A Security Curriculum, Not a Pile of Links
Most "learn cybersecurity" advice hands you a reading list and wishes you luck. h4cker, maintained by security author and educator Omar Santos, is organized the other way round: thousands of curated references, tools, scripts and labs grouped by domain, so you start at the landing page for your goal and follow a path.
What It Covers
Ethical hacking and pen-testing, bug bounties, DFIR, networking, Linux, AI security, and cert prep for OSCP, CEH and PenTest+. Books, courses, tools and hands-on labs — including intentionally vulnerable applications packaged in Docker, so you have somewhere legitimate to practise.
It works at every level: fundamentals, then pen-testing with labs, then exploit development and certifications.
The Rule That Makes It Legitimate
The repo is for authorized and ethical use only. Practise on the vulnerable labs it ships, on CTF platforms, or on systems you own or have written permission to test. That boundary isn't a formality — it's the entire difference between security work and a criminal offence, and the material itself is explicit about it.
What's in the Guide
The domains it covers, the beginner-to-advanced path through them, what the Docker labs give you, and a direct link to the repo. Free and MIT licensed.
The full field guide is in the PDF.
Get the Guide
Drop your email below and we'll send it straight to your inbox.