Think you're being attacked right now? →
Refreshed 1 October 2026

Loadout

A route through learning to break and defend systems properly, rebuilt at the start of every month. Fifteen places, in the order they actually make sense. No account, no email, no course to buy.

> current edition — September 2026

How to use this
  • Start at the route below rather than the sections. The sections are the library; the route is the path through it.
  • Pick one thing and finish it. Six half-finished platforms teach you less than one completed path.
  • Everything here is free to start. Where a paid tier exists it is marked, and none of it is needed to get value.
What changed this month
  • First edition. The route, the fifteen entries and the monthly pick are all new.
  • Every URL was checked on 22 September 2026 before this went up.
The route

Six steps, in this order

The sections below are the library. This is the path through it. Most people fail at this by starting at step three, getting beaten, and concluding they are not clever enough.

  1. 01

    Get comfortable at a command line

    Everything after this assumes it. OverTheWire's Bandit is the shortest honest route there, and it costs nothing but evenings.

    Start with: OverTheWire — Bandit

  2. 02

    Learn how the web actually breaks

    Most real intrusions start in a browser. PortSwigger's Academy is free, structured, and the labs are the real thing rather than a quiz.

    Start with: PortSwigger Web Security Academy

  3. 03

    Break something end to end

    Reading stops teaching you at some point. A full machine, start to finish, is where it turns into a skill.

    Start with: Hack The Box

  4. 04

    Turn round and defend

    The half that pays in Australia, and the half almost nobody practises. Investigate an attack instead of running one.

    Start with: CyberDefenders

  5. 05

    Write it up

    The finding is worth nothing until someone else can act on it. Every platform above has a write-up culture - join it.

    Start with: Blue Team Labs Online

  6. 06

    Then compete

    When practice stops stretching you, a real competition will. Not before - starting here just demoralises people.

    Start with: CTFtime

This month, if you only do one thing

PortSwigger Web Security Academy

If you do one thing this month, do this. Free, written by the people who build Burp Suite, and the labs are real rather than multiple choice. Most of what an attacker does to a small business starts in a browser, and this is the best free explanation of that on the internet.

Time to expect: 40+ hours if you finish it. Worth every one.

01 — Start from nothing

No background assumed. Open these if you have never done this and do not want to be humiliated in the first ten minutes.

  • OverTheWire — Bandit free

    Thirty-odd levels that teach the Linux command line by making you need it.

    After it Move around a Linux box without looking up every command.

    Time 10-15 hours

  • TryHackMe free tier

    Guided paths that hold your hand and then let go.

    After it Follow an attack from first access to full control, with the reasoning explained.

    Time A few hours a week, ongoing

  • picoCTF free

    Built for school students, which is exactly why it is the gentlest introduction to how a CTF feels.

    After it Know whether you enjoy this before spending money on it.

    Time A weekend

02 — The web, properly

Where most real intrusions begin, and the part people skip because machines are more fun.

  • PortSwigger Web Security Academy free

    Free, structured, and the labs are the real thing rather than a quiz.

    After it Explain and demonstrate the attacks that actually put small businesses on the news.

    Time 40+ hours

  • OWASP Juice Shop free

    A deliberately insecure web application you run yourself. Open source, no account, no queue.

    After it Practise offline, on your own machine, with nothing to sign up for.

    Time 10-20 hours

  • PayloadsAllTheThings free

    The payload reference everyone has bookmarked and nobody admits to.

    After it Recognise a technique when you see it, instead of pasting one you do not understand.

    Time Reference

03 — Machines to break

Full systems, attacked end to end. This is where the reading turns into a skill.

  • Hack The Box free tier

    The big one. Retired machines plus community write-ups are the highest-value combination on the site.

    After it Take a machine from nothing to administrator and explain every step.

    Time 4-12 hours per machine

  • VulnHub free

    Downloadable vulnerable VMs you run in your own lab. No subscription, no queue, works offline.

    After it Practise without internet, on hardware you control.

    Time 3-8 hours per box

  • pwn.college free

    University-grade material, free and public. Harder than it looks and worth the bruises.

    After it Understand why an exploit works rather than that it does.

    Time Months, honestly

04 — Defending, not just breaking

The half that actually pays in this country, and the half almost nobody practises. That is the opportunity.

  • CyberDefenders free tier

    Blue-team labs built on real artefacts - packet captures, memory images, log sets.

    After it Reconstruct what an attacker did from what they left behind.

    Time 3-6 hours per lab

  • LetsDefend free tier

    A simulated SOC queue. Closer to a real analyst's day than anything else on this list.

    After it Triage an alert under time pressure without freezing.

    Time A few hours a week

  • Blue Team Labs Online free tier

    Investigations rather than puzzles, and you have to write up what you found.

    After it Produce a finding somebody else can act on. This is the part that gets you hired.

    Time 2-5 hours per investigation

05 — Tabs you will never close

Reference, not training. Open them once and they stay open for the rest of your career.

  • HackTricks free

    The methodology notebook. When you are stuck, this is usually where the next idea comes from.

    After it Have somewhere to go at 1am when nothing is working.

    Time Reference

  • GTFOBins free

    Trusted Unix binaries and what they can be talked into doing. Short, brutal, essential.

    After it Spot a privilege escalation path in a list of installed software.

    Time Reference

  • LOLBAS free

    The Windows counterpart. If you learn one thing about living-off-the-land attacks, learn this list.

    After it Understand why blocking scripts is not the same as blocking attackers.

    Time Reference

When practice stops being enough

CTFtime

Every competition worth entering, with a calendar and archived write-ups. When practice stops being enough, start here.

What this page is, and is not

This is a reading list, not a service and not a course. Nothing on it is sold by IN-SEC, nothing on it pays us, and there are no affiliate links — the moment a link pays for its place, the page stops being worth reading.

There is no email gate on this page and there never will be. No form, no account, no "enter your address to see the list". If something is worth giving away, give it away.

The picks change on the first of each month. If a link here has gone stale or you think something belongs on it, tell us: enquiries@in-sec.org.

Practise on systems you own or have been given written permission to test. Everything listed here provides its own legal target environment, which is the entire point of using it rather than someone else's network.

Running a business rather than a lab?

Different problem, same person. If an insurer, a client or your bank has asked you a security question you cannot answer yet, that is a twenty-minute conversation.

Book a 20-minute call