1663 words
8 minutes
Security+ (SY0-701) Labs

Overview#

This roadmap supports the Security+ (SY0-701) course with hands-on labs from 101Labs and TryHackMe, organized into 15 sections that take you from reconnaissance and network basics through web attacks, password cracking, wireless, shells and post-exploitation, scripting, and security tools, ending with governance, risk, and architecture.

The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Every link opens the lab directly.

Total labs104
101Labs (CompTIA Security+ labs)96
TryHackMe8
Sections15

Note: four labs (hping, ARP reconnaissance, Nessus, and OpenVPN) appear in two sections because they support more than one topic, so the total counts each appearance (100 unique labs). The final review list in section 15 points back to earlier labs rather than repeating their links. TryHackMe also occasionally moves rooms between free and paid, so if you find a lab that is locked, let me know and I will update the list.

Exam Domains at a Glance#

Most labs in this roadmap are practical, so they concentrate on the threat and operations domains of SY0-701. The conceptual domains are covered mainly by section 14, alongside your study notes.

DomainExam WeightMain Sections in This Roadmap
General Security Concepts12%14
Threats, Vulnerabilities, and Mitigations22%03, 05, 06, 08, 09
Security Architecture18%14
Security Operations28%01, 02, 04, 07, 10, 11, 12, 13
Security Program Management and Oversight20%14

Section Map#

#SectionFocusLabs
01Reconnaissance & Network BasicsInformation gathering and core network utilities12
02Scanning & EnumerationIP scanners, anonymous scanning, and hping3
03Web Attacks & VulnerabilitiesClassic web attacks and the OWASP Top 1015
04Web Tools & ExploitationBurp Suite, cURL, Gobuster, Nikto, ZAP, and Nessus7
05Passwords, Hashing & CrackingHashcat, John the Ripper, and Responder4
06Wireless AttacksEvil twin, WPS, WPA handshakes, and Wi-Fi monitoring6
07Network Tools & Traffic AnalysisNetcat, Tcpdump, Wireshark, hping, and ARP5
08Shells, Exploitation & Post-ExploitationReverse and bind shells, MSFvenom, and Meterpreter14
09Privilege EscalationEnumeration for privilege escalation and process inspection4
10Linux & System SkillsLinux concepts, file operations, and VPN access5
11Scripting & AutomationBash, Python, and PowerShell scripting8
12Security Tools & FrameworksHydra, SQLmap, Sn1per, BeEF, Nessus, and OpenVAS6
13OSINT & Misc ToolsSite cloning, checksums, SSH, and lab setup6
14Governance, Risk & ArchitectureSecurity principles, cryptography, IAM, governance, and architecture8
15Advanced Topics & Final ReviewWeaponizing vulnerabilities and a final review set1

Suggested Learning Path#

  1. Foundations: Linux & System Skills -> Reconnaissance & Network Basics -> Scanning & Enumeration
  2. Concepts: Governance, Risk & Architecture, alongside your study notes
  3. Web: Web Attacks & Vulnerabilities -> Web Tools & Exploitation
  4. Attacks and credentials: Passwords, Hashing & Cracking -> Wireless Attacks -> Network Tools & Traffic Analysis
  5. Exploitation: Shells, Exploitation & Post-Exploitation -> Privilege Escalation
  6. Tooling and automation: Security Tools & Frameworks -> Scripting & Automation -> OSINT & Misc Tools
  7. Wrap-up: Advanced Topics & Final Review

Section 10 (Linux & System Skills) is the best warm-up, since almost every other lab assumes you are comfortable in a Linux shell and connected to the lab network.


01. Reconnaissance & Network Basics#

Focus: Information gathering and core network utilities
Labs: 12

Learn the command-line tools every security professional uses to gather information and inspect a network: Nmap, Recon-ng, theHarvester, DNS tools, and the everyday utilities (ping, traceroute, netstat, ARP, ipconfig/ifconfig).

#LabPlatform
1Nmap101Labs
2Recon-ng101Labs
3Information Gathering Using theHarvester101Labs
4Nslookup101Labs
5Dig101Labs
6Using Traceroute in Linux101Labs
7Ping and Its Various Uses101Labs
8Using Netstat to View Networking Information101Labs
9Using ARP for Network Reconnaissance101Labs
10Using ipconfig to View and Modify Network Information on Windows101Labs
11Using ifconfig to View and Modify Network Information on Linux101Labs
12Gathering DNS Information with DNSenum101Labs

02. Scanning & Enumeration#

Focus: IP scanners, anonymous scanning, and hping
Labs: 3

Discovering hosts and services on a network with IP scanners, anonymous port scanning, and hping for auditing and testing network devices.

#LabPlatform
1IP Scanners101Labs
2Using Scanless for Easy Anonymous Port Scanning101Labs
3hping for Security Auditing and Testing of Network Devices101Labs

03. Web Attacks & Vulnerabilities#

Focus: Classic web attacks and the OWASP Top 10
Labs: 15

The most common web application attacks in practice: XSS, CSRF, directory traversal, SQL injection, and broken access control, followed by a walk through the OWASP Top 10 (A1 to A10) one lab at a time.

Common Web Attacks#

#LabPlatform
1Conducting a Cross-Site Scripting (XSS) Attack101Labs
2Directory Traversal101Labs
3Cross-Site Request Forgery (CSRF)101Labs
4Manual SQL Injection101Labs
5Broken Access Control101Labs

OWASP Top 10#

#LabPlatform
6OWASP A1: OS Command Injection101Labs
7OWASP A2: Broken Authentication and Session Management (Username Enumeration)101Labs
8OWASP A3: Sensitive Information Disclosure101Labs
9OWASP A4: XML External Entities (XXE)101Labs
10OWASP A5: Broken Access Control101Labs
11OWASP A6: Security Misconfiguration101Labs
12OWASP A7: Cross-Site Scripting (XSS)101Labs
13OWASP A8: Insecure Deserialization101Labs
14OWASP A9: Using Components with Known Vulnerabilities101Labs
15OWASP A10: Unvalidated Redirects and Forwards101Labs

04. Web Tools & Exploitation#

Focus: Burp Suite, cURL, Gobuster, Nikto, ZAP, and Nessus
Labs: 7

The tooling behind web testing: intercepting and manipulating requests with Burp Suite, working with cURL, discovering directories with Gobuster, and scanning for vulnerabilities with Nikto, ZAP, and Nessus.

#LabPlatform
1How to Use Burp Suite to Intercept Client-Side Requests101Labs
2Using Burp Suite’s Intruder101Labs
3Using cURL101Labs
4Using Gobuster to Discover Directories101Labs
5Web Application Vulnerability Scanning with Nikto101Labs
6Web Server Vulnerability Scanning with ZAP101Labs
7Running a Vulnerability Scan with Nessus101Labs

05. Passwords, Hashing & Cracking#

Focus: Hashcat, John the Ripper, and Responder
Labs: 4

How passwords are attacked: cracking with Hashcat and John the Ripper, and capturing password hashes on the network with Responder.

#LabPlatform
1How to Crack Passwords with Hashcat101Labs
2Cracking Basic Hashes with John the Ripper101Labs
3More Advanced Uses of John the Ripper101Labs
4Capturing Password Hashes with Responder101Labs

06. Wireless Attacks#

Focus: Evil twin, WPS, WPA handshakes, and Wi-Fi monitoring
Labs: 6

Wireless security in practice: evil twin attacks, WPS attacks with Reaver and Wifite, discovering networks and capturing WPA handshakes with the Aircrack-ng suite, and monitoring signals with Kismet.

#LabPlatform
1Evil Twin Attack with Airgeddon101Labs
2Hack WPS with Reaver101Labs
3Hacking WPS Networks with Wifite101Labs
4How to Discover Nearby Wi-Fi Networks with Airodump-ng101Labs
5How to Capture a WPA Handshake File Using Airodump-ng and Aireplay-ng101Labs
6Monitoring Wi-Fi Signals with Kismet101Labs

07. Network Tools & Traffic Analysis#

Focus: Netcat, Tcpdump, Wireshark, hping, and ARP
Labs: 5

Working with traffic directly: Netcat for connections, Tcpdump and Wireshark for capturing and inspecting packets (including credentials sent over HTTP), and hping and ARP for probing devices.

#LabPlatform
1Netcat101Labs
2Packet Capture with Tcpdump101Labs
3Capturing Credentials Submitted Through HTTP with Wireshark101Labs
4hping for Security Auditing and Testing of Network Devices101Labs
5Using ARP for Network Reconnaissance101Labs

08. Shells, Exploitation & Post-Exploitation#

Focus: Reverse and bind shells, MSFvenom, and Meterpreter
Labs: 14

From getting a shell to using it: reverse and bind shells with Netcat and Socat, stabilizing shells, building payloads with MSFvenom, and working with Meterpreter, including process migration and exploiting a vulnerable FTP service.

Netcat & Socat Shells#

#LabPlatform
1Getting a Reverse Shell on a Server Through a File Upload101Labs
2Establishing a Reverse Shell with Netcat101Labs
3How to Stabilise Netcat Shells101Labs
4Getting a Reverse Shell Using Socat101Labs
5Establishing a Bind Shell Using Socat101Labs
6Establishing a Stable Socat Shell101Labs

Metasploit & Meterpreter#

#LabPlatform
7Creating Metasploit Payloads with MSFvenom101Labs
8Establishing a Reverse Shell on a Linux Target Using MSFvenom and Metasploit101Labs
9Basic Meterpreter Commands101Labs
10More Advanced Meterpreter Commands101Labs
11How to Migrate to a Different Process on the Target Machine After Establishing a Meterpreter Shell101Labs
12How to Establish a Meterpreter Shell on a Windows Target Using SET101Labs
13Upgrading a Limited Shell to Meterpreter Shell Using Metasploit101Labs
14Exploiting a Vulnerable FTP Service to Gain a Shell Using Metasploit101Labs

09. Privilege Escalation#

Focus: Enumeration for privilege escalation and process inspection
Labs: 4

Escalating privileges manually with Python and enumerating for weaknesses with WinPEAS and LinPEAS, plus using Process Explorer to find and scan suspicious processes.

#LabPlatform
1Manual Privilege Escalation Using Python101Labs
2How to Enumerate for Privilege Escalation on a Windows Target with WinPEAS101Labs
3How to Enumerate for Privilege Escalation on a Linux Target with LinPEAS101Labs
4How to Use Process Explorer to Find and Scan Suspicious Processes for Malware101Labs

10. Linux & System Skills#

Focus: Linux concepts, file operations, and VPN access
Labs: 5

The Linux skills every security lab depends on: fundamental and advanced Linux operations, file operations, and connecting to an internal network with OpenVPN.

#LabPlatform
1Fundamental Linux Concepts101Labs
2Linux Operations: Advanced Linux Operations101Labs
3Basic File Operations101Labs
4Advanced File Operations101Labs
5How to Connect to an Internal Network Using OpenVPN101Labs

11. Scripting & Automation#

Focus: Bash, Python, and PowerShell scripting
Labs: 8

Automating security tasks with the three most common scripting languages: Bash, Python, and PowerShell, each from introduction to more advanced use.

Bash#

#LabPlatform
1Introduction to Bash Scripting101Labs
2More Bash Scripting101Labs
3Advanced Bash Scripting101Labs

Python#

#LabPlatform
4Introduction to Python Scripting101Labs
5More Python Scripting101Labs
6More Advanced Python Scripting101Labs

PowerShell#

#LabPlatform
7Introduction to Scripting with PowerShell101Labs
8More Advanced Scripting with PowerShell101Labs

12. Security Tools & Frameworks#

Focus: Hydra, SQLmap, Sn1per, BeEF, Nessus, and OpenVAS
Labs: 6

Popular security tools and frameworks in action: online password attacks with Hydra, automated SQL injection with SQLmap, reconnaissance with Sn1per, browser exploitation with BeEF, and vulnerability scanning with Nessus and OpenVAS.

#LabPlatform
1Hydra101Labs
2Automating SQL Injection Using SQLmap101Labs
3Sn1per101Labs
4Browser Exploitation Framework (BeEF)101Labs
5Running a Vulnerability Scan with Nessus101Labs
6Perform a Network Vulnerability Scan with OpenVAS101Labs

13. OSINT & Misc Tools#

Focus: Site cloning, checksums, SSH, and lab setup
Labs: 6

Miscellaneous but important skills: credential harvesting with site cloning, verifying integrity with MD5 checksums, connecting over SSH from Windows and Linux, and setting up your own Kali Linux virtual machine.

#LabPlatform
1Credential Harvesting Using Site Cloning101Labs
2How to Connect to an Internal Network Using OpenVPN101Labs
3Using MD5 Checksums101Labs
4How to SSH into a Server from a Windows Machine Using PuTTY101Labs
5How to SSH into a Server from a Linux Machine101Labs
6How to Set Up Your Own Kali Linux Virtual Machine101Labs

14. Governance, Risk & Architecture#

Focus: Security principles, cryptography, IAM, governance, and architecture
Labs: 8

The conceptual side of Security+, covered with TryHackMe rooms: security engineering, security principles, cryptography, identity and access management, governance and regulation, vulnerability management, security architecture, and virtualization.

#LabPlatform
1Security Engineer IntroTryHackMe
2Security PrinciplesTryHackMe
3Cryptography IntroTryHackMe
4IAAA and IDMTryHackMe
5Cyber Governance and RegulationTryHackMe
6Vulnerability ManagementTryHackMe
7Intro to Security ArchitectureTryHackMe
8Virtualization and ContainersTryHackMe

15. Advanced Topics & Final Review#

Focus: Weaponizing vulnerabilities and a final review set
Labs: 1

One advanced lab on weaponizing vulnerabilities, followed by a final review list. Finish here by re-running the key labs from earlier sections without looking at the instructions.

#LabPlatform
1Weaponizing Vulnerabilities101Labs

Final Review#

Re-run these labs from earlier sections without looking at the instructions. If you can complete them from memory, you are ready.

  • Cross-Site Request Forgery (CSRF) (section 03)
  • Web Server Vulnerability Scanning with ZAP (section 04)
  • Getting a Reverse Shell on a Server Through a File Upload (section 08)
  • Manual Privilege Escalation Using Python (section 09)
  • Using Gobuster to Discover Directories (section 04)
  • Netcat (section 07)

Tips for Getting the Most Out of These Labs#

  • Set up your environment first. Build your Kali Linux virtual machine and connect over OpenVPN before starting the practical sections.
  • Take notes on every lab: the tool, the command, and what it does, so you can come back to them later.
  • Tie each lab to an exam objective. Ask yourself which threat, attack, or control the lab demonstrates, since that is how the exam frames it.
  • Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.

These labs are for learning and practice in the provided lab environments only. Never use any tool or technique, especially the wireless, password, and exploitation labs, on systems or networks you do not own or have explicit permission to test.

Security+ (SY0-701) Labs
https://bad-glitch.github.io/posts/labs/security-plus---labs/security/
Author
Amr Abdel Hamide
Published at
2026-09-19