Learn how computers talk to each other before you learn how to break them: networking, the Linux command line and how the web works come first, and tools come after. Most beginners stall because they do it the other way round, installing Kali, running tools they don’t understand, and getting results they can’t interpret.
This is an ordering guide. It tells you what to learn first, what to postpone, and what to skip entirely, with exercises you can run in a lab today.
Legal note: only test systems you own or have written permission to test. Everything below targets your own lab, or
scanme.nmap.org, which the Nmap project allows for light test scans.
What is ethical hacking, in one paragraph?
Ethical hacking is using an attacker’s techniques, with permission and within an agreed scope, to find weaknesses before real attackers do. The permission is what makes it ethical and legal. In a professional setting it usually takes the form of a penetration test, which follows a methodology (planning, discovery, attack and reporting are the phases in NIST’s SP 800-115 technical testing guide) and ends with a report someone can act on. If that’s the career you’re after, our guide on how to become a penetration tester covers the job itself.
The learn-first, learn-later, skip list
| Learn first | Learn later | Skip (for now or for good) |
|---|---|---|
| TCP/IP, ports, DNS, HTTP | Active Directory attacks | Memorising lists of 100 tools |
| Linux command line | Exploit development and buffer overflows | “Hacking” Wi-Fi you don’t own |
| How web apps work: requests, cookies, sessions | Cloud and container attacks | Anonymity rabbit holes (Tor chains, VPN stacking) |
| Nmap, properly | Writing your own tools | Courses that are only tool demos |
| Burp Suite or ZAP basics | Mobile app testing | “Hack any phone” videos |
| The OWASP Top 10 | Evasion and red-team tradecraft | Exam dumps |
| Writing clear notes and reports | Advanced certifications | Buying a “hacking laptop” |
The “learn later” column isn’t unimportant. It’s simply much easier once the first column is solid. The “skip” column is either a distraction, illegal, or both.
Step 1: networking, because every attack crosses a network
You need to understand, without looking it up:
- What an IP address and a subnet are, and why
192.168.1.0/24contains 256 addresses. - What a port is, and the difference between TCP and UDP.
- Common services and their default ports: SSH (22), HTTP (80), HTTPS (443), SMB (445), RDP (3389), DNS (53).
- What DNS does and how a domain becomes an IP address.
- What happens, step by step, when your browser loads a page.
A quick self-test once your lab from Step 3 is running (here the lab’s DNS server is 10.10.10.1 and the target web app is juice.lab.test): run these and explain every line of output.
$ dig +short juice.lab.test @10.10.10.1
10.10.10.5
$ curl -sI http://juice.lab.test:3000 | head -4
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
If you can explain what dig asked for and who answered, what 200 OK means, and what each of those headers is for, you’re ready to move on.
Step 2: Linux, because your tools live there
You don’t need to be a Linux administrator. You need to move around, read files, find things and understand permissions. Practise until these feel natural:
$ pwd
/home/learner
$ ls -la ~/lab
total 16
drwxr-xr-x 2 learner learner 4096 Oct 10 10:02 .
drwxr-x--- 9 learner learner 4096 Oct 10 10:01 ..
-rw-r--r-- 1 learner learner 311 Oct 10 10:02 notes.md
-rwxr-xr-x 1 learner learner 198 Oct 10 10:02 sweep.sh
$ grep -i “password” ~/lab/notes.md
- check web app login for default password
$ ss -tlnp
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
LISTEN 0 511 127.0.0.1:8080 0.0.0.0:* users:((“python3”,pid=2142,fd=3))
Know what rwx means, what sudo does, how to use pipes (|), and how to read a short Bash script. That covers a surprising amount of day-to-day testing work.
Step 3: build a lab before you touch any tools
You need somewhere legal to practise. A laptop with 8 GB of RAM (16 GB is more comfortable) can run an attacker machine and one or two deliberately vulnerable targets in VirtualBox on a host-only network. Our guide to building a cybersecurity home lab walks through free and low-cost setups.
Good beginner targets:
- OWASP Juice Shop, a deliberately insecure web shop maintained by OWASP.
- PortSwigger’s Web Security Academy, free browser-based labs, with no local setup needed.
- Deliberately vulnerable virtual machines from reputable sources, running only on an isolated network.
Step 4: Nmap, properly
Nmap is the first real tool to learn because it answers the first real question: what is running here? Learn it deeply rather than learning ten scanners shallowly. The Nmap reference guide is excellent, and the project explains the legal issues around scanning clearly.
A light, permitted scan against the Nmap project’s own test host:
$ nmap -sV -p 22,80 scanme.nmap.org
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:15 WAT
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.19s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.7 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.42 seconds
Versions can change over time, so your output may differ. Then do the same against your own lab:
$ sudo nmap -sS -sV -p- --min-rate 1000 10.10.10.5
Nmap scan report for 10.10.10.5
Host is up (0.00041s latency).
Not shown: 65532 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0)
80/tcp open http nginx 1.18.0 (Ubuntu)
3000/tcp open ppp?
Now the important part, which tools can’t do for you: interpret it. Port 3000 shows ppp? because Nmap couldn’t match the service fingerprint confidently, so you check it by hand:
$ curl -s http://10.10.10.5:3000 | grep -o "<title>.*</title>"
<title>OWASP Juice Shop</title>
That’s the habit that separates ethical hackers from tool operators: don’t trust a label, verify it.
Step 5: web applications, the biggest attack surface you’ll meet
For many organisations, the most exposed systems are web applications and APIs. Learn:
- How HTTP requests and responses work: methods, headers, cookies, status codes.
- How sessions and authentication work, and how they fail.
- The OWASP Top 10, as categories of risk rather than a checklist to memorise.
- An intercepting proxy, Burp Suite Community Edition or OWASP ZAP, to see and modify traffic between your browser and the app.
A first proper exercise: set up Burp with Juice Shop, log in with a test account, and find where your session token lives. Then try to view another user’s basket by changing an ID in the request. If it works, you’ve found an insecure direct object reference, one of the most common real-world findings, and you understand why it worked.
What to skip, and why
Memorising tool lists. Distributions ship hundreds of tools; working testers use a small core set well. Learn the categories (scanning, proxying, password attacks, exploitation frameworks) and one solid tool in each.
Wi-Fi “hacking” first. It’s a niche skill, it requires specific hardware, and practising on networks you don’t own is illegal. Learn it later, on your own access point, if a role calls for it.
Anonymity obsession. Ethical hackers work with permission and usually from known IP addresses agreed with the client. Hiding is not part of the job.
Exploit development before fundamentals. Buffer overflows and assembly are fascinating and worth learning eventually. As a first topic, they’ll stall you for months.
Exam dumps. Apart from being against certifying bodies' policies, they produce people who can pass a test but can’t do the work, and interviews find that out quickly.
A 16-week roadmap at about eight hours a week
| Weeks | Focus | You can do this by the end |
|---|---|---|
| 1–3 | Networking fundamentals | Explain how a page loads; read dig, curl and ping output |
| 4–5 | Linux command line | Navigate, search files, read permissions, write a 10-line Bash script |
| 6 | Lab build | Attacker VM plus Juice Shop on an isolated network |
| 7–8 | Nmap | Scan your lab, explain every open port, verify services by hand |
| 9–12 | Web testing | Use Burp or ZAP; work through beginner Web Security Academy labs |
| 13–14 | Methodology | Map what you’ve done to MITRE ATT&CK tactics; follow a testing process end to end |
| 15–16 | Reporting | Write a professional report on one lab target: findings, evidence, risk, fix |
The reporting weeks aren’t optional. A finding nobody understands doesn’t get fixed, and a clear report is what clients pay for.
How do I know I’m making progress?
You’re on track when you can:
- Look at a scan result and say what you’d test next, and why.
- Explain a vulnerability to a non-technical person in two sentences.
- Reproduce a finding from your notes a week later.
- Spend an hour stuck without giving up, then find the answer in documentation rather than a walkthrough.
If the volume of material feels overwhelming, read is cybersecurity hard to learn?. The short version: it’s broad rather than impossibly deep, and it gets easier once the foundations click.