🗺️ Roadmap Completo de OSINT y Ciberseguridad 2026: De Intermedio a Especialista

🗺️ Roadmap Completo de OSINT y Ciberseguridad 2026: De Intermedio a Especialista

La guía de rutas más completa del blog: un roadmap integrado que cubre OSINT, Pentesting/Red Team y Blue Team/SOC desde nivel intermedio hasta especialización profesional. Con certificaciones, plataformas de práctica, recursos gratuitos, y tiempos realistas para cada fase.

Jafet Brito

Jafet Brito

Security Researcher

🗺️ Roadmap Completo de OSINT y Ciberseguridad 2026: De Intermedio a Especialista

Por Jafet Brito · Security Researcher · Publicado el 11 de junio de 2026


“La ciberseguridad no es un destino. Es una dirección.” — Filosofía Zero Trust

⚠️ Nota importante: Este roadmap asume que ya tienes conocimientos de IT, redes o Linux básico. Si partes desde cero absoluto, te recomiendo completar primero el CompTIA ITF+ o el path Pre-Security de TryHackMe antes de continuar aquí.


🧭 Cómo Leer Este Roadmap

Este no es un roadmap lineal — es un árbol de caminos con una base común y tres especializaciones que convergen en el nivel avanzado. La estructura es la siguiente:

📦 FASE 0: Base Común (Todos los caminos)

   ┌────┴────┬─────────────┐
   ↓         ↓             ↓
🔍 OSINT   ⚔️ Red Team   🛡️ Blue Team
   ↓         ↓             ↓
   └────┬────┴─────────────┘

🎯 FASE AVANZADA: Especialización & Convergencia

Puedes seguir un solo camino o los tres — y en el nivel avanzado, los mejores profesionales siempre han tocado los tres. Un buen Red Teamer entiende de OSINT y de defensa. Un buen analista SOC entiende cómo piensan los atacantes.


📦 FASE 0: Los Cimientos — Lo Que Todo Especialista Debe Saber

⏱️ Tiempo estimado: 2-4 meses (si ya tienes base de IT) 🎯 Objetivo: Tener el lenguaje, los conceptos, y el entorno de trabajo para cualquiera de los tres caminos

🖥️ 0.1 — Sistema Operativo: Linux como Lengua Materna

La ciberseguridad ocurre primordialmente en Linux. No puedes ser efectivo en ninguno de los tres caminos sin sentirte cómodo en la terminal.

Lo que debes dominar:

  • 🔧 Navegación del filesystem: ls, cd, find, locate, which
  • 📄 Manipulación de archivos y texto: cat, grep, awk, sed, cut, sort, uniq
  • 🔒 Permisos: chmod, chown, umask, gestión de usuarios y grupos
  • 🌐 Red desde terminal: ip, ss, netstat, ping, traceroute, curl, wget
  • ⚙️ Procesos: ps, top, htop, kill, systemctl, cron
  • 📦 Scripting Bash: variables, loops, condicionales, funciones

Recursos gratuitos:


🌐 0.2 — Redes: El Idioma que Habla Internet

Lo que debes dominar:

  • 📡 Modelo OSI y TCP/IP — Capa por capa, qué hace cada una
  • 🔢 Direccionamiento: IPv4, IPv6, CIDR notation, subnetting
  • 📨 Protocolos fundamentales: TCP, UDP, ICMP, DNS, HTTP/HTTPS, SMTP, FTP, SSH, SMB, RDP
  • 🔍 Herramientas de análisis: Wireshark, tcpdump, nmap básico
  • 🔒 Conceptos de seguridad de red: Firewalls, NAT, VLANs, VPN, proxies

Recursos gratuitos:


🔐 0.3 — Conceptos de Seguridad Fundamentales

Lo que debes dominar:

  • 🎯 La Tríada CIA: Confidentiality, Integrity, Availability
  • ⚔️ Tipos de ataques: Phishing, MitM, DoS/DDoS, SQL Injection, XSS, CSRF, Buffer Overflow
  • 🔑 Criptografía básica: Simétrica vs asimétrica, hashing, PKI, TLS/SSL
  • 🏛️ Frameworks: MITRE ATT&CK, Cyber Kill Chain, OWASP Top 10
  • 📋 Conceptos de compliance: GDPR, ISO 27001 (solo entender qué son)

Recursos gratuitos:


🏅 Certificación de Fase 0 Recomendada

Si quieres validar esta fase con una certificación:

CertificaciónCostoFormatoValor
CompTIA Security+~$400 USDExamen teórico + prácticoAlto — estándar de la industria, requerida por DoD
ISC2 CC (Certified in Cybersecurity)Gratis (iniciativa 1MCC)Examen teóricoMedio — excelente punto de entrada sin costo
CompTIA Network+~$380 USDExamen teóricoAlto — si tu base de redes es débil

💡 Recomendación: Si tienes presupuesto limitado, empieza con el ISC2 CC gratuito para validar el conocimiento y usa el dinero ahorrado para certificaciones más avanzadas.


🔍 CAMINO A: OSINT — Inteligencia de Fuentes Abiertas

⏱️ Tiempo estimado post-Fase 0: 3-6 meses para nivel funcional, 12+ meses para nivel avanzado 🎯 Roles objetivo: OSINT Analyst, Threat Intelligence Analyst, Investigador Digital, Journalist investigativo

🗺️ A.1 — Fundamentos del Ciclo OSINT

Antes de las herramientas, entiende el proceso. El OSINT no es buscar en Google — es el ciclo completo de inteligencia aplicado a fuentes abiertas:

1. Planificación    → ¿Qué necesito saber? ¿Cuáles son los requisitos?
2. Recolección      → Búsqueda activa/pasiva en fuentes abiertas
3. Procesamiento    → Limpiar, normalizar y estructurar datos crudos
4. Análisis         → Interpretar, correlacionar, identificar patrones
5. Diseminación     → Comunicar los hallazgos de forma accionable
6. Feedback         → Ajustar el ciclo según los resultados

Conceptos clave a dominar:

  • 🎭 Sock puppets y OPSEC: Cuentas falsas para investigación sin revelar identidad. Separación de entornos de investigación.
  • 🌐 Búsqueda avanzada: Google Dorks, Bing Dorks, operadores de búsqueda booleana
  • 📊 Pivoting: Moverse de un dato (email) → a otro (dominio) → a otro (IP) → a otro (persona)
  • ⚖️ Ética y legalidad: Los límites entre OSINT legal e ilegal varían por jurisdicción

Recursos gratuitos:


🛠️ A.2 — Stack de Herramientas OSINT Esenciales

Organiza tu aprendizaje por categoría. Lee nuestra Guía Completa de Herramientas OSINT para detalles de cada herramienta.

🌐 Dominios e Infraestructura

  • Shodan — Motor de búsqueda de dispositivos conectados
  • Censys — Certificados TLS y escaneo de infraestructura
  • crt.sh — Certificate Transparency logs
  • DNSDumpster — Mapeo DNS pasivo
  • SecurityTrails — Historial DNS

👤 Personas y Redes Sociales

📸 Imágenes y Geolocalización


📚 A.3 — Práctica Real: Dónde Entrenar OSINT


🏅 Certificaciones OSINT

CertificaciónEmisorCostoNivelDescripción
OSCPOffensive Security$1,499AvanzadoIncluye componente OSINT fuerte en recon
GOSI (GIAC OSINT)GIAC/SANS~$949IntermedioLa certificación OSINT más reconocida
PNPTTCM Security$400IntermedioExamen práctico con componente OSINT real
Certified OSINT ProfessionalOSMOSIS~$300Básico/MedioEspecífica para OSINT

⚔️ CAMINO B: Red Team & Pentesting

⏱️ Tiempo estimado post-Fase 0: 6-12 meses para nivel junior, 18-24 meses para nivel mid 🎯 Roles objetivo: Junior Penetration Tester, Red Team Operator, Bug Bounty Hunter, Vulnerability Researcher

🗺️ B.1 — El Framework Mental del Atacante

Antes de herramientas, entiende cómo piensa un atacante. El estándar de la industria para sistematizar esto es el framework MITRE ATT&CK y el modelo del Cyber Kill Chain:

KILL CHAIN (Lockheed Martin):
1. Reconnaissance    → OSINT, escaneo de red, enumeración
2. Weaponization     → Preparar el payload / exploit
3. Delivery          → Email, web, USB, ingeniería social
4. Exploitation      → Ejecutar el exploit en el objetivo
5. Installation      → Establecer persistencia
6. C2 (Command & Control) → Canal de comunicación con el objetivo
7. Actions on Objectives  → Exfiltración, movimiento lateral, impacto

Esta estructura define las fases del pentesting que debes aprender en orden.


🛠️ B.2 — Stack Técnico Red Team por Fase

🔍 Fase 1: Reconocimiento (Recon)

Lo primero es siempre OSINT. Ver Camino A para el stack completo.

Herramientas adicionales para recon técnico:

  • Nmap — El escáner de puertos estándar. Domínalo completamente.
  • Masscan — Escaneo de puertos a velocidad máxima
  • theHarvester — Recolección de emails, subdominios, IPs desde buscadores
  • Amass — Enumeración avanzada de subdominios (OWASP)
  • Subfinder — Subdominios pasivos, extremadamente rápido

💥 Fase 2: Scanning y Enumeración

🎯 Fase 3: Explotación

🔝 Fase 4: Post-Explotación y Movimiento Lateral

⚠️ Zero Trust en herramientas: Todas estas herramientas son de doble filo. Solo úsalas en entornos que te pertenecen, plataformas de práctica autorizadas (HackTheBox, TryHackMe), o en compromisos con contrato firmado. El uso no autorizado es ilegal.


📚 B.3 — Plataformas de Práctica Red Team

PROGRESIÓN RECOMENDADA:
TryHackMe → HackTheBox → PortSwigger → OffSec Labs
(Guiado)    (Realista)   (Web App)    (Certificación)
  • 🎮 TryHackMe — Comenzar aquí. Rooms guiados, browser-based. Free tier generoso.
    • Paths recomendados: Jr Penetration Tester, Red Teaming, Offensive Pentesting
  • 🎮 Hack The Box — Siguiente nivel. Menos guiado, más realista. Free tier con máquinas rotativas.
    • Paths recomendados: Penetration Testing Job Role, Active Directory 101
  • 🌐 PortSwigger Web Security Academy100% gratuito. El estándar de oro para pentesting web. Labs interactivos con Burp Suite.
  • 🎮 VulnHub — Máquinas virtuales vulnerables para descargar y practicar localmente. Completamente gratis.
  • 🎮 PentesterLab — Web app security con badge system. Tier gratis disponible.

📝 B.4 — El Skill Olvidado: Writing Reports

Un pentester que no sabe escribir reportes pierde el 50% de su valor. Las empresas contratan pentesting para tener un reporte accionable — no para ver un exploit bonito.

Un buen reporte de pentesting tiene:

1. Executive Summary     → Para el C-suite: impacto de negocio en lenguaje no técnico
2. Scope & Methodology   → Qué se probó, cómo, cuándo
3. Risk Summary          → Tabla de hallazgos por criticidad
4. Technical Findings    → Para cada vuln: descripción, evidencia (screenshot),
                           CVSS score, CVE si aplica, pasos de reproducción,
                           impacto, recomendación de remediación
5. Appendices            → Logs, herramientas usadas, referencias

🏅 Certificaciones Red Team — Mapa Completo

NIVEL ENTRY (0-12 meses de práctica):
┌─────────────────────────────────────────────────────┐
│  eJPT (eLearnSecurity)     ~$200   Hands-on básico  │
│  CompTIA PenTest+          ~$400   Teórico+práctico │
│  PJPT (TCM Security)       $30     Hands-on básico  │
└─────────────────────────────────────────────────────┘

NIVEL MID (1-2 años de práctica):
┌─────────────────────────────────────────────────────┐
│  OSCP (OffSec)             $1,499  EL ESTÁNDAR ORO  │
│  PNPT (TCM Security)       $400    Práctico+reporte │
│  GPEN (GIAC)               ~$949   Enterprise focus │
└─────────────────────────────────────────────────────┘

NIVEL AVANZADO (2+ años):
┌─────────────────────────────────────────────────────┐
│  OSEP (OffSec)             ~$1,299 Evasión + AV     │
│  CRTO (Zero-Point Security) £399   AD Red Team      │
│  OSWE (OffSec)             ~$1,299 Web Expert       │
│  GXPN (GIAC)              ~$949   Expert pentest    │
│  OSED (OffSec)             ~$1,299 Exploit dev      │
└─────────────────────────────────────────────────────┘

💡 Consejo de carrera: La ruta más respetada en 2026 es eJPT/PJPT → OSCP → especialización (OSEP/CRTO/OSWE). El OSCP sigue siendo la credencial de referencia que más empleadores requieren para roles de pentesting.


🛡️ CAMINO C: Blue Team & SOC

⏱️ Tiempo estimado post-Fase 0: 4-8 meses para Tier 1 SOC, 12-18 meses para Tier 2/3 🎯 Roles objetivo: SOC Analyst (Tier 1/2/3), Threat Hunter, Incident Responder, Threat Intelligence Analyst, Security Engineer

🗺️ C.1 — El Framework Mental del Defensor

El Blue Team piensa en términos de detección, respuesta y resiliencia. Los frameworks clave:

NIST Cybersecurity Framework (CSF):
├── Identify     → Inventario de assets, gestión de riesgos
├── Protect      → Controles preventivos, segmentación, hardening
├── Detect       → Monitoreo, alertas, hunting de amenazas
├── Respond      → Incident response, contención, erradicación
└── Recover      → Restauración, post-mortem, mejoras

MITRE D3FEND (el contraparte defensivo de ATT&CK):
Técnicas de defensa mapeadas contra las técnicas de ataque de ATT&CK

🛠️ C.2 — Stack Técnico Blue Team

📊 SIEM — El Centro Nervioso del SOC

Los SIEMs correlacionan logs de toda la infraestructura para detectar amenazas:

  • Splunk — El estándar de la industria. Free tier disponible para práctica.
  • Microsoft Sentinel — Cloud-native SIEM. Domina en empresas Microsoft.
  • Elastic SIEM / ELK Stack — Open source. Puedes instalarlo localmente gratis.
  • Wazuh — Open source, excelente para homelabs. 100% gratuito.

🔍 Herramientas de Análisis y Detección

🎯 Threat Hunting

  • Sigma Rules — El estándar abierto de reglas de detección, vendor-agnostic
  • MITRE ATT&CK Navigator — Para mapear amenazas y gaps de cobertura
  • OpenCTI — Plataforma open source de Threat Intelligence

📚 C.3 — Plataformas de Práctica Blue Team


🏅 Certificaciones Blue Team — Mapa Completo

NIVEL ENTRY (0-12 meses):
┌──────────────────────────────────────────────────────┐
│  CompTIA Security+        ~$400   Base requerida     │
│  CompTIA CySA+            ~$400   SOC-focused        │
│  BTL1 (Blue Team Labs)    ~$500   Hands-on SOC       │
└──────────────────────────────────────────────────────┘

NIVEL MID (1-2 años):
┌──────────────────────────────────────────────────────┐
│  Splunk Core Certified    ~$130   SIEM standard      │
│  Microsoft SC-200         ~$165   Sentinel/Defender  │
│  GCIH (GIAC)              ~$949   Incident Handler   │
│  GCFE (GIAC)              ~$949   Digital Forensics  │
└──────────────────────────────────────────────────────┘

NIVEL AVANZADO (2+ años):
┌──────────────────────────────────────────────────────┐
│  GCIA (GIAC)              ~$949   Intrusion Analyst  │
│  GCTI (GIAC)              ~$949   Threat Intelligence│
│  CISSP (ISC2)             ~$749   Management/Senior  │
│  CISM (ISACA)             ~$760   Security Manager   │
└──────────────────────────────────────────────────────┘

🎯 FASE AVANZADA: Especialización y Convergencia

Esta fase es donde el mapa se vuelve personal. No hay una ruta única — hay vectores de especialización que eliges según tus intereses, el mercado laboral de tu región, y tu experiencia acumulada.

🔬 Especialización Ofensiva (Red Team Avanzado)

Active Directory Attack & Defense

El 90% de las empresas Fortune 500 usa Active Directory. Dominarlo es obligatorio para cualquier Red Teamer serio.

Cloud Pentesting

AWS, Azure, y GCP son el nuevo perímetro. Las empresas están migrando masivamente y la mayoría no tiene equipo que sepa testear cloud.

Bug Bounty

El camino hacia ingresos independientes. La plataforma más grande es HackerOne y Bugcrowd.


🔬 Especialización Defensiva (Blue Team Avanzado)

Threat Intelligence

Convertir datos en inteligencia accionable. El rol más estratégico del Blue Team.

Digital Forensics & Incident Response (DFIR)

Responder cuando el incidente ya ocurrió. El rol más demandado en 2026.

Security Engineering / DevSecOps

Integrar seguridad en el pipeline de desarrollo. El rol que más crece con la expansión de cloud nativo.


📅 Timeline Realista — ¿Cuánto Tiempo Toma?

Estas estimaciones asumen estudio constante de 1-2 horas diarias + práctica en labs los fines de semana.

PARTIENDO DE NIVEL INTERMEDIO (ya sabes IT/redes/Linux básico):

╔══════════════════════════════════════════════════════════════╗
║  MES 0-3:   Fase 0 (Fundamentos)                            ║
║             + ISC2 CC (gratuito) o CompTIA Security+        ║
╠══════════════════════════════════════════════════════════════╣
║  MES 3-6:   Inicio de camino elegido                        ║
║             + TryHackMe (el path de tu camino)              ║
║             + Primera certificación de nivel entry          ║
╠══════════════════════════════════════════════════════════════╣
║  MES 6-12:  Profundización técnica                          ║
║             + HackTheBox (Red) / LetsDefend (Blue)          ║
║             + Certificación mid-level (OSCP / BTL1)         ║
╠══════════════════════════════════════════════════════════════╣
║  MES 12-18: Portfolio + aplicaciones laborales              ║
║             + Proyectos propios documentados                ║
║             + Participación en CTFs y comunidades           ║
╠══════════════════════════════════════════════════════════════╣
║  MES 18-24+: Especialización avanzada                       ║
║              + Certificación avanzada de tu track           ║
║              + Contribuciones open source                   ║
╚══════════════════════════════════════════════════════════════╝

🏠 Construye Tu Homelab — El Activo Más Valioso

Ninguna plataforma de práctica reemplaza tu propio laboratorio. El homelab te da libertad total para experimentar, romper cosas, y aprender de los errores.

Setup mínimo (una sola máquina con recursos moderados):

Hardware mínimo recomendado:
- CPU: 4+ cores (Intel/AMD modernos)
- RAM: 16GB (32GB ideal para AD labs)
- Storage: 500GB SSD
- Costo estimado: $200-600 USD en hardware usado

Software base (todo gratuito):
├── Hypervisor: VirtualBox o VMware Workstation (free)
├── Máquina atacante: Kali Linux o Parrot OS
├── Objetivos vulnerables:
│   ├── VulnHub machines (gratuitas)
│   ├── DVWA (Damn Vulnerable Web Application)
│   ├── GOAD (Active Directory lab)
│   └── Metasploitable 3
└── Defensa/monitoreo:
    ├── Wazuh SIEM (gratuito)
    ├── ELK Stack (gratuito)
    └── Security Onion (gratuito)

🌐 Comunidades y Recursos Permanentes

💬 Comunidades

📰 Newsletters y Blogs Obligatorios

🎙️ Podcasts


🔐 El Principio Zero Trust Aplicado a Tu Carrera

Como filosofía de vida profesional, Zero Trust se aplica perfectamente al desarrollo de carrera en ciberseguridad:

  • Never trust, always verify: No asumas que sabes algo solo porque lo leíste. Verifica en el lab.
  • Principio de mínimo privilegio: No intentes aprender todo a la vez. Profundiza en una dirección antes de expandir.
  • Segmentación: Separa tu entorno de aprendizaje de tus sistemas de trabajo/personal.
  • Monitoreo continuo: Documenta tu progreso. Un diario de aprendizaje + repos de GitHub con proyectos es tu mejor CV.
  • Assume breach: En los CTFs, asume que el objetivo está comprometido y trabaja desde ahí. En la vida real, asume que tu organización ya fue comprometida y diseña defensas acordemente.

🏁 Conclusión: El Mapa No Es el Territorio

Este roadmap es una guía, no una prisión. La ciberseguridad es uno de los campos más dinámicos que existen — lo que aprendes hoy puede volverse obsoleto en dos años, y nuevas áreas de especialización aparecen constantemente (AI security, quantum cryptography, satellite hacking, OT/ICS security).

Lo que nunca cambia:

  • 🧠 La mentalidad del atacante: Cómo piensa alguien que intenta comprometer un sistema
  • 🔍 La curiosidad estructurada: La habilidad de investigar cualquier tecnología desde cero
  • 📝 La comunicación técnica: Explicar hallazgos complejos de forma accionable
  • ⚖️ La ética: Saber dónde están las líneas — legales, morales, y profesionales

El mejor momento para empezar fue hace un año. El segundo mejor momento es ahora.

Elige tu camino, configura tu lab, y haz el primer CTF esta semana. El resto viene solo. 🚀


Escrito por Jafet Brito · Security Researcher · Zero Trust Mindset Recursos verificados y actualizados a junio de 2026.



🗺️ Complete OSINT & Cybersecurity Roadmap 2026: From Intermediate to Specialist

By Jafet Brito · Security Researcher · Published June 11, 2026


“Cybersecurity is not a destination. It is a direction.” — Zero Trust Philosophy

⚠️ Important note: This roadmap assumes you already have IT, networking, or basic Linux knowledge. If you’re starting from absolute zero, complete the CompTIA ITF+ or TryHackMe’s Pre-Security path first.


🧭 How to Read This Roadmap

This is not a linear roadmap — it’s a tree of paths with a common foundation and three specializations that converge at the advanced level:

📦 PHASE 0: Common Foundation (all paths)

   ┌────┴────┬─────────────┐
   ↓         ↓             ↓
🔍 OSINT   ⚔️ Red Team   🛡️ Blue Team
   ↓         ↓             ↓
   └────┬────┴─────────────┘

🎯 ADVANCED PHASE: Specialization & Convergence

📦 PHASE 0: The Foundation — What Every Specialist Must Know

⏱️ Estimated time: 2-4 months (if you already have an IT background) 🎯 Goal: Have the language, concepts, and work environment for any of the three paths

🖥️ 0.1 — Operating System: Linux as Mother Tongue

What you must master: Filesystem navigation, file manipulation (grep, awk, sed), permissions, networking from terminal, process management, basic Bash scripting.

Free resources:


🌐 0.2 — Networking: The Language the Internet Speaks

What you must master: OSI model, TCP/IP, addressing (IPv4, CIDR), fundamental protocols (TCP, UDP, DNS, HTTP/S, SSH, SMB), Wireshark/tcpdump/nmap, security concepts (firewalls, NAT, VPN).

Free resources:


🔐 0.3 — Core Security Concepts

What you must master: CIA Triad, attack types (phishing, MitM, SQL injection, XSS), basic cryptography (symmetric/asymmetric, hashing, TLS), MITRE ATT&CK, Cyber Kill Chain, OWASP Top 10.

Free resources:


🏅 Phase 0 Certification Options

CertificationCostFormatValue
CompTIA Security+~$400Theory + practicalHigh — DoD baseline, industry standard
ISC2 CCFree (1MCC initiative)Theory examMedium — best free entry point
CompTIA Network+~$380Theory examHigh — if networking background is weak

🔍 PATH A: OSINT — Open Source Intelligence

⏱️ Estimated time post-Phase 0: 3-6 months functional, 12+ months advanced 🎯 Target roles: OSINT Analyst, Threat Intelligence Analyst, Digital Investigator

🗺️ A.1 — The OSINT Intelligence Cycle

1. Planning      → What do I need to know? Requirements?
2. Collection    → Active/passive search of open sources
3. Processing    → Clean, normalize, structure raw data
4. Analysis      → Interpret, correlate, identify patterns
5. Dissemination → Communicate findings actionably
6. Feedback      → Adjust cycle based on results

Key concepts: Sock puppets & OPSEC, advanced search operators, Google/Bing Dorks, pivoting (email → domain → IP → person), ethics and legality.

Free resources:


🛠️ A.2 — OSINT Tool Stack by Category

Domains & Infrastructure: Shodan, Censys, crt.sh, DNSDumpster, SecurityTrails, VirusTotal, Wayback Machine

People & Social Media: Sherlock, Maigret, Hunter.io, SpiderFoot, Maltego, Social-Searcher

Images & Geolocation: Google Lens, PimEyes, FaceCheck.ID, ExifTool, GeoSpy AI, Google Earth Pro, Mapillary

See the Complete OSINT Tools Guide for full details, use cases, and tips on each.


📚 A.3 — Where to Practice OSINT


🏅 OSINT Certifications

CertIssuerCostLevel
GOSIGIAC/SANS~$949Mid — most recognized OSINT cert
PNPTTCM Security$400Mid — practical with real OSINT component
Certified OSINT ProfessionalOSMOSIS~$300Entry/Mid — OSINT-specific

⚔️ PATH B: Red Team & Pentesting

⏱️ Estimated time post-Phase 0: 6-12 months junior, 18-24 months mid-level 🎯 Target roles: Junior Penetration Tester, Red Team Operator, Bug Bounty Hunter

🗺️ B.1 — The Cyber Kill Chain

1. Reconnaissance        → OSINT, network scanning, enumeration
2. Weaponization         → Prepare payload/exploit
3. Delivery              → Email, web, USB, social engineering
4. Exploitation          → Execute exploit on target
5. Installation          → Establish persistence
6. C2 (Command & Control)→ Communication channel with target
7. Actions on Objectives → Exfiltration, lateral movement, impact

🛠️ B.2 — Red Team Technical Stack by Phase

Reconnaissance: Nmap, Masscan, theHarvester, Amass, Subfinder

Scanning & Enumeration: OpenVAS, Nikto, Gobuster/ffuf, Enum4linux, BloodHound (for AD)

Exploitation: Metasploit Framework, Burp Suite Community, SQLMap, Hydra/Hashcat, Responder

Post-Exploitation: Mimikatz, PowerView/SharpHound, CrackMapExec/NetExec, Cobalt Strike/Havoc C2


📚 B.3 — Red Team Practice Platforms

RECOMMENDED PROGRESSION:
TryHackMe → HackTheBox → PortSwigger → OffSec Labs
(Guided)    (Realistic)  (Web App)    (Certification)
  • 🎮 TryHackMe — Start here. Guided rooms. Generous free tier.
    • Recommended paths: Jr Penetration Tester, Red Teaming, Offensive Pentesting
  • 🎮 Hack The Box — Next level. Less guided, more realistic.
    • Recommended paths: Penetration Testing Job Role, Active Directory 101
  • 🌐 PortSwigger Web Security Academy100% free. Gold standard for web pentesting.
  • 🎮 VulnHub — Downloadable vulnerable VMs. Completely free.

🏅 Red Team Certifications — Full Map

ENTRY LEVEL (0-12 months practice):
├── eJPT (eLearnSecurity)     ~$200   Hands-on basics
├── CompTIA PenTest+          ~$400   Theory + practical
└── PJPT (TCM Security)       $30     Hands-on basics

MID LEVEL (1-2 years practice):
├── OSCP (OffSec)             $1,499  THE GOLD STANDARD
├── PNPT (TCM Security)       $400    Practical + report
└── GPEN (GIAC)               ~$949   Enterprise focus

ADVANCED (2+ years):
├── OSEP (OffSec)             ~$1,299 Evasion + AV bypass
├── CRTO (Zero-Point Security) £399   AD Red Team
├── OSWE (OffSec)             ~$1,299 Web Expert
└── GXPN (GIAC)              ~$949   Expert pentesting

💡 Career advice: The most respected 2026 path is eJPT/PJPT → OSCP → specialization (OSEP/CRTO/OSWE). OSCP remains the reference credential most employers require for pentesting roles.


🛡️ PATH C: Blue Team & SOC

⏱️ Estimated time post-Phase 0: 4-8 months for Tier 1 SOC, 12-18 months for Tier 2/3 🎯 Target roles: SOC Analyst, Threat Hunter, Incident Responder, Security Engineer

🗺️ C.1 — The NIST CSF Framework

├── Identify  → Asset inventory, risk management
├── Protect   → Preventive controls, segmentation, hardening
├── Detect    → Monitoring, alerting, threat hunting
├── Respond   → Incident response, containment, eradication
└── Recover   → Restoration, post-mortem, improvements

🛠️ C.2 — Blue Team Technical Stack

SIEM: Splunk (industry standard), Microsoft Sentinel (Azure/Microsoft shops), Elastic SIEM/ELK Stack (open source), Wazuh (free, great for homelabs)

Analysis & Detection: Zeek, Suricata, Volatility, Autopsy/Sleuth Kit, TheHive, MISP

Threat Hunting: Sigma Rules, MITRE ATT&CK Navigator, OpenCTI


📚 C.3 — Blue Team Practice Platforms


🏅 Blue Team Certifications — Full Map

ENTRY LEVEL (0-12 months):
├── CompTIA Security+    ~$400   Required baseline
├── CompTIA CySA+        ~$400   SOC-focused
└── BTL1 (Blue Team Labs) ~$500  Hands-on SOC

MID LEVEL (1-2 years):
├── Splunk Core Certified ~$130  SIEM standard
├── Microsoft SC-200      ~$165  Sentinel/Defender
├── GCIH (GIAC)          ~$949  Incident Handler
└── GCFE (GIAC)          ~$949  Digital Forensics

ADVANCED (2+ years):
├── GCIA (GIAC)          ~$949  Intrusion Analyst
├── GCTI (GIAC)          ~$949  Threat Intelligence
├── CISSP (ISC2)         ~$749  Management/Senior
└── CISM (ISACA)         ~$760  Security Manager

🎯 ADVANCED PHASE: Specialization & Convergence

🔬 Offensive Specialization

Active Directory Attack & Defense — 90% of Fortune 500 uses AD. Mandatory for serious Red Teamers.

Cloud Pentesting — AWS, Azure, GCP are the new perimeter.

Bug Bounty — Path to independent income.


🔬 Defensive Specialization

Threat Intelligence — Converting data to actionable intelligence.

  • 🌐 OpenCTI + MISP — Free open source TI stack
  • 🏅 Certs: GCTI, CREST CTI

DFIR — The most demanded role in 2026.


📅 Realistic Timeline

STARTING FROM INTERMEDIATE LEVEL (IT/networking/Linux basics):

Month 0-3:   Phase 0 Foundation
             + ISC2 CC (free) or CompTIA Security+

Month 3-6:   Start chosen path
             + TryHackMe path for your track
             + First entry-level certification

Month 6-12:  Technical deepening
             + HackTheBox (Red) / LetsDefend (Blue)
             + Mid-level cert (OSCP / BTL1)

Month 12-18: Portfolio + job applications
             + Documented personal projects
             + CTF participation and communities

Month 18-24+: Advanced specialization
              + Advanced certification for your track
              + Open source contributions

🏠 Build Your Homelab

Minimum recommended hardware:
- CPU: 4+ cores
- RAM: 16GB (32GB ideal for AD labs)
- Storage: 500GB SSD
- Estimated cost: $200-600 USD used hardware

Free software base:
├── Hypervisor: VirtualBox or VMware Workstation (free)
├── Attack machine: Kali Linux or Parrot OS
├── Vulnerable targets: VulnHub, DVWA, GOAD, Metasploitable 3
└── Defense/monitoring: Wazuh, ELK Stack, Security Onion (all free)

🌐 Communities & Permanent Resources

Communities: TryHackMe Discord, Hack The Box Discord, r/netsec, r/osint, Bellingcat Community

Must-read blogs/newsletters: Krebs on Security, Schneier on Security, SANS Reading Room, The DFIR Report, HackTricks

Podcasts: Darknet Diaries, Risky Business, SANS Internet Stormcast


🏁 Conclusion: The Map Is Not the Territory

This roadmap is a guide, not a prison. Cybersecurity is one of the most dynamic fields in existence. What never changes:

  • 🧠 The attacker’s mindset — How someone thinks when trying to compromise a system
  • 🔍 Structured curiosity — The ability to research any technology from scratch
  • 📝 Technical communication — Explaining complex findings actionably
  • ⚖️ Ethics — Knowing where the lines are — legal, moral, and professional

The best time to start was a year ago. The second-best time is now.

Choose your path, set up your lab, and complete your first CTF this week. The rest follows. 🚀


Written by Jafet Brito · Security Researcher · Zero Trust Mindset Resources verified and updated as of June 2026.