Overview | TryHackMe |
| 4 | Security Principles | TryHackMe |
| 5 | Nessus | TryHackMe |
| 6 | MITRE | TryHackMe |
| 7 | Yara | TryHackMe |
| 8 | OpenVAS | TryHackMe |
03. System & Network Host-Based Attacks
Focus: Networking, privilege escalation, Metasploit, and boot2root machines
Labs: 55
The core hands-on section: networking fundamentals and traffic analysis, privilege escalation on Windows and Linux, exploitation with Metasploit, and a long list of boot2root machines to apply everything end to end. Start with the basic machines, then move on to the wider CTF collection.
Networking & Basics
| # | Lab | Platform |
|---|---|---|
| 1 | Networking Concepts | TryHackMe |
| 2 | Networking Essentials | TryHackMe |
| 3 | Networking Core Protocols | TryHackMe |
| 4 | Wireshark: The Basics | TryHackMe |
| 5 | Tcpdump | TryHackMe |
Privilege Escalation & Hardening
| # | Lab | Platform |
|---|---|---|
| 6 | Windows PrivEsc | TryHackMe |
| 7 | Linux PrivEsc | TryHackMe |
| 8 | Linux Privilege Escalation | TryHackMe |
| 9 | Common Linux Privesc | TryHackMe |
| 10 | Windows Local Persistence | TryHackMe |
| 11 | Linux System Hardening | TryHackMe |
Metasploit & Exploitation
| # | Lab | Platform |
|---|---|---|
| 12 | Metasploit: Introduction | TryHackMe |
| 13 | Metasploit: Exploitation | TryHackMe |
| 14 | Meterpreter | TryHackMe |
Basic Exploitation
| # | Lab | Platform |
|---|---|---|
| 15 | Vulnversity | TryHackMe |
| 16 | Basic Pentesting | TryHackMe |
| 17 | Steel Mountain | TryHackMe |
CTF & Exploitation Labs
| # | Lab | Platform |
|---|---|---|
| 18 | GamingServer | TryHackMe |
| 19 | OverlayFS | TryHackMe |
| 20 | Psycho Break | TryHackMe |
| 21 | Bounty Hacker | TryHackMe |
| 22 | CTF | TryHackMe |
| 23 | RootMe | TryHackMe |
| 24 | Pickle Rick | TryHackMe |
| 25 | c4ptur3-th3-fl4g | TryHackMe |
| 26 | Library | TryHackMe |
| 27 | Thompson | TryHackMe |
| 28 | Simple CTF | TryHackMe |
| 29 | LazyAdmin | TryHackMe |
| 30 | Anonforce | TryHackMe |
| 31 | Ignite | TryHackMe |
| 32 | Wgel CTF | TryHackMe |
| 33 | Kenobi | TryHackMe |
| 34 | DAV | TryHackMe |
| 35 | Ninja Skills | TryHackMe |
| 36 | Ice | TryHackMe |
| 37 | Lian_Yu | TryHackMe |
| 38 | The Cod Caper | TryHackMe |
| 39 | Blaster | TryHackMe |
| 40 | Startup | TryHackMe |
| 41 | Chill Hack | TryHackMe |
| 42 | Colddbox: Easy | TryHackMe |
| 43 | GLITCH | TryHackMe |
| 44 | All in One | TryHackMe |
| 45 | Archangel | TryHackMe |
| 46 | Cyborg | TryHackMe |
| 47 | Lunizz CTF | TryHackMe |
| 48 | Badbyte | TryHackMe |
| 49 | Team | TryHackMe |
| 50 | VulnNet: Node | TryHackMe |
| 51 | VulnNet: Internal | TryHackMe |
| 52 | Atlas | TryHackMe |
| 53 | VulnNet: Roasted | TryHackMe |
| 54 | Cat Pictures | TryHackMe |
| 55 | Mustacchio | TryHackMe |
04. Web Application Attacks
Focus: Web fundamentals, SQL injection, and XSS
Labs: 49
From how the web works to hands-on exploitation: web fundamentals and OWASP first, then SQL injection (TryHackMe followed by PortSwigger), and finally the full PortSwigger XSS track covering reflected, stored, DOM-based, and context-specific XSS, plus exploitation and CSP bypass.
Web Basics
| # | Lab | Platform |
|---|---|---|
| 1 | Web Fundamentals | TryHackMe |
| 2 | Web App Security 101 | TryHackMe |
| 3 | Web Application Basics | TryHackMe |
| 4 | JavaScript Essentials | TryHackMe |
| 5 | Burp Suite: The Basics | TryHackMe |
| 6 | OWASP Top 10 - 2021 | TryHackMe |
| 7 | How Websites Work | TryHackMe |
| 8 | HTTP in Detail | TryHackMe |
| 9 | OWASP Juice Shop | TryHackMe |
| 10 | DNS in Detail | TryHackMe |
| 11 | Putting It All Together | TryHackMe |
| 12 | Walking An Application | TryHackMe |
SQL Injection - TryHackMe
| # | Lab | Platform |
|---|---|---|
| 13 | SQL Fundamentals | TryHackMe |
| 14 | Advanced SQL Injection | TryHackMe |
| 15 | SQL Injection Lab | TryHackMe |
SQL Injection - PortSwigger: Basic
| # | Lab | Level |
|---|---|---|
| 16 | SQL injection vulnerability in WHERE clause allowing retrieval of hidden data | Apprentice |
| 17 | SQL injection vulnerability allowing login bypass | Apprentice |
SQL Injection - PortSwigger: Examining the Database
| # | Lab | Level |
|---|---|---|
| 18 | Querying the database type and version on Oracle | Practitioner |
| 19 | Querying the database type and version on MySQL and Microsoft | Practitioner |
| 20 | Listing the database contents on non-Oracle databases | Practitioner |
| 21 | Listing the database contents on Oracle | Practitioner |
SQL Injection - PortSwigger: UNION Attacks
| # | Lab | Level |
|---|---|---|
| 22 | UNION attack: determining the number of columns | Practitioner |
| 23 | UNION attack: finding a column containing text | Practitioner |
| 24 | UNION attack: retrieving data from other tables | Practitioner |
| 25 | UNION attack: retrieving multiple values in a single column | Practitioner |
SQL Injection - PortSwigger: Blind
| # | Lab | Level |
|---|---|---|
| 26 | Blind SQLi with conditional responses | Practitioner |
| 27 | Blind SQLi with conditional errors | Practitioner |
| 28 | Blind SQLi with time delays | Practitioner |
XSS - Reflected & Stored
| # | Lab | Level |
|---|---|---|
| 29 | Reflected XSS into HTML context with nothing encoded | Apprentice |
| 30 | Stored XSS into HTML context with nothing encoded | Apprentice |
XSS - DOM-Based
| # | Lab | Level |
|---|---|---|
| 31 | DOM XSS in document.write sink using source location.search | Apprentice |
| 32 | DOM XSS in innerHTML sink using source location.search | Apprentice |
| 33 | DOM XSS in jQuery anchor href attribute sink using location.search source | Apprentice |
| 34 | DOM XSS in jQuery selector sink using a hashchange event | Apprentice |
| 35 | DOM XSS in document.write sink using source location.search inside a select element | Practitioner |
| 36 | DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded | Practitioner |
| 37 | Reflected DOM XSS | Practitioner |
| 38 | Stored DOM XSS | Practitioner |
XSS - Contexts
| # | Lab | Level |
|---|---|---|
| 39 | XSS in an attribute with angle brackets HTML-encoded | Apprentice |
| 40 | XSS in an href attribute with double quotes HTML-encoded | Apprentice |
| 41 | XSS into a JavaScript string with angle brackets HTML-encoded | Apprentice |
| 42 | XSS in a HTML context with most tags and attributes blocked | Practitioner |
| 43 | XSS in a HTML context with all standard tags blocked | Practitioner |
| 44 | XSS with some SVG markup allowed | Practitioner |
| 45 | Reflected XSS in canonical link tag | Expert |
XSS - Exploitation
| # | Lab | Level |
|---|---|---|
| 46 | Exploiting XSS to steal cookies | Practitioner |
| 47 | Exploiting XSS to capture passwords | Practitioner |
| 48 | Exploiting XSS to perform CSRF | Practitioner |
XSS - Content Security Policy
| # | Lab | Level |
|---|---|---|
| 49 | Reflected XSS protected by CSP, with CSP bypass | Expert |
Tips for Getting the Most Out of These Labs
- Take notes on every lab: the tool, the command, and the idea behind it, so you can come back to them later.
- Avoid walkthroughs until you have genuinely tried on your own.
- Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.
- Do the CTF machines methodically: enumerate first, note every service and version, then exploit. The same process will carry you through the exam.
These labs are for learning and practice in authorized environments only. Never test any technique on systems you do not own or have explicit permission to test.