30 resources · 30 free
Cyber Security
Protect systems and data — ethical hacking, network security, and security fundamentals.
Certified Cloud Security Professional (CCSP) (Coursera, Infosec)
Coursera (Infosec): CCSP certification prep — cybersecurity basics, all 6 CCSP domains (architecture, data security, platform/infrastructure security, application security, operations, legal/compliance), exam essentials. 8 modules, ~2 weeks at 10h/week.
AI Security (Coursera, Infosec)
Coursera (Infosec): AI fundamentals, building AI, responsible AI, existing and emerging laws, AI governance and risk management, AI security and privacy. 6 modules, ~8 hours, flexible schedule.
TryHackMe
Gamified cyber security training platform with hundreds of hands-on rooms covering beginner security basics, network pentesting, web hacking, and defensive blue-team topics. You learn by completing guided virtual-machine labs directly in your browser. Ideal for absolute beginners and students wanting structured, practical progression. Trusted by millions of learners and widely used in universities and bootcamps. Free tier includes many core rooms; a subscription unlocks the full library.
OverTheWire Bandit
Classic free wargame that teaches Linux command line and security fundamentals through 30+ levels played over SSH. Each level is a small puzzle teaching shell skills, file permissions, and basic exploitation concepts. Perfect for beginners learning terminal basics before moving to offensive security. A long-running community institution in security education.
Hack The Box
Popular hands-on platform with vulnerable machines, CTF-style challenges, and a large hacking community. The free tier gives access to a starter set of machines, challenges, and Academy basics, letting you practice real pentesting techniques against intentionally vulnerable targets. Suited to learners with some basics who want realistic practice. Widely referenced in security job postings and used by thousands of professionals for skill-building.
picoCTF
Free capture-the-flag competition and learning platform created by Carnegie Mellon University for beginners. Solve puzzles across cryptography, web exploitation, forensics, binary exploitation, and reverse engineering, with guided picoGym practice rooms available year-round. Designed for middle and high school students but great for any newcomer. Backed by an elite university with a large global player community.
Cybrary
Online cyber security training platform with video courses covering Security+, ethical hacking, SOC analysis, and cloud security. You learn via structured video lessons, labs, and practice exams, with many courses available free. Good for career-changers preparing for certifications. One of the largest cyber training catalogs, with millions of registered learners.
SANS Cyber Aces Online
Free open courseware from the SANS Institute, the global leader in cyber security training, teaching operating systems, networking, and system administration fundamentals. Each module combines tutorials, videos, and quizzes you can complete at your own pace with no registration. Perfect for people exploring security careers before paying for formal training. Rare free access to a world-class professional curriculum, maintained as a philanthropic program.
OWASP Top 10
The de-facto standard awareness document of the ten most critical web application security risks, maintained by the Open Worldwide Application Security Project. You learn how injection, broken access control, and other top risks work and how to mitigate them. Essential reading for developers, testers, and pentesters alike. Backed by a global non-profit and cited across the industry.
PortSwigger Web Security Academy
Free, world-class web security training with detailed learning paths for every major vulnerability class, from SQL injection to SSRF. Each topic pairs an in-depth tutorial with interactive lab exercises running in your browser. Aimed at beginners and working pentesters sharpening web skills. Created by PortSwigger, the makers of Burp Suite, and free to everyone.
Professor Messer Security+ Videos
Complete free video course covering every objective of the CompTIA Security+ exam, plus pop-quiz videos and downloadable study notes. You learn core security domains: threats, attacks, architecture, operations, and risk management. Ideal for certification candidates and career-changers studying on a budget. One of the most trusted free exam-prep resources, with millions of views.
NCSC Guidance
Authoritative cyber security guidance library from the UK National Cyber Security Centre, including Cyber Essentials, secure configuration advice, and incident management playbooks. You learn practical defence measures used by governments and businesses. Ideal for professionals and small organisations implementing security baselines. Official guidance from the UK's national technical authority.
r/netsec Wiki
Community-curated wiki from Reddit's r/netsec, a leading network security subreddit, collecting recommended books, courses, podcasts, tools, and career advice. You get vetted starting points chosen by working security practitioners. Great for newcomers overwhelmed by options. Aggregates the collective recommendations of hundreds of thousands of security professionals.
Prove your interest
Unlock this bonus resource by showing you are serious.
OWASP Juice Shop
Intentionally insecure web application designed for security training, with more than 100 hacking challenges spanning injection, XSS, broken authentication, and API flaws. You practice real attacks locally or on the hosted demo, with a learning-mode hint system. Perfect for developers and pentesters honing web exploitation skills. An official OWASP flagship project with an active open-source community.
Prove your interest
Unlock this bonus resource by showing you are serious.
Hacker101
Free web security course created by HackerOne covering how the web works, common vulnerability classes, and how to find and report real bugs. Video lessons pair with capture-the-flag challenges, and top performers earn recognition from the HackerOne community. Ideal for aspiring bug bounty hunters and ethical hackers. Backed by the leading bug bounty platform.
Prove your interest
Unlock this bonus resource by showing you are serious.
LetsDefend
Hands-on blue-team training platform with SOC labs, malware analysis exercises, and simulated security operations centre scenarios. You learn to detect and respond to attacks by working actual alerts and incidents in a browser-based SOC environment. Built for aspiring SOC analysts and defenders. Free tier includes a starter set of labs; a subscription unlocks the full catalogue.
Prove your interest
Unlock this bonus resource by showing you are serious.
Blue Team Labs Online
Gamified defensive security platform with scenario-based challenges in digital forensics, phishing analysis, log review, and threat hunting. You solve challenges in your own lab environment and earn points and badges on the leaderboard. Ideal for students and professionals building blue-team skills. A well-regarded community platform for defender training.
Prove your interest
Unlock this bonus resource by showing you are serious.
NIST Cybersecurity Framework
The US National Institute of Standards and Technology's framework for improving critical infrastructure cyber security, organised around Identify, Protect, Detect, Respond, and Recover. You learn the professional vocabulary and structure used to build organisational security programmes. Essential reading for governance, compliance, and management roles. An internationally adopted standard.
Prove your interest
Unlock this bonus resource by showing you are serious.
SANS Reading Room
Large free library of thousands of practitioner research papers and white papers on every security topic: malware analysis, forensics, penetration testing, and security management. You deepen knowledge through real-world, graduate-level writing from SANS faculty and students. Great for self-study beyond beginner level. Free access to content from the world's leading commercial security training institute.
Prove your interest
Unlock this bonus resource by showing you are serious.
MITRE ATT&CK
Free, globally referenced knowledge base of adversary tactics and techniques based on real-world attack observations. You learn how attacks are classified, from initial access to exfiltration, and how defenders map detections to techniques. Essential for threat hunters, red teams, and SOC analysts. Maintained by MITRE and used by security teams worldwide.
Prove your interest
Unlock this bonus resource by showing you are serious.
OpenSecurityTraining2
Free, in-depth courses on low-level security topics such as x86 assembly, memory corruption exploitation, reverse engineering, and hardware security. You follow university-grade lecture slides, videos, and labs, with guided learning paths toward high-skill security jobs. Aimed at intermediate learners wanting serious technical depth. Run by a 501(c)(3) non-profit with all materials under open licenses.
Prove your interest
Unlock this bonus resource by showing you are serious.
Wireshark
The world's most widely used network protocol analyser, letting you capture and inspect every packet on your network. You learn traffic analysis, protocol behaviour, and how to investigate suspicious activity hands-on. Essential for network admins, SOC analysts, and anyone learning how the internet really works. Free, open source, and maintained for over 25 years.
Prove your interest
Unlock this bonus resource by showing you are serious.
CyberChef
A free web app from GCHQ, the Cyber Swiss Army Knife, for encoding, decoding, hashing, encryption, and data transformation tasks. You drag and drop operations to decode Base64, parse hex, identify hashes, and solve CTF-style puzzles. Perfect for CTF players and analysts working with logs and payloads. Official open-source tool from the UK intelligence agency, with tens of thousands of GitHub stars.
Prove your interest
Unlock this bonus resource by showing you are serious.
Cryptopals
Free set of programming-driven cryptography challenges that teach real crypto concepts by breaking them. You implement attacks against AES, RSA, and other primitives in any language, learning how crypto actually fails in practice. Ideal for developers and security students with some coding ability. A famous challenge set used in university courses worldwide.
Prove your interest
Unlock this bonus resource by showing you are serious.
VulnHub
Free collection of intentionally vulnerable virtual machines to download and attack in your own lab. Each machine is a realistic pentesting target with community-written walkthroughs and difficulty ratings. Perfect for practising enumeration, exploitation, and privilege escalation at your own pace. A long-standing favourite of the penetration testing community.
Prove your interest
Unlock this bonus resource by showing you are serious.
CyLab Security Academy (picoCTF)
Carnegie Mellon CyLab's free capture-the-flag learning platform, formerly picoCTF, offering thousands of challenges across binary exploitation, cryptography, web security, forensics, and reverse engineering. Includes the famous annual picoCTF competition plus always-available practice categories and structured learning tracks. Ideal for students and hobbyists who learn best by solving real security puzzles; free and self-paced.
Prove your interest
Unlock this bonus resource by showing you are serious.
Google Phishing Quiz
A free interactive quiz from Jigsaw and Google that trains you to spot phishing emails through eight realistic inbox scenarios. You read each simulated message and decide whether it is legitimate or a scam, then get instant feedback explaining the clues you missed. The quiz teaches red flags like urgent language, mismatched sender addresses, and deceptive links in a hands-on way. No sign-up required and playable in minutes. A proven awareness trainer used widely in security education.
Prove your interest
Unlock this bonus resource by showing you are serious.
Crypto 101
A free introductory e-book on cryptography by Laurens Van Houtven, available to read online or download in multiple formats. It explains how cryptographic systems actually work, why they fail, and how real-world attacks break them, with hands-on Python exercises built into the text. The book walks through AES, RSA, Diffie-Hellman, hashing, and TLS while debunking common myths about encryption. Written for programmers and curious learners with a practical, example-driven style. Entirely free.
Prove your interest
Unlock this bonus resource by showing you are serious.
Darknet Diaries
A critically acclaimed true-story podcast hosted by Jack Rhysider that explores hacking, cyber crime, and the dark side of the internet. Each episode tells a carefully researched real story, from penetration testers breaking into banks to social engineers and data breaches, teaching security lessons through narrative. Episodes include expert interviews and explain the techniques in accessible depth. Free on the website and all podcast platforms.
Prove your interest
Unlock this bonus resource by showing you are serious.
NetworkChuck (YouTube)
A hugely popular free channel teaching networking, IT, and cyber security fundamentals in an energetic, beginner-friendly style. Tutorials cover setting up home labs, learning Linux, ethical hacking with tools like Kali and Wireshark, and entry-level certifications like Network+ and Security+. Project-based episodes let viewers follow along and build real skills on free software. Hundreds of free videos with clear step-by-step demonstrations. Great for newcomers choosing a path into security.
Prove your interest
Unlock this bonus resource by showing you are serious.
18 more resources in Cyber Security
MMIC members see the full catalog — every resource, no limits.