Overview
This roadmap supports the Security+ (SY0-701) course with hands-on labs from 101Labs and TryHackMe, organized into 15 sections that take you from reconnaissance and network basics through web attacks, password cracking, wireless, shells and post-exploitation, scripting, and security tools, ending with governance, risk, and architecture.
The roadmap was put together by Netriders Academy, with the labs curated by Ahmed Sultan. Every link opens the lab directly.
| Total labs | 104 |
| 101Labs (CompTIA Security+ labs) | 96 |
| TryHackMe | 8 |
| Sections | 15 |
Note: four labs (hping, ARP reconnaissance, Nessus, and OpenVPN) appear in two sections because they support more than one topic, so the total counts each appearance (100 unique labs). The final review list in section 15 points back to earlier labs rather than repeating their links. TryHackMe also occasionally moves rooms between free and paid, so if you find a lab that is locked, let me know and I will update the list.
Exam Domains at a Glance
Most labs in this roadmap are practical, so they concentrate on the threat and operations domains of SY0-701. The conceptual domains are covered mainly by section 14, alongside your study notes.
| Domain | Exam Weight | Main Sections in This Roadmap |
|---|---|---|
| General Security Concepts | 12% | 14 |
| Threats, Vulnerabilities, and Mitigations | 22% | 03, 05, 06, 08, 09 |
| Security Architecture | 18% | 14 |
| Security Operations | 28% | 01, 02, 04, 07, 10, 11, 12, 13 |
| Security Program Management and Oversight | 20% | 14 |
Section Map
| # | Section | Focus | Labs |
|---|---|---|---|
| 01 | Reconnaissance & Network Basics | Information gathering and core network utilities | 12 |
| 02 | Scanning & Enumeration | IP scanners, anonymous scanning, and hping | 3 |
| 03 | Web Attacks & Vulnerabilities | Classic web attacks and the OWASP Top 10 | 15 |
| 04 | Web Tools & Exploitation | Burp Suite, cURL, Gobuster, Nikto, ZAP, and Nessus | 7 |
| 05 | Passwords, Hashing & Cracking | Hashcat, John the Ripper, and Responder | 4 |
| 06 | Wireless Attacks | Evil twin, WPS, WPA handshakes, and Wi-Fi monitoring | 6 |
| 07 | Network Tools & Traffic Analysis | Netcat, Tcpdump, Wireshark, hping, and ARP | 5 |
| 08 | Shells, Exploitation & Post-Exploitation | Reverse and bind shells, MSFvenom, and Meterpreter | 14 |
| 09 | Privilege Escalation | Enumeration for privilege escalation and process inspection | 4 |
| 10 | Linux & System Skills | Linux concepts, file operations, and VPN access | 5 |
| 11 | Scripting & Automation | Bash, Python, and PowerShell scripting | 8 |
| 12 | Security Tools & Frameworks | Hydra, SQLmap, Sn1per, BeEF, Nessus, and OpenVAS | 6 |
| 13 | OSINT & Misc Tools | Site cloning, checksums, SSH, and lab setup | 6 |
| 14 | Governance, Risk & Architecture | Security principles, cryptography, IAM, governance, and architecture | 8 |
| 15 | Advanced Topics & Final Review | Weaponizing vulnerabilities and a final review set | 1 |
Suggested Learning Path
- Foundations: Linux & System Skills -> Reconnaissance & Network Basics -> Scanning & Enumeration
- Concepts: Governance, Risk & Architecture, alongside your study notes
- Web: Web Attacks & Vulnerabilities -> Web Tools & Exploitation
- Attacks and credentials: Passwords, Hashing & Cracking -> Wireless Attacks -> Network Tools & Traffic Analysis
- Exploitation: Shells, Exploitation & Post-Exploitation -> Privilege Escalation
- Tooling and automation: Security Tools & Frameworks -> Scripting & Automation -> OSINT & Misc Tools
- Wrap-up: Advanced Topics & Final Review
Section 10 (Linux & System Skills) is the best warm-up, since almost every other lab assumes you are comfortable in a Linux shell and connected to the lab network.
01. Reconnaissance & Network Basics
Focus: Information gathering and core network utilities
Labs: 12
Learn the command-line tools every security professional uses to gather information and inspect a network: Nmap, Recon-ng, theHarvester, DNS tools, and the everyday utilities (ping, traceroute, netstat, ARP, ipconfig/ifconfig).
| # | Lab | Platform |
|---|---|---|
| 1 | Nmap | 101Labs |
| 2 | Recon-ng | 101Labs |
| 3 | Information Gathering Using theHarvester | 101Labs |
| 4 | Nslookup | 101Labs |
| 5 | Dig | 101Labs |
| 6 | Using Traceroute in Linux | 101Labs |
| 7 | Ping and Its Various Uses | 101Labs |
| 8 | Using Netstat to View Networking Information | 101Labs |
| 9 | Using ARP for Network Reconnaissance | 101Labs |
| 10 | Using ipconfig to View and Modify Network Information on Windows | 101Labs |
| 11 | Using ifconfig to View and Modify Network Information on Linux | 101Labs |
| 12 | Gathering DNS Information with DNSenum | 101Labs |
02. Scanning & Enumeration
Focus: IP scanners, anonymous scanning, and hping
Labs: 3
Discovering hosts and services on a network with IP scanners, anonymous port scanning, and hping for auditing and testing network devices.
| # | Lab | Platform |
|---|---|---|
| 1 | IP Scanners | 101Labs |
| 2 | Using Scanless for Easy Anonymous Port Scanning | 101Labs |
| 3 | hping for Security Auditing and Testing of Network Devices | 101Labs |
03. Web Attacks & Vulnerabilities
Focus: Classic web attacks and the OWASP Top 10
Labs: 15
The most common web application attacks in practice: XSS, CSRF, directory traversal, SQL injection, and broken access control, followed by a walk through the OWASP Top 10 (A1 to A10) one lab at a time.
Common Web Attacks
| # | Lab | Platform |
|---|---|---|
| 1 | Conducting a Cross-Site Scripting (XSS) Attack | 101Labs |
| 2 | Directory Traversal | 101Labs |
| 3 | Cross-Site Request Forgery (CSRF) | 101Labs |
| 4 | Manual SQL Injection | 101Labs |
| 5 | Broken Access Control | 101Labs |
OWASP Top 10
04. Web Tools & Exploitation
Focus: Burp Suite, cURL, Gobuster, Nikto, ZAP, and Nessus
Labs: 7
The tooling behind web testing: intercepting and manipulating requests with Burp Suite, working with cURL, discovering directories with Gobuster, and scanning for vulnerabilities with Nikto, ZAP, and Nessus.
| # | Lab | Platform |
|---|---|---|
| 1 | How to Use Burp Suite to Intercept Client-Side Requests | 101Labs |
| 2 | Using Burp Suiteās Intruder | 101Labs |
| 3 | Using cURL | 101Labs |
| 4 | Using Gobuster to Discover Directories | 101Labs |
| 5 | Web Application Vulnerability Scanning with Nikto | 101Labs |
| 6 | Web Server Vulnerability Scanning with ZAP | 101Labs |
| 7 | Running a Vulnerability Scan with Nessus | 101Labs |
05. Passwords, Hashing & Cracking
Focus: Hashcat, John the Ripper, and Responder
Labs: 4
How passwords are attacked: cracking with Hashcat and John the Ripper, and capturing password hashes on the network with Responder.
| # | Lab | Platform |
|---|---|---|
| 1 | How to Crack Passwords with Hashcat | 101Labs |
| 2 | Cracking Basic Hashes with John the Ripper | 101Labs |
| 3 | More Advanced Uses of John the Ripper | 101Labs |
| 4 | Capturing Password Hashes with Responder | 101Labs |
06. Wireless Attacks
Focus: Evil twin, WPS, WPA handshakes, and Wi-Fi monitoring
Labs: 6
Wireless security in practice: evil twin attacks, WPS attacks with Reaver and Wifite, discovering networks and capturing WPA handshakes with the Aircrack-ng suite, and monitoring signals with Kismet.
07. Network Tools & Traffic Analysis
Focus: Netcat, Tcpdump, Wireshark, hping, and ARP
Labs: 5
Working with traffic directly: Netcat for connections, Tcpdump and Wireshark for capturing and inspecting packets (including credentials sent over HTTP), and hping and ARP for probing devices.
| # | Lab | Platform |
|---|---|---|
| 1 | Netcat | 101Labs |
| 2 | Packet Capture with Tcpdump | 101Labs |
| 3 | Capturing Credentials Submitted Through HTTP with Wireshark | 101Labs |
| 4 | hping for Security Auditing and Testing of Network Devices | 101Labs |
| 5 | Using ARP for Network Reconnaissance | 101Labs |
08. Shells, Exploitation & Post-Exploitation
Focus: Reverse and bind shells, MSFvenom, and Meterpreter
Labs: 14
From getting a shell to using it: reverse and bind shells with Netcat and Socat, stabilizing shells, building payloads with MSFvenom, and working with Meterpreter, including process migration and exploiting a vulnerable FTP service.
Netcat & Socat Shells
| # | Lab | Platform |
|---|---|---|
| 1 | Getting a Reverse Shell on a Server Through a File Upload | 101Labs |
| 2 | Establishing a Reverse Shell with Netcat | 101Labs |
| 3 | How to Stabilise Netcat Shells | 101Labs |
| 4 | Getting a Reverse Shell Using Socat | 101Labs |
| 5 | Establishing a Bind Shell Using Socat | 101Labs |
| 6 | Establishing a Stable Socat Shell | 101Labs |
Metasploit & Meterpreter
09. Privilege Escalation
Focus: Enumeration for privilege escalation and process inspection
Labs: 4
Escalating privileges manually with Python and enumerating for weaknesses with WinPEAS and LinPEAS, plus using Process Explorer to find and scan suspicious processes.
10. Linux & System Skills
Focus: Linux concepts, file operations, and VPN access
Labs: 5
The Linux skills every security lab depends on: fundamental and advanced Linux operations, file operations, and connecting to an internal network with OpenVPN.
| # | Lab | Platform |
|---|---|---|
| 1 | Fundamental Linux Concepts | 101Labs |
| 2 | Linux Operations: Advanced Linux Operations | 101Labs |
| 3 | Basic File Operations | 101Labs |
| 4 | Advanced File Operations | 101Labs |
| 5 | How to Connect to an Internal Network Using OpenVPN | 101Labs |
11. Scripting & Automation
Focus: Bash, Python, and PowerShell scripting
Labs: 8
Automating security tasks with the three most common scripting languages: Bash, Python, and PowerShell, each from introduction to more advanced use.
Bash
| # | Lab | Platform |
|---|---|---|
| 1 | Introduction to Bash Scripting | 101Labs |
| 2 | More Bash Scripting | 101Labs |
| 3 | Advanced Bash Scripting | 101Labs |
Python
| # | Lab | Platform |
|---|---|---|
| 4 | Introduction to Python Scripting | 101Labs |
| 5 | More Python Scripting | 101Labs |
| 6 | More Advanced Python Scripting | 101Labs |
PowerShell
| # | Lab | Platform |
|---|---|---|
| 7 | Introduction to Scripting with PowerShell | 101Labs |
| 8 | More Advanced Scripting with PowerShell | 101Labs |
12. Security Tools & Frameworks
Focus: Hydra, SQLmap, Sn1per, BeEF, Nessus, and OpenVAS
Labs: 6
Popular security tools and frameworks in action: online password attacks with Hydra, automated SQL injection with SQLmap, reconnaissance with Sn1per, browser exploitation with BeEF, and vulnerability scanning with Nessus and OpenVAS.
| # | Lab | Platform |
|---|---|---|
| 1 | Hydra | 101Labs |
| 2 | Automating SQL Injection Using SQLmap | 101Labs |
| 3 | Sn1per | 101Labs |
| 4 | Browser Exploitation Framework (BeEF) | 101Labs |
| 5 | Running a Vulnerability Scan with Nessus | 101Labs |
| 6 | Perform a Network Vulnerability Scan with OpenVAS | 101Labs |
13. OSINT & Misc Tools
Focus: Site cloning, checksums, SSH, and lab setup
Labs: 6
Miscellaneous but important skills: credential harvesting with site cloning, verifying integrity with MD5 checksums, connecting over SSH from Windows and Linux, and setting up your own Kali Linux virtual machine.
14. Governance, Risk & Architecture
Focus: Security principles, cryptography, IAM, governance, and architecture
Labs: 8
The conceptual side of Security+, covered with TryHackMe rooms: security engineering, security principles, cryptography, identity and access management, governance and regulation, vulnerability management, security architecture, and virtualization.
| # | Lab | Platform |
|---|---|---|
| 1 | Security Engineer Intro | TryHackMe |
| 2 | Security Principles | TryHackMe |
| 3 | Cryptography Intro | TryHackMe |
| 4 | IAAA and IDM | TryHackMe |
| 5 | Cyber Governance and Regulation | TryHackMe |
| 6 | Vulnerability Management | TryHackMe |
| 7 | Intro to Security Architecture | TryHackMe |
| 8 | Virtualization and Containers | TryHackMe |
15. Advanced Topics & Final Review
Focus: Weaponizing vulnerabilities and a final review set
Labs: 1
One advanced lab on weaponizing vulnerabilities, followed by a final review list. Finish here by re-running the key labs from earlier sections without looking at the instructions.
| # | Lab | Platform |
|---|---|---|
| 1 | Weaponizing Vulnerabilities | 101Labs |
Final Review
Re-run these labs from earlier sections without looking at the instructions. If you can complete them from memory, you are ready.
- Cross-Site Request Forgery (CSRF) (section 03)
- Web Server Vulnerability Scanning with ZAP (section 04)
- Getting a Reverse Shell on a Server Through a File Upload (section 08)
- Manual Privilege Escalation Using Python (section 09)
- Using Gobuster to Discover Directories (section 04)
- Netcat (section 07)
Tips for Getting the Most Out of These Labs
- Set up your environment first. Build your Kali Linux virtual machine and connect over OpenVPN before starting the practical sections.
- Take notes on every lab: the tool, the command, and what it does, so you can come back to them later.
- Tie each lab to an exam objective. Ask yourself which threat, attack, or control the lab demonstrates, since that is how the exam frames it.
- Repeat labs a few days later without looking at the solution. This is what makes the knowledge stick.
These labs are for learning and practice in the provided lab environments only. Never use any tool or technique, especially the wireless, password, and exploitation labs, on systems or networks you do not own or have explicit permission to test.