LX5 SECURITY · STARTER PACK
The “I Know Nothing About Cybersecurity” Starter Pack
🔓 The “I Know Nothing About Cybersecurity” Starter Pack From confused → dangerous (in a good way) One-liner: Everything you need to go from “what’s a firewall?” to landing a real security job — games, free tools, career paths, and $0 training that actually slaps. 🗺️ Your Cheat Code Menu What you’re walking away with: A complete blueprint to learn hacking legally, protect yourself online, build a practice lab for free, get certified, and switch careers into a field paying $60K-$200K+ with a 500,000 worker shortage. 💡 Why This Matters (Zero Skills → Real Money) Cybersecurity has 469,930 job openings and not enough people to fill them — no degree required for most Free games and podcasts teach the same skills that $8,000 bootcamps charge for One certification (Security+) opens doors to $60K+ jobs — study materials are 100% free ✨ What’s Inside 🎮 Games that teach hacking (browser-based, zero install) 🎧 Podcasts that explain breaches like true crime stories 💻 Free labs you can run on any computer 📜 Certification roadmap with exact study plan 💰 Career switching guide for military, finance, healthcare backgrounds 🔴🔵 Red team vs blue team — which path fits your personality 🕵️ OSINT — finding anything about anyone using public info 💸 Bug bounties — get paid to hack companies legally 🛡️ Enterprise tools that cost $0 (same ones Fortune 500 uses)
PART 1: START HERE (ZERO EXPERIENCE) 🎮 Learn By Playing Games Skip the boring tutorials. These are actual games that teach real skills. 🕹️ Top 5 Games That Teach Security (Free, Browser-Based) 🎧 Podcasts That Explain Security Like True Crime 📺 YouTube Channels (Free Video Training) ⚡ 5-Minute Security Wins Do these today. Seriously. Takes 5 minutes each. Puts you ahead of 90% of people. Win Tool Time 1. Get a password manager Bitwarden (free, open-source) 5 min 2. Turn on 2FA everywhere Email, bank, social media 10 min 3. Install updates NOW Stop hitting “remind me later” 2 min 4. Hover before clicking Check where links actually go 0 min 5. VPN on public WiFi ProtonVPN (free tier) 3 min 📅 30-Day Challenge (Zero to Dangerous) Week Do This Week 1 Listen to 3 Darknet Diaries episodes Week 2 Complete KC7’s first investigation Week 3 Set up Bitwarden + enable 2FA on everything Week 4 Start TryHackMe “Pre Security” path Result: More secure than 90% of people. Foundation for everything else.
PART 2: CAPTURE THE FLAG (CTF) COMPETITIONS 🚩 What’s a CTF? Think escape room meets hacking puzzle. You solve challenges, find hidden “flags,” get points. Companies use CTF winners for hiring. It’s how people prove skills without degrees. 🏆 Best Beginner Platforms (Ranked) Rank Platform Link Why Start Here 1 PicoCTF picoctf.org Made by Carnegie Mellon for absolute beginners 2 TryHackMe tryhackme.com Guided paths, browser-based, badges 3 OverTheWire overthewire.org/wargames Classic Linux fundamentals 4 CTFlearn ctflearn.com Community challenges, easy filters 5 Hack The Box hackthebox.com “Starting Point” track for newbies 6 CryptoHack cryptohack.org Interactive cryptography 7 Hacker101 CTF ctf.hacker101.com Unlocks invites to paid bug bounties 🔄 Always-On Practice (No Deadlines) Platform Link Focus picoGym picoctf.org Archive of past challenges Root-Me root-me.org 470+ challenges RingZer0ctf ringzer0ctf.com Codebreaking to shellcoding pwnable.kr pwnable.kr Binary exploitation Cryptopals cryptopals.com 48 crypto challenges Crackmes crackmes.one Reverse engineering practice 📆 Annual Competitions Event Link When PicoCTF picoctf.org/competitions Spring US Cyber Open uscybergames.com Summer (has Beginner’s Game Room) CSAW CTF ctftime.org September Google CTF capturetheflag.withgoogle.com Summer (Beginner’s Quest) Find more: ctftime.org/event/list/upcoming 🧰 Essential CTF Tools (All Free) Tool Link What It Does CyberChef gchq.github.io/CyberChef Swiss army knife for data transformation Ghidra ghidra-sre.org NSA’s reverse engineering tool (yes, really) Wireshark wireshark.org See network traffic John the Ripper openwall.com/john Crack password hashes pwntools github.com/Gallopsled/pwntools Python exploit toolkit 💬 CTF Communities Community Link ImaginaryCTF Discord discord.com/invite/ctf (14,000+ members) Capture The Flag Discord discord.com/invite/V8UqnZ6JBG picoCTF Community picoctf.org/community.html Finding teams: CTFtime FAQ or Hopper’s Roppers guide
PART 3: GET CERTIFIED (Security+ Speedrun) 📜 Why Security+ First? Recognized by Department of Defense (required for many gov jobs) Often listed as “preferred” even when not required Opens doors to $60K+ entry roles All study materials can be 100% free ⏱️ Realistic Timeline Your Background Study Time IT experience 4-6 weeks Some tech background 6-8 weeks Complete beginner 8-12 weeks 📚 Free Study Resources (Ranked) 🎓 The Free Study Stack 📝 Free Practice Exams 💵 Exam Details Detail Info Questions Up to 90 Time 90 minutes Passing Score 750/900 (~83%) Cost $425 (but discounts exist) Get Discounts: CompTIA Academic Store → 40% off with student verification Professor Messer Vouchers → Discount + free Exam Hacks eBook 📊 What To Study Most Domain Weight Security Operations 28% ← focus here Threats/Vulnerabilities 22% Program Management 20% Security Architecture 18% General Concepts 12% 🚀 After Security+ Level Next Cert Focus Intermediate CySA+ SOC analyst, threat analysis Intermediate PenTest+ Penetration testing Advanced CASP+ Enterprise security Senior CISSP Requires 5+ years experience
PART 4: BUILD YOUR LAB ($0 BUDGET) 🏠 Why A Homelab? Practice breaking stuff without consequences Learn tools companies actually use Build portfolio proof Costs $0 with virtualization 💻 Free Virtualization Tool Link Best For VirtualBox virtualbox.org Beginners, any OS (FREE) Proxmox proxmox.com Dedicated server, web UI (FREE) VMware Player vmware.com Windows users (FREE personal) 🎯 Vulnerable Targets (Practice Hacking Legally) 📦 Pre-Built Vulnerable VMs 🥧 Raspberry Pi Projects ($35 computer) ☁️ Cloud Free Tiers (Skip Hardware Entirely) Provider Link Free Offer Oracle Cloud oracle.com/cloud/free BEST: 4 ARM CPUs, 24GB RAM — forever free AWS aws.amazon.com/free 750 hrs/month for 12 months Azure azure.microsoft.com/free $200 credit + 750 hrs VM Google Cloud cloud.google.com/free $300 credit for 90 days 🛡️ Enterprise Tools (Free Versions) 🔍 SIEM/XDR (Security Monitoring) 🚨 IDS/IPS (Intrusion Detection) 🖥️ Free EDR (Endpoint Detection)
PART 5: CAREER PATHS 🔴🔵 Red Team vs Blue Team Red Team = Offense (attackers, penetration testers) Blue Team = Defense (security analysts, incident responders) 💰 Salary Comparison 🧠 Personality Fit 📊 Job Availability Reality Check 🎓 Certification Paths 🔄 Career Switching Guide 🎖️ Military → Cybersecurity 💼 Finance/Accounting → GRC 👮 Law Enforcement → Cybersecurity 💼 Entry-Level Jobs (No Experience Required) Role Salary Job Search SOC Analyst Tier 1 $60,000-$75,000 Indeed GRC Analyst $60,000-$80,000 Indeed IT Help Desk (Security path) $45,000-$55,000 Indeed Security Administrator $55,000-$70,000 ZipRecruiter Career planning tool: CyberSeek Career Pathway — official US job market data 📄 Resume & Interview Prep Resource Link STAR Method for Cyber Resumes Transform responsibilities into achievements Resume Examples Entry to senior templates Common Interview Questions 9 questions with prep strategies 111 Interview Questions Comprehensive bank 🤝 Networking (Free Conferences) BSides Conferences = Community-run security cons. Usually $20-50. Every major city has one. Event Link BSides Directory Wikipedia List BSides NYC bsidesnyc.org BSides Chicago bsideschicago.org
PART 6: OSINT (Find Anything About Anyone) 🕵️ What’s OSINT? Open Source Intelligence = Finding info using publicly available sources. Used by journalists, investigators, and security researchers. No hacking. No illegal access. Just knowing where to look. 📚 Free Training 🎓 Courses & Guides 🛠️ Free OSINT Tools 🔧 The Essential Toolkit 🎯 Practice Challenges Platform Link Format Trace Labs CTF tracelabs.org/initiatives/search-party Real missing persons investigations TryHackMe OSINT Rooms tryhackme.com OhSINT, Sakura Room OSINT Dojo osintdojo.com Realistic scenarios GeoGuessr geoguessr.com Geolocation practice sourcing.games sourcing.games Tricky rabbit-hole challenges 💬 Communities Community Link Trace Labs Discord tracelabs.org/discord OSINT Curious Project discord.gg/exxBcKee Bellingcat Discord discord.gg/bellingcat 📺 OSINT YouTube Channels Channel Link OSINT Curious Project youtube.com/@OSINTCurious OSINT Dojo youtube.com/@osintdojo Sector035 youtube.com/@Sector035 🔍 Real Investigation Examples Source Link Notable Work Bellingcat bellingcat.com MH17, Navalny poisoning, Skripal case Trace Labs Blog tracelabs.org/blog Missing persons case studies
PART 7: BUG BOUNTIES (Get Paid To Hack) 💸 What Are Bug Bounties? Companies pay you to find security vulnerabilities in their systems. Legally. With permission. First year earnings: $0-500/month (steep learning curve) After 1-2 years: $2,000-5,000/month Top 5% hunters: Earn 50% of all bounties Millionaires: 6 hackers have earned $1M+ on HackerOne alone 🏆 Best Platforms (Ranked for Beginners) 📋 Platform Comparison Rank Platform Link Why Start Here 1 HackerOne hackerone.com Largest, includes Hacker101 training 2 Bugcrowd bugcrowd.com/hackers Bugcrowd University (free training) 3 Intigriti intigriti.com/researchers Best onboarding, EU-focused 4 YesWeHack yeswehack.com Built-in training, gamified 5 Open Bug Bounty openbugbounty.org Non-profit, good for learning 📚 Free Training 🎓 Learning Resources Resource Link Notes PortSwigger Web Security Academy portswigger.net/web-security BEST FREE RESOURCE — 190+ interactive labs Hacker101 hacker101.com HackerOne’s official course + CTF NahamSec Beginner Resources github.com/nahamsec Curated list TryHackMe tryhackme.com Gamified, browser-based 📖 Methodology Guides Guide Link Bug Bounty Methodology 2024 infosecwriteups.com zseano’s Methodology bugbountyhunter.com GitHub Checklist github.com/sehno/Bug-bounty 🧰 Essential Free Tools Tool Link Purpose Burp Suite Community portswigger.net/burp/communitydownload Web proxy (industry standard) OWASP ZAP zaproxy.org 100% free alternative Nuclei github.com/projectdiscovery/nuclei Template-based scanner ffuf github.com/ffuf/ffuf Fast web fuzzer Amass github.com/OWASP/Amass Subdomain enumeration 📺 YouTube Channels Channel Link Style NahamSec youtube.com/nahamsec Live hacking, interviews InsiderPhD youtube.com/InsiderPhD Beginner series STÖK youtube.com/STOKfredrik Bounty Thursdays LiveOverflow youtube.com/LiveOverflow Deep technical dives PwnFunction youtube.com/PwnFunction Animated vulnerability explanations 💬 Communities Community Link NahamSec Discord discord.com/invite/nahamsec Bug Bounty Forum bugbountyforum.com
PART 8: ADVANCED TOPICS 🟣 Purple Team Operations Red + Blue working together. Continuous testing and improvement. 📚 Purple Team Resources 🔍 Detection Engineering Writing rules that catch attackers. Platform-agnostic skills. 📚 Sigma & YARA Rules 📡 Threat Intelligence Turning threat data into action. 🧠 Threat Intel Resources 🏰 Zero Trust Architecture “Never trust, always verify” — continuous authentication everywhere. 📚 Zero Trust Resources ☁️ Cloud Security Certifications 🎓 Cloud Security Certs by Platform 🏢 GRC (Governance, Risk, Compliance) The business side of security. Policies, audits, frameworks. 💰 GRC Career Path 📋 Incident Response Playbooks Pre-defined procedures for when things go wrong. 📚 Playbook Resources 📊 SIEM Tool Comparison 🔧 Splunk vs Sentinel vs Elastic vs CrowdStrike
🚀 Your Action Plan This Week Create accounts: TryHackMe, PicoCTF, HackerOne Set up password manager (Bitwarden) Enable 2FA on everything Listen to 1 Darknet Diaries episode This Month Start Professor Messer Security+ videos Complete 5 TryHackMe beginner rooms Join 2 Discord communities Play KC7 Cyber Detective 90 Days Pass Security+ (or schedule exam) Build homelab with VirtualBox + DVWA Complete one CTF competition Apply to 10 entry-level positions Job market reality: 469,930 open positions 225,200 worker shortage 29% growth projected 2024-2034 No degree required for most roles The people who will be securing the future are learning right now. This guide has everything. The tools are free. The training is free. The jobs are waiting.