How to Start Ethical Hacking in 2026, Beginner Roadmap | Techonquer

Beginner Roadmap 2026
Six steps from zero to your first bug bounty report
No certification pressure, no tool worship. This is the order that actually works, with honest timelines, the exact skills each stage needs, and the mistakes that cost beginners the most months.
6 steps
Fundamentals to bug bounty
4 to 6 months
Realistic, with weekly practice
Zero
Prior experience required
Before you start
Who this roadmap is for

This is written for someone with no security background. A college student, a working professional switching tracks, or a self taught learner who has watched a lot of videos and still cannot explain what they can actually do.

  • What you need a laptop with 8 GB RAM, an internet connection, and six to ten focused hours a week
  • What you do not need a computer science degree, an expensive certification, or a high end machine
  • What this is not a shortcut. Anyone promising a security job in thirty days is selling something
Read this firstEthical means authorised. Testing a system you do not own, without written permission, is an offence under the Information Technology Act in India and under similar laws elsewhere. Everything in this roadmap happens inside your own lab or inside programs that invited you.
Step 013 to 4 weeks
Learn the fundamentals

Almost everyone skips this and regrets it around month three. Burp Suite and Nmap only make sense once you understand what a request, a port and a permission actually are. Without fundamentals, every tool becomes magic you cannot debug.

Networking
  • The TCP/IP model, and where HTTP, DNS, SSH and SMB sit in it
  • TCP versus UDP, the three way handshake, and why a scan can say filtered
  • DNS records, A, CNAME, MX, TXT, and how subdomain resolution works
  • Common ports and the services behind them, 21, 22, 25, 53, 80, 139, 443, 445, 3306, 3389
  • NAT, private address ranges, and what your home router is actually doing
Linux
  • File system layout, etc, var, home, tmp, and what lives where
  • Users, groups, file permissions, SUID and why it matters for privilege escalation
  • Processes, services, cron jobs, and reading logs
  • Core commands, grep, find, awk, sed, curl, ssh, and writing a basic bash loop
Web basics
  • The full request and response cycle, methods, status codes, headers
  • Cookies, sessions and tokens, and how a site knows who you are
  • HTML, a little JavaScript, and how forms send data
  • What a web server, an application server and a database each do
One scripting language
  • Python is the standard pick. Variables, loops, functions, file handling, requests library
  • Goal is automation, not software engineering. If you can loop over a wordlist and send requests, that is enough for now
CheckpointYou can explain, out loud, everything that happens between typing a URL and the page appearing. You can navigate a Linux box without searching for every command. If not, stay here a little longer. This month saves you three later.
Common mistakeJumping to Kali Linux in week one. Kali is a toolbox. Without fundamentals you will run tools, get output you cannot interpret, and conclude that you are bad at this.
Step 022 to 3 days
Set up your lab

You need a place where breaking things is allowed and free. That means virtual machines on your own laptop, not a friend's website and not an IP you found in a Shodan search.

Your attack machine
  • Kali Linux or Parrot OS, running inside VirtualBox or VMware Workstation Player, both free
  • Give it 4 GB RAM minimum, 8 GB if your host can spare it, and 60 GB disk
  • Install guest additions so copy paste and screen resizing work, you will use both constantly
Your targets
  • Metasploitable 2 deliberately vulnerable Linux box, good for network level practice
  • DVWA classic web vulnerability playground with difficulty levels
  • OWASP Juice Shop modern JavaScript app, far closer to what real targets look like today
  • A Windows evaluation VM for Active Directory and Windows privilege escalation later
Network and hygiene
  • Put every vulnerable VM on a host only network so it is never reachable from the internet
  • Take a snapshot right after each clean install, so a broken exploit costs two minutes, not two hours
  • Keep one shared folder for notes and one for tools, and back the notes folder up
CheckpointYour Kali VM can ping your target VM, your host cannot be reached from either, and you have a snapshot you can roll back to. That is a working lab.
If your laptop is weakBrowser based labs remove the VM requirement entirely. You can do the whole of Step 03 without installing anything, and come back to local VMs later.
Step 03Every week, from now on
Practice on real labs

This is where the actual learning happens. Reading about SQL injection teaches you the definition. Solving a box that has one teaches you how to find it when nobody told you it was there.

Where to practise, in order
  • TryHackMe guided rooms built for people starting from nothing. Follow a learning path rather than random rooms
  • Hacklido Labs browser based CTF and lab environment at learn.hacklido.com, no VM setup needed, good for daily practice
  • PortSwigger Web Security Academy free, and the best structured web vulnerability labs that exist
  • Hack The Box move here once you can work without step by step hints. Start with retired easy machines and read the official writeups after you try
  • CTF events weekend competitions. Start in the web category, and read other people's writeups afterwards, that is where most of the value is
How to practise so it sticks
  • One machine or one lab, properly, beats five machines followed along with a video
  • Give yourself a time box. Stuck for forty minutes, then read the hint. Stuck for two hours with no progress teaches nothing
  • After every box, write down what you tried, what failed, and what finally worked
CheckpointYou have solved at least ten easy machines or lab sets on your own, and you have written notes for each of them. Those notes become Step 05.
Common mistakeWatching walkthrough videos while solving. It feels productive and teaches almost nothing. Try first, fail properly, then watch.
Step 044 to 6 weeks
Learn hacking concepts

Now the vulnerabilities themselves. Learn the class of bug first and the tool second, because tools get deprecated and rewritten while the underlying logic stays the same for decades.

Core vulnerability classes
  • Injection SQL injection, command injection, template injection. The common thread is untrusted input reaching an interpreter
  • Cross site scripting reflected, stored and DOM based, and why output encoding is the real fix
  • Broken access control IDOR, forced browsing, horizontal and vertical privilege escalation. This class pays the most in bug bounty
  • SSRF making the server request things on your behalf, and why cloud metadata endpoints matter
  • File handling unrestricted upload, path traversal, local file inclusion
  • Authentication and logic flaws OTP bypass, weak password reset, race conditions, rate limit gaps
Tools worth real time
  • Burp Suite proxy, repeater, intruder, decoder, comparer. Learn this one deeply, it is your main workspace
  • Nmap host discovery, service and version detection, and the scripting engine
  • ffuf or dirsearch content discovery, parameter fuzzing, virtual host discovery
  • sqlmap for confirming and exploiting injection you already found manually
  • Wireshark for actually seeing traffic instead of imagining it
  • subfinder, amass, httpx for recon once you start on real scope
The methodology that ties it together
  • Recon, map the attack surface before touching anything
  • Enumerate, list every endpoint, parameter, role and feature
  • Test, one vulnerability class at a time across the whole surface
  • Exploit and escalate, prove real impact rather than stopping at a pop up
  • Document as you go, screenshots and requests, not from memory afterwards
CheckpointGiven a login page and a dashboard, you can list ten things you would test and explain why each one might break. That is methodology, and it is what interviews probe.
Step 05Ongoing
Build real skills and proof

Nobody can see what you know. They can only see what you documented. This step turns a person who watched tutorials into a person who gets interview calls.

What to build
  • Writeups one per machine or challenge you solve, published on a blog, Medium or GitHub. Twenty writeups is a portfolio
  • A real report pick one lab finding and write it in professional format, title, severity with CVSS, steps to reproduce, impact, remediation, references
  • A small tool a subdomain checker, a header auditor, a wordlist cleaner. Simple is fine, working is the point
  • A public profile GitHub with clean READMEs, and a LinkedIn that shows work instead of claiming passion
Report writing, the skill nobody practises
  • Reports are most of the actual job. A pentester who finds bugs but writes badly gets fewer clients
  • Write impact in business terms. Not an IDOR exists, but any logged in user can read every other customer's invoices
  • Steps to reproduce must work for someone who has never seen the app
  • Always suggest a fix. It is what separates a report from a complaint
CheckpointYou can hand someone a link with ten writeups and one full report. At entry level, that is worth more than any single certificate.
Step 06Month 4 onwards
Start bug hunting

Bug bounty is where your practice meets real targets, legally. It is also where beginners quit fastest, because the early months are mostly duplicates and informatives.

How to start properly
  • Pick one platform HackerOne, Bugcrowd or Intigriti, and filter for programs that welcome new hunters
  • Read the scope every single time out of scope testing gets you banned, not paid
  • Go narrow and deep one program, one vulnerability class, for weeks. Shallow scanning of a hundred targets finds nothing that has not already been reported
  • Hunt where automation is weak business logic, access control, and multi step flows. Scanners cannot understand intent
  • Report well clear title, reproducible steps, honest impact, and a suggested fix
What the first year actually looks like
  • Months of duplicates and informatives before the first accepted bug is normal
  • Your first payout is usually small. The value is the validation and the writeup you can now show
  • Most people who quit, quit in the first three months, right before it starts working
Reality checkBug bounty is not a stable first income. Treat it as practice on real targets and as portfolio material while you apply for SOC, VAPT or security analyst roles. The job pays the bills, the bounties build the name.
Planning
A realistic six month schedule

This assumes six to ten focused hours a week. Faster is possible with more hours, but the order does not change.

Period
Focus
Month 1
Networking, Linux and web fundamentals. Lab setup in the last week
Month 2
Guided labs daily, first ten easy machines, notes for every one
Month 3
OWASP Top 10 in depth, Burp Suite deeply, PortSwigger labs
Month 4
Methodology practice, harder machines, first published writeups, first bug bounty program
Month 5
Full practice report, portfolio cleanup, resume with real evidence, start applying
Month 6
Interview preparation, continued hunting, pick a specialisation
After the roadmap
Where this leads

Ethical hacking is one door into a wide field. Once you have fundamentals plus lab evidence, these are the common first roles and where each one goes next.

SOC Analyst
Defensive. SIEM, alert triage, incident response. Highest number of entry level openings in India
VAPT Analyst
Offensive. Web and network penetration testing, client reports, consulting firms hire heavily
Application Security
Code review, secure SDLC, working alongside developers. Pays well, needs coding comfort
Cloud Security
AWS and Azure misconfigurations, IAM, container security. Fastest growing demand
Threat Intelligence
OSINT, IOC analysis, MITRE ATT and CK mapping, adversary tracking
AI Security
Prompt injection, model abuse, LLM red teaming. New field, very few experienced people
Certifications
When certificates actually help

Certificates open HR filters. They do not replace skill, and taking one too early is the most common money mistake beginners make.

  • Months 1 to 3 none. Spend the money on lab subscriptions instead
  • Offensive path OSCP is still the one hiring managers recognise for penetration testing roles
  • Defensive path a SOC oriented certification plus practical SIEM experience matters more than a generic security cert
  • Compliance and GRC ISO 27001 and similar, useful if you are heading towards audit and risk work
  • Whatever you pick, take it after you can already do the work, not as a way to learn it
Stuck on which step you are actually on?

Most people are further along than they think on theory and further behind than they think on practice. Send us where you are and we will tell you the next thing to do, not a sales pitch.

Common questions
Do I need a degree to get into ethical hacking?
No. Entry level security hiring cares about demonstrable skill, and most managers will take a candidate with solid lab writeups over one with only a certificate. A degree helps clear HR filters at large companies, it is not a gate on the skill itself.
Which certification should I start with?
None for the first three months. Build fundamentals and lab experience first, then choose a certification that matches the role you want. OSCP for offensive roles, a SOC focused track for defensive ones.
How long until I can get a job?
Four to eight months of steady weekly practice to be interview ready for an entry level SOC or junior penetration testing role. That assumes real hands on work, not passive video watching.
Do I need an expensive laptop?
No. 8 GB RAM and an SSD will run one attack VM and one target VM comfortably. Browser based labs remove even that requirement while you are starting out.
Is ethical hacking legal in India?
Testing systems you own or have written authorisation for is legal. Testing anything else, including scanning a site out of curiosity, can fall under the Information Technology Act. Stay inside your own lab and inside the scope of authorised bug bounty programs.
Should I learn programming first?
Not a full programming course. Enough Python to automate repetitive tasks, and enough JavaScript to read what a web page is doing. Deeper coding becomes important later if you move towards application security.
Can I learn ethical hacking for free?
Yes. TryHackMe free rooms, PortSwigger Web Security Academy, browser based labs and public writeups cover the entire roadmap. Paid training buys structure, feedback and speed, not secret knowledge.
This roadmap is educational. Only test systems you own or are explicitly authorised to test.