farhanashrafdev/90DaysOfCyberSecurity

This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, covering topics such as Network+, Security+, Linux, Python, Traffic Analysis, Git, ELK, AWS, Azure, and Hacking. The repository also includes a `LEARN.md

cybersecurityethical-hackingcommunityexchangelearnhacktoberfest
Croissance des étoiles
Étoiles
19.2k
Forks
2.2k
Croissance hebdomadaire
+247
Issues
3
5k10k15k
janv. 2023mars 2024juin 2025sept. 2026
README

90-Day Cybersecurity Study Plan

All Contributors

farhanashrafdev%2F90DaysOfCyberSecurity | Trendshift

📚 Table of Contents

📘 Introduction

Welcome to the 90 Days of Cybersecurity challenge!
This repository provides a structured, 90-day self-paced study plan designed to help learners build a strong foundation in cybersecurity. Whether you're a beginner looking to break into the field or a professional aiming to sharpen your skills, this roadmap offers a wide range of curated resources, hands-on tasks, and learning materials.

The daily modules cover essential and advanced topics, including:

  • Networking fundamentals (Network+)
  • Security principles (Security+)
  • Linux basics and shell scripting
  • Python programming for security tasks
  • Traffic analysis and packet inspection
  • Version control with Git
  • SIEM tools and log analysis using the ELK stack
  • Cloud security with GCP, AWS and Azure
  • Penetration testing and ethical hacking
  • Landing the job: a one-page resume and an AI-assisted job-search pipeline with career-ops

Each day is designed with actionable tasks, tutorials, and reading materials to help you stay on track. For a full list of resources, refer to learn.md.

🎯 Goals and Audience

📌 Goals

The primary goal of this 90-day plan is to help learners:

  • Build a solid foundation in core cybersecurity concepts and practices.
  • Gain hands-on experience through daily exercises and real-world tools.
  • Develop the technical skills necessary for certifications such as CompTIA Network+ and Security+.
  • Explore key domains including network security, system hardening, cloud security, scripting, and ethical hacking.
  • Cultivate a consistent learning habit over 90 days to support long-term retention and growth.

By the end of this journey, you should feel confident navigating a variety of cybersecurity tools, concepts, and techniques.

👥 Intended Audience

This repository is ideal for:

  • Aspiring cybersecurity professionals preparing for entry-level roles or certifications.
  • IT professionals transitioning into a security-focused career.
  • Students studying computer science, information systems, or network engineering.
  • Self-learners seeking a structured and comprehensive study plan.
  • Developers and DevOps engineers looking to better understand secure infrastructure and threat detection.
  • Anyone curious about how cybersecurity works in real-world environments.

No prior experience is required, though basic familiarity with computers, networks, or programming will be helpful.

🚀 Start Here

New to the plan? Read this first, then jump to Day 1.

  • Time budget: aim for 1-2 focused hours a day. The day numbers are a guide, not a deadline; it is fine to spend longer on a topic.
  • Follow the order: Days 1-28 (networking, security basics, Linux) are the foundation everything else builds on. Do not skip ahead to hacking.
  • Certifications are optional: the Network+ and Security+ playlists teach the concepts you need. You do not have to sit the exams to follow this plan or to get a first job.
  • Track your progress: fork this repo (or copy the plan into a notes file) and tick off each day as you finish it.
  • Everything is free: if a site puts content behind a paywall, use the alternatives listed in the same section or in learn.md.
  • Questions or study buddies: use GitHub Discussions. Issues are for broken links and content fixes.
  • Prefer another language? See Translations.

Day 1-7: Network+

  • Watch videos from Professor Messer's N10-009 Playlist
  • Complete any related practice questions or exercises.

Day 8-14: Security+

Strongly Recommend Professor Messer's:

Another Alternative You Can Use:

Additional Practice:

  • Complete any related practice questions or exercises.

Day 15-28: Linux

Day 29-42: Python

Youtube Course:

Day 43-56: Traffic Analysis

Youtube:

Day 57-63: Git

Day 64-70: ELK

Day 71-77: Cloud Platforms

Any one of them works fine.

GCP:

AWS

Azure

Day 78-84: Review and Practice

  • Go back through Days 1-77 and review any weak areas.
  • Complete hands-on challenges on TryHackMe: https://tryhackme.com
  • Set up a home lab using VirtualBox or VMware to practice what you have learned.
  • Try building a small project that combines networking, Linux, Python, and security concepts.

Day 85-90: Hacking

Youtube:

Day 91-92: One Page Resume

Day 93-95: Where and How to Apply

Run your job search with career-ops

career-ops is a free, open-source job-search system that runs inside an AI coding CLI such as Claude Code, Codex, OpenCode, GitHub Copilot CLI or Antigravity CLI (free tier, no API key needed). Paste a job URL and it scores the posting against your cv.md (1-5), generates an ATS-friendly tailored PDF and tracks every application in one place. It never applies for you; you always review and submit.

Before using any AI CLI, redact sensitive personal data in cv.md (for example address/phone) and review the tool/provider’s privacy and data-retention settings before pasting your resume content.

  1. Set up (Day 93): install Node.js, skim the setup guide, then run npx @santifer/career-ops init. Good security habit: npx downloads and runs the latest release, so check the release notes before running it (pin a version with @santifer/career-ops@<version> if you want a reproducible install). Open your AI CLI in the new career-ops folder and follow the onboarding chat. Tell it your target roles (for example SOC analyst, security analyst, junior penetration tester) so the evaluations fit entry-level security jobs.
  2. Evaluate (Day 94): paste 10-20 postings you found on Indeed or LinkedIn. Only apply to roles that score 4.0/5 or higher; treat it as a filter, not a spray-and-pray tool.
  3. Apply and prepare (Day 95): generate tailored CVs for your shortlist, apply, and use the interview-prep mode to build your STAR stories before the first call.

Translations

🎉 Contributors

Thank you for being a part of the 90DaysOfCyberSecurity community! We appreciate everyone who helps improve our content.

Contribution Categories:

  • Documentation: Improve or add to the study material and guides.
  • Tutorials & Guides: Create or enhance tutorials explaining complex concepts.
  • Suggested Resources: Recommend useful tools, articles, books, or other resources.
  • Ideas / Topics: Suggest new topics to be added to the learning materials.
  • Review & Feedback: Provide feedback on existing materials and suggest improvements.
  • Community Support: Answer questions and help others in discussions or issues.
  • Tests & Quizzes: Add quizzes, challenges, or tests to check learning progress.
  • Real-World Applications: Share real-life examples or case studies of cybersecurity practices.
  • Mentoring: Help others with study advice, tips, or hosting study sessions.

Thank you to all contributors for your amazing work! 🎉

Contributors ✨

Thanks goes to these wonderful people (emoji key):

Farhan Ashraf
Farhan Ashraf

📖
Wanderer479
Wanderer479

📖
Muhammad Mahad
Muhammad Mahad

📖
André Oliveira
André Oliveira

📖
arbenp
arbenp

📖 🐛
paduh
paduh

📖
Emmanuel Ferdman
Emmanuel Ferdman

🐛 📖
King Triton
King Triton

📖 🌍
Mr
Mr

🎨 💡
Parth Dinesh Mane
Parth Dinesh Mane

💬
LUser-12
LUser-12

🤔

This project follows the all-contributors specification. Contributions of any kind welcome!

Dépôts similaires
sherlock-project/sherlock

Hunt down social media accounts by username across social networks

PythonPyPIcliMIT Licenseosintreconnaissance
sherlockproject.xyz
91.1k10.7k
usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

PythonPyPIApache License 2.0agentsartificial-intelligence
strix.ai
61.4k6.7k
WerWolv/ImHex

🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.

C++GNU General Public License v2.0hex-editorreverse-engineering
imhex.werwolv.net
54.8k2.5k
x64dbg/x64dbg

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

C++Otherdebuggerwindows
x64dbg.com
49.5k2.8k
KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

TypeScriptnpmGNU Affero General Public License v3.0penetration-testingpentesting
keygraph.io
47.9k5.5k
soxoj/maigret

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

PythonPyPIcliMIT Licenseosintsocial-network
maigret.app/gh
37.4k2.9k
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

PythonPyPIskillApache License 2.0ai-agentsclaude-code
mahipal.engineer/Anthropic-Cybersecurity-Skills/
32.4k3.9k
The-Art-of-Hacking/h4cker

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

Jupyter NotebookawesomeMIT Licensehackingpenetration-testing
hackerrepo.org
29.3k5.4k
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

GoGo ModulesGNU General Public License v3.0firewallhttp-flood
ly.safepoint.cloud/fUxS0GW
22.5k1.5k
lissy93/personal-security-checklist

🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2026

TypeScriptnpmawesomeOtherprivacysecurity
digital-defense.io
22.3k1.5k
Lissy93/personal-security-checklist

🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2024

TypeScriptnpmawesomeOtherprivacysecurity
digital-defense.io
22.2k1.5k
smicallef/spiderfoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

PythonPyPIappMIT Licensefootprintingosint
spiderfoot.net
22k3.5k