The โI Know Nothing About Cybersecurityโ Starter Pack
From confused โ dangerous (in a good way)
One-liner: Everything you need to go from โwhatโs a firewall?โ to landing a real security job โ games, free tools, career paths, and $0 training that actually slaps.
Your Cheat Code Menu
What youโre walking away with: A complete blueprint to learn hacking legally, protect yourself online, build a practice lab for free, get certified, and switch careers into a field paying $60K-$200K+ with a 500,000 worker shortage.
Why This Matters (Zero Skills โ Real Money)
- Cybersecurity has 469,930 job openings and not enough people to fill them โ no degree required for most
- Free games and podcasts teach the same skills that $8,000 bootcamps charge for
- One certification (Security+) opens doors to $60K+ jobs โ study materials are 100% free
Whatโs Inside
Games that teach hacking (browser-based, zero install)
Podcasts that explain breaches like true crime stories
Free labs you can run on any computer
Certification roadmap with exact study plan
Career switching guide for military, finance, healthcare backgrounds

Red team vs blue team โ which path fits your personality
OSINT โ finding anything about anyone using public info
Bug bounties โ get paid to hack companies legally
Enterprise tools that cost $0 (same ones Fortune 500 uses)
PART 1: START HERE (ZERO EXPERIENCE)
Learn By Playing Games
Skip the boring tutorials. These are actual games that teach real skills.
๐น๏ธ Top 5 Games That Teach Security (Free, Browser-Based)
| Game |
Link |
What You Learn |
| KC7 Cyber Detective |
kc7cyber.com |
Investigate breaches like a detective โ Microsoft Wall of Fame winner |
| TryHackMe |
tryhackme.com |
Guided hacking missions with badges and leaderboards |
| OverTheWire Bandit |
overthewire.org/wargames |
Learn command line from level 0 โ progressive difficulty |
| ThreatGEN Red vs Blue |
threatgen.com |
Play as attacker OR defender โ actual game engine |
| SpaceShelter (Google) |
spacesheltergame.withgoogle.com |
Online safety basics disguised as space adventure |
Why games work: 60% higher completion rate than courses. 30-40% better retention. Youโre having fun while your brain absorbs real skills.
๐ง Podcasts That Explain Security Like True Crime
Start with: Darknet Diaries episodes on the Xbox Underground or NotPetya โ you wonโt stop listening.
๐บ YouTube Channels (Free Video Training)
5-Minute Security Wins
Do these today. Seriously. Takes 5 minutes each. Puts you ahead of 90% of people.
| Win |
Tool |
Time |
| 1. Get a password manager |
Bitwarden (free, open-source) |
5 min |
| 2. Turn on 2FA everywhere |
Email, bank, social media |
10 min |
| 3. Install updates NOW |
Stop hitting โremind me laterโ |
2 min |
| 4. Hover before clicking |
Check where links actually go |
0 min |
| 5. VPN on public WiFi |
ProtonVPN (free tier) |
3 min |
30-Day Challenge (Zero to Dangerous)
| Week |
Do This |
| Week 1 |
Listen to 3 Darknet Diaries episodes |
| Week 2 |
Complete KC7โs first investigation |
| Week 3 |
Set up Bitwarden + enable 2FA on everything |
| Week 4 |
Start TryHackMe โPre Securityโ path |
Result: More secure than 90% of people. Foundation for everything else.
PART 2: CAPTURE THE FLAG (CTF) COMPETITIONS
Whatโs a CTF?
Think escape room meets hacking puzzle. You solve challenges, find hidden โflags,โ get points. Companies use CTF winners for hiring. Itโs how people prove skills without degrees.
๐ Best Beginner Platforms (Ranked)
๐ Always-On Practice (No Deadlines)
๐ Annual Competitions
Find more: ctftime.org/event/list/upcoming
๐งฐ Essential CTF Tools (All Free)
๐ฌ CTF Communities
Finding teams: CTFtime FAQ or Hopperโs Roppers guide
PART 3: GET CERTIFIED (Security+ Speedrun)
Why Security+ First?
- Recognized by Department of Defense (required for many gov jobs)
- Often listed as โpreferredโ even when not required
- Opens doors to $60K+ entry roles
- All study materials can be 100% free
Realistic Timeline
| Your Background |
Study Time |
| IT experience |
4-6 weeks |
| Some tech background |
6-8 weeks |
| Complete beginner |
8-12 weeks |
Free Study Resources (Ranked)
๐ The Free Study Stack
Professor Messer Extras (FREE):
๐ Free Practice Exams
Exam Details
| Detail |
Info |
| Questions |
Up to 90 |
| Time |
90 minutes |
| Passing Score |
750/900 (~83%) |
| Cost |
$425 (but discounts exist) |
Get Discounts:
What To Study Most
| Domain |
Weight |
| Security Operations |
28% โ focus here |
| Threats/Vulnerabilities |
22% |
| Program Management |
20% |
| Security Architecture |
18% |
| General Concepts |
12% |
After Security+
| Level |
Next Cert |
Focus |
| Intermediate |
CySA+ |
SOC analyst, threat analysis |
| Intermediate |
PenTest+ |
Penetration testing |
| Advanced |
CASP+ |
Enterprise security |
| Senior |
CISSP |
Requires 5+ years experience |
PART 4: BUILD YOUR LAB ($0 BUDGET)
Why A Homelab?
- Practice breaking stuff without consequences
- Learn tools companies actually use
- Build portfolio proof
- Costs $0 with virtualization
Free Virtualization
| Tool |
Link |
Best For |
| VirtualBox |
virtualbox.org |
Beginners, any OS (FREE) |
| Proxmox |
proxmox.com |
Dedicated server, web UI (FREE) |
| VMware Player |
vmware.com |
Windows users (FREE personal) |
Vulnerable Targets (Practice Hacking Legally)
๐ฆ Pre-Built Vulnerable VMs
One-line Docker setup:
docker run --rm -it -p 80:80 vulnerables/web-dvwa # DVWA
docker run --rm -p 3000:3000 bkimminich/juice-shop # Juice Shop
docker run -p 8080:8080 webgoat/webgoat # WebGoat
๐ฅง Raspberry Pi Projects ($35 computer)
Cloud Free Tiers (Skip Hardware Entirely)
Enterprise Tools (Free Versions)
๐ SIEM/XDR (Security Monitoring)
Setup guides:
๐จ IDS/IPS (Intrusion Detection)
| Tool |
Link |
Best For |
| Suricata |
suricata.io |
High-speed, multi-threaded |
| Snort |
snort.org |
Industry standard, huge rule library |
| Zeek |
zeek.org |
Network forensics |
| OSSEC |
ossec.net |
Host-based detection |
๐ฅ๏ธ Free EDR (Endpoint Detection)
PART 5: CAREER PATHS

Red Team vs Blue Team
Red Team = Offense (attackers, penetration testers)
Blue Team = Defense (security analysts, incident responders)
๐ฐ Salary Comparison
| Path |
Entry Level |
Experienced |
| Blue Team (SOC Analyst) |
$60,000-$75,000 |
$80,000-$150,000+ |
| Red Team (Pentester) |
$60,000-$86,000 |
$90,000-$120,000+ |
| Purple Team (Both) |
$111,000-$195,000 |
18% salary premium |
๐ง Personality Fit
| Choose Red Team If Youโฆ |
Choose Blue Team If Youโฆ |
| Love breaking things |
Prefer building/protecting |
| Thrive on variety |
Excel at pattern recognition |
| Think like a criminal |
Handle routine monitoring well |
| Prefer creativity |
Strong collaboration skills |
| Handle time pressure |
Data-driven decisions |
๐ Job Availability Reality Check
- 469,930 cybersecurity job postings annually
- 225,200 worker shortage
- Blue team SOC openings: 10,000+ at any time
- Entry pentester openings: Very limited
Verdict: Blue team is significantly easier to break into. Red team usually requires 2-5 years security experience first.
๐ Certification Paths
Blue Team:
- Entry: Security+, ISC2 CC
- Mid: CySA+, GCIA, BTL1
- Advanced: GCIH, GCFA, CISSP
Red Team:
- Entry: PenTest+, CEH, eJPT
- Mid: OSCP (gold standard), GPEN
- Advanced: CRTO, OSCE, GXPN
Career Switching Guide
๐๏ธ Military โ Cybersecurity
๐ผ Finance/Accounting โ GRC
Finance backgrounds crush it in GRC (Governance, Risk, Compliance). You already understand audits, regulations, risk assessment.
GRC Salary Range: $78K (entry) โ $200K+ (CISO)
๐ฎ Law Enforcement โ Cybersecurity
Entry-Level Jobs (No Experience Required)
| Role |
Salary |
Job Search |
| SOC Analyst Tier 1 |
$60,000-$75,000 |
Indeed |
| GRC Analyst |
$60,000-$80,000 |
Indeed |
| IT Help Desk (Security path) |
$45,000-$55,000 |
Indeed |
| Security Administrator |
$55,000-$70,000 |
ZipRecruiter |
Career planning tool: CyberSeek Career Pathway โ official US job market data
Resume & Interview Prep
Networking (Free Conferences)
BSides Conferences = Community-run security cons. Usually $20-50. Every major city has one.
PART 6: OSINT (Find Anything About Anyone)
Whatโs OSINT?
Open Source Intelligence = Finding info using publicly available sources. Used by journalists, investigators, and security researchers.
No hacking. No illegal access. Just knowing where to look.
Free Training
๐ Courses & Guides
| Resource |
Link |
Notes |
| Security Blue Team - Intro to OSINT |
securityblue.team |
Gamified + capstone projects |
| My OSINT Training |
myosint.training |
From industry expert Micah Hoffman |
| The Cyber Mentor - OSINT in 4.5 Hours |
YouTube |
Comprehensive free course |
| DFIR Diva Directory |
training.dfirdiva.com |
Curated training list |
Free OSINT Tools
๐ง The Essential Toolkit
Practice Challenges
Communities
OSINT YouTube Channels
Real Investigation Examples
PART 7: BUG BOUNTIES (Get Paid To Hack)
What Are Bug Bounties?
Companies pay you to find security vulnerabilities in their systems. Legally. With permission.
- First year earnings: $0-500/month (steep learning curve)
- After 1-2 years: $2,000-5,000/month
- Top 5% hunters: Earn 50% of all bounties
- Millionaires: 6 hackers have earned $1M+ on HackerOne alone
Best Platforms (Ranked for Beginners)
๐ Platform Comparison
Free Training
๐ Learning Resources
Methodology Guides
Essential Free Tools
YouTube Channels
Communities
PART 8: ADVANCED TOPICS
Purple Team Operations
Red + Blue working together. Continuous testing and improvement.
๐ Purple Team Resources
Salary premium: Purple team earns 18% more than pure red/blue roles.
Detection Engineering
Writing rules that catch attackers. Platform-agnostic skills.
๐ Sigma & YARA Rules
Sigma = Detects log events (generic, converts to any SIEM)
YARA = Detects files/malware (pattern matching)
Threat Intelligence
Turning threat data into action.
๐ง Threat Intel Resources
Key stat: SOCs see 11,000 alerts/day average. Only 19% worth investigating.
Zero Trust Architecture
โNever trust, always verifyโ โ continuous authentication everywhere.
๐ Zero Trust Resources
ROI: Forrester study shows 234% ROI, 44% cost reduction vs legacy systems.
Cloud Security Certifications
๐ Cloud Security Certs by Platform
| Platform |
Certification |
Cost |
| AWS |
Security - Specialty |
$300 |
| Azure |
AZ-500 Security Engineer |
$165 |
| GCP |
Professional Cloud Security Engineer |
$200 |
| Vendor-Neutral |
CCSP (ISCยฒ) |
$599 |
| Vendor-Neutral |
CCSK (Cloud Security Alliance) |
$395 |
Salary impact: AWS AI certs bring up to 47% salary increase.
GRC (Governance, Risk, Compliance)
The business side of security. Policies, audits, frameworks.
๐ฐ GRC Career Path
| Level |
Role |
Salary |
| Entry |
GRC Analyst |
$78,000 |
| Mid |
Risk Specialist |
$85,000-$110,000 |
| Senior |
GRC Manager |
$120,000-$180,000 |
| Executive |
CISO |
$142,000-$200,000+ (Fortune 500: $1M+) |
Key cert: ISCยฒ CGRC (Certified in Governance, Risk & Compliance)
Growth driver: 3% job growth 2024-2034, driven by regulatory complexity + AI ethics oversight.
Incident Response Playbooks
Pre-defined procedures for when things go wrong.
๐ Playbook Resources
Key stat: Median attacker dwell time: 10 days (Mandiant M-Trends 2024)
SIEM Tool Comparison
๐ง Splunk vs Sentinel vs Elastic vs CrowdStrike
| Tool |
Best For |
Cost Model |
Learning Curve |
| Splunk |
Large enterprises, flexibility |
Per GB ingested (expensive) |
Steep |
| Microsoft Sentinel |
Microsoft shops, Azure-native |
Per GB (free for M365 logs) |
Medium |
| Elastic Security |
Open-source, customization |
Open-source or cloud |
Steep |
| CrowdStrike Falcon |
EDR-first, fast deployment |
Per endpoint |
Easy |
Key differentiator: Sentinel shows 234% ROI with 85% cheaper data lake tier (2025).
Your Action Plan
This Week
- Create accounts: TryHackMe, PicoCTF, HackerOne
- Set up password manager (Bitwarden)
- Enable 2FA on everything
- Listen to 1 Darknet Diaries episode
This Month
- Start Professor Messer Security+ videos
- Complete 5 TryHackMe beginner rooms
- Join 2 Discord communities
- Play KC7 Cyber Detective
90 Days
- Pass Security+ (or schedule exam)
- Build homelab with VirtualBox + DVWA
- Complete one CTF competition
- Apply to 10 entry-level positions
Job market reality:
- 469,930 open positions
- 225,200 worker shortage
- 29% growth projected 2024-2034
- No degree required for most roles
The people who will be securing the future are learning right now.
This guide has everything. The tools are free. The training is free. The jobs are waiting.
Start today. Bookmark this. Come back when stuck.