Roadmap: Pentesting, Security, Privacy and CTF/Bug Bounty¶
This roadmap explains how the modules connect, what learning paths are available, and how this topic fits into the broader leaps curriculum.
Table of Contents¶
- Learning Path Overview
- Module Dependencies
- Recommended Learning Paths
- Related Topic Connections
- Certification Alignment
Learning Path Overview¶
This topic is designed as a linear progression, but learners with existing experience can skip ahead with awareness of what they are missing. The map below shows the dependency relationships between modules.
flowchart TD
M01["01: Introduction\n(Ethics, Law, Lab Setup)"]
M02["02: Networking for Security\n(OSI, Protocols, Recon)"]
M03["03: Web Application Security\n(OWASP Top 10 Overview)"]
M04["04: SQL Injection\n(Classic, Blind, Parameterized)"]
M05["05: XSS and Client-Side\n(Stored, Reflected, DOM, CSP)"]
M06["06: Broken Access Control\n(IDOR, RBAC, JWT, Mass Assignment)"]
M07["07: Recon and OSINT\n(Passive, Active, Shodan, Dorking)"]
M08["08: Exploitation Basics\n(Burp Suite, Metasploit, CVE Research)"]
M09["09: Post-Exploitation\n(Priv Esc, Persistence, Lateral Movement)"]
M10["10: CTF Methodology\n(Categories, Strategy, Writeups)"]
M11["11: Bug Bounty Programs\n(Scope, Reports, CVSS, Disclosure)"]
M12["12: Capstone Project\n(Full Pentest Report)"]
M01 --> M02
M02 --> M03
M03 --> M04
M03 --> M05
M03 --> M06
M04 --> M08
M05 --> M08
M06 --> M08
M02 --> M07
M07 --> M08
M08 --> M09
M09 --> M10
M09 --> M11
M10 --> M12
M11 --> M12
Module dependency graph showing prerequisite relationships
Recommended Learning Paths¶
Path A: Complete Beginner (no security background)¶
Follow the modules in order: 01 → 02 → 03 → 04 → 05 → 06 → 07 → 08 → 09 → 10 → 11 → 12
Estimated time: 100–120 hours over 3–6 months
Path B: Developer or Sysadmin (networking/programming background)¶
You may start at Module 03 after reviewing Module 01 for ethics and legal requirements. Module 02 is still recommended if you have not studied networking from an attacker perspective.
Estimated time: 60–80 hours over 2–4 months
Path C: CTF Focus¶
Complete Modules 01–03, then jump to Module 10 for CTF methodology. Return to Modules 04–09 to fill in technical depth as you encounter those vulnerability classes in competitions.
Path D: Bug Bounty Focus¶
Complete Modules 01–08 thoroughly, then prioritize Module 11 (Bug Bounty Programs). Module 12's capstone pentest report is excellent preparation for professional bug bounty reporting.
Related Topic Connections¶
| Topic | Relationship |
|---|---|
| [[networks]] | Prerequisite — TCP/IP, DNS, HTTP fundamentals are assumed by Module 02+ |
| [[devops-platform-engineering]] | Extension — cloud attack surfaces, container escapes, CI/CD poisoning |
| [[python]] | Complement — scripting exploits, automating recon, writing custom tools |
| [[javascript-typescript-react]] | Complement — essential for understanding web application vulnerabilities |
Certification Alignment¶
This curriculum maps to the following industry certifications:
| Certification | Modules Most Relevant |
|---|---|
| CompTIA Security+ | 01, 02, 03, 07 |
| eJPT (eLearnSecurity Junior Penetration Tester) | 01–09 |
| OSCP (Offensive Security Certified Professional) | 01–12 (full curriculum) |
| CEH (Certified Ethical Hacker) | 01–11 |
| Web Application Hacker (BSCP — Burp Suite Certified Practitioner) | 03–06, 08 |
[!NOTE] Completing this leaps topic does not itself grant certification. Certifications require separate examination. This curriculum provides the foundational knowledge — the practical experience comes from hours spent on HackTheBox, TryHackMe, and real bug bounty programs.