The ultimate path: a 24-week program
This is the overview for a 90-minute day, five days per week. The weekly learner plan is the calendar of record, including each week's lab and promotion evidence. The planner may reorder a week only when prerequisite evidence and the assessment rubric justify it.
This is a proposed curriculum, not 24 finished weeks of material. Check the content and coverage map before choosing a lesson; introductory lessons do not yet supply the full teaching depth or native labs required by every track.
Weekly rhythm
| Day | Work | Evidence |
|---|---|---|
| 1 | New concept and prediction | one-page model |
| 2 | Small lab experiment | redacted transcript |
| 3 | Variation and failure case | comparison table |
| 4 | Detection, defense, or code review | tested hypothesis |
| 5 | Teach-back and retrieval review | five-minute explanation |
Reserve 20 minutes for retrieval, 15 for study, 40 for the lab step, and 15 for writing. If a lab overruns, carry it forward; never mark it complete to preserve the calendar.
Progression
| Weeks | Module | Required outcome |
|---|---|---|
| 1 | Orientation and foundations | scope a lab and distinguish observation, inference, and proof |
| 2 | Linux and operating systems | explain processes, permissions, files, and isolation |
| 3 | Networking | trace DNS, routing, TCP, and HTTP failures |
| 4–5 | Windows and Active Directory | model objects, tokens, policy, and trust |
| 6 | Kerberos and identity | diagram ticket flow and authorization boundaries |
| 7–8 | Lateral movement | compare protocols, prerequisites, and telemetry |
| 9 | Detection and response | reproduce a harmless event and test a detection hypothesis |
| 10–11 | Web application security | test a local vulnerable app and write a bounded finding |
| 12 | Programming and automation | build a small parser with tests and safe defaults |
| 13–14 | Cloud and containers | reason about identity, policy, images, and namespaces |
| 15–16 | Reverse engineering and malware | perform static-first analysis in an isolated lab |
| 17 | Wireless and embedded systems | produce a passive assessment and identify the missing device-specific lab |
| 18 | SCADA and industrial security | model the control system, decode the synthetic trace, and investigate an unexpected command |
| 19 | OSINT and human factors | triangulate claims without collecting personal data |
| 20 | Threat hunting | turn behavior into telemetry and test false positives |
| 21 | DFIR and incident response | preserve evidence and build a timeline |
| 22 | AI security and supply chain | evaluate prompt/data/tool boundaries locally |
| 23 | Cryptography and secure engineering | review primitives, keys, dependencies, and invariants |
| 24 | Capstone | reproduce a complete authorized investigation and teach it |
Promotion gates
Move to the next phase only when the previous phase has a reviewed model, a reproducible bounded lab, a defensive implication, and a teach-back. A failed experiment is valid evidence when the explanation identifies the missing prerequisite. The assessment rubric defines the score required for promotion.