How to Start Ethical Hacking in 2026, Beginner Roadmap | Techonquer
This is written for someone with no security background. A college student, a working professional switching tracks, or a self taught learner who has watched a lot of videos and still cannot explain what they can actually do.
- What you need a laptop with 8 GB RAM, an internet connection, and six to ten focused hours a week
- What you do not need a computer science degree, an expensive certification, or a high end machine
- What this is not a shortcut. Anyone promising a security job in thirty days is selling something
Almost everyone skips this and regrets it around month three. Burp Suite and Nmap only make sense once you understand what a request, a port and a permission actually are. Without fundamentals, every tool becomes magic you cannot debug.
- The TCP/IP model, and where HTTP, DNS, SSH and SMB sit in it
- TCP versus UDP, the three way handshake, and why a scan can say filtered
- DNS records, A, CNAME, MX, TXT, and how subdomain resolution works
- Common ports and the services behind them, 21, 22, 25, 53, 80, 139, 443, 445, 3306, 3389
- NAT, private address ranges, and what your home router is actually doing
- File system layout, etc, var, home, tmp, and what lives where
- Users, groups, file permissions, SUID and why it matters for privilege escalation
- Processes, services, cron jobs, and reading logs
- Core commands, grep, find, awk, sed, curl, ssh, and writing a basic bash loop
- The full request and response cycle, methods, status codes, headers
- Cookies, sessions and tokens, and how a site knows who you are
- HTML, a little JavaScript, and how forms send data
- What a web server, an application server and a database each do
- Python is the standard pick. Variables, loops, functions, file handling, requests library
- Goal is automation, not software engineering. If you can loop over a wordlist and send requests, that is enough for now
You need a place where breaking things is allowed and free. That means virtual machines on your own laptop, not a friend's website and not an IP you found in a Shodan search.
- Kali Linux or Parrot OS, running inside VirtualBox or VMware Workstation Player, both free
- Give it 4 GB RAM minimum, 8 GB if your host can spare it, and 60 GB disk
- Install guest additions so copy paste and screen resizing work, you will use both constantly
- Metasploitable 2 deliberately vulnerable Linux box, good for network level practice
- DVWA classic web vulnerability playground with difficulty levels
- OWASP Juice Shop modern JavaScript app, far closer to what real targets look like today
- A Windows evaluation VM for Active Directory and Windows privilege escalation later
- Put every vulnerable VM on a host only network so it is never reachable from the internet
- Take a snapshot right after each clean install, so a broken exploit costs two minutes, not two hours
- Keep one shared folder for notes and one for tools, and back the notes folder up
This is where the actual learning happens. Reading about SQL injection teaches you the definition. Solving a box that has one teaches you how to find it when nobody told you it was there.
- TryHackMe guided rooms built for people starting from nothing. Follow a learning path rather than random rooms
- Hacklido Labs browser based CTF and lab environment at learn.hacklido.com, no VM setup needed, good for daily practice
- PortSwigger Web Security Academy free, and the best structured web vulnerability labs that exist
- Hack The Box move here once you can work without step by step hints. Start with retired easy machines and read the official writeups after you try
- CTF events weekend competitions. Start in the web category, and read other people's writeups afterwards, that is where most of the value is
- One machine or one lab, properly, beats five machines followed along with a video
- Give yourself a time box. Stuck for forty minutes, then read the hint. Stuck for two hours with no progress teaches nothing
- After every box, write down what you tried, what failed, and what finally worked
Now the vulnerabilities themselves. Learn the class of bug first and the tool second, because tools get deprecated and rewritten while the underlying logic stays the same for decades.
- Injection SQL injection, command injection, template injection. The common thread is untrusted input reaching an interpreter
- Cross site scripting reflected, stored and DOM based, and why output encoding is the real fix
- Broken access control IDOR, forced browsing, horizontal and vertical privilege escalation. This class pays the most in bug bounty
- SSRF making the server request things on your behalf, and why cloud metadata endpoints matter
- File handling unrestricted upload, path traversal, local file inclusion
- Authentication and logic flaws OTP bypass, weak password reset, race conditions, rate limit gaps
- Burp Suite proxy, repeater, intruder, decoder, comparer. Learn this one deeply, it is your main workspace
- Nmap host discovery, service and version detection, and the scripting engine
- ffuf or dirsearch content discovery, parameter fuzzing, virtual host discovery
- sqlmap for confirming and exploiting injection you already found manually
- Wireshark for actually seeing traffic instead of imagining it
- subfinder, amass, httpx for recon once you start on real scope
- Recon, map the attack surface before touching anything
- Enumerate, list every endpoint, parameter, role and feature
- Test, one vulnerability class at a time across the whole surface
- Exploit and escalate, prove real impact rather than stopping at a pop up
- Document as you go, screenshots and requests, not from memory afterwards
Nobody can see what you know. They can only see what you documented. This step turns a person who watched tutorials into a person who gets interview calls.
- Writeups one per machine or challenge you solve, published on a blog, Medium or GitHub. Twenty writeups is a portfolio
- A real report pick one lab finding and write it in professional format, title, severity with CVSS, steps to reproduce, impact, remediation, references
- A small tool a subdomain checker, a header auditor, a wordlist cleaner. Simple is fine, working is the point
- A public profile GitHub with clean READMEs, and a LinkedIn that shows work instead of claiming passion
- Reports are most of the actual job. A pentester who finds bugs but writes badly gets fewer clients
- Write impact in business terms. Not an IDOR exists, but any logged in user can read every other customer's invoices
- Steps to reproduce must work for someone who has never seen the app
- Always suggest a fix. It is what separates a report from a complaint
Bug bounty is where your practice meets real targets, legally. It is also where beginners quit fastest, because the early months are mostly duplicates and informatives.
- Pick one platform HackerOne, Bugcrowd or Intigriti, and filter for programs that welcome new hunters
- Read the scope every single time out of scope testing gets you banned, not paid
- Go narrow and deep one program, one vulnerability class, for weeks. Shallow scanning of a hundred targets finds nothing that has not already been reported
- Hunt where automation is weak business logic, access control, and multi step flows. Scanners cannot understand intent
- Report well clear title, reproducible steps, honest impact, and a suggested fix
- Months of duplicates and informatives before the first accepted bug is normal
- Your first payout is usually small. The value is the validation and the writeup you can now show
- Most people who quit, quit in the first three months, right before it starts working
This assumes six to ten focused hours a week. Faster is possible with more hours, but the order does not change.
Ethical hacking is one door into a wide field. Once you have fundamentals plus lab evidence, these are the common first roles and where each one goes next.
Certificates open HR filters. They do not replace skill, and taking one too early is the most common money mistake beginners make.
- Months 1 to 3 none. Spend the money on lab subscriptions instead
- Offensive path OSCP is still the one hiring managers recognise for penetration testing roles
- Defensive path a SOC oriented certification plus practical SIEM experience matters more than a generic security cert
- Compliance and GRC ISO 27001 and similar, useful if you are heading towards audit and risk work
- Whatever you pick, take it after you can already do the work, not as a way to learn it
Most people are further along than they think on theory and further behind than they think on practice. Send us where you are and we will tell you the next thing to do, not a sales pitch.