to get students hired as cybersecurity engineers in the U.S.
If your goal is:
- ✅ 7 months
- ✅ Students become employable
- ✅ Resume with 5 years of experience (through realistic enterprise projects)
- ✅ Pass technical interviews
then they need to learn much more than what is listed on that poster.
Phase 1. Computer & Networking (Weeks 1-4)
Without this foundation students struggle later.
Operating Systems
- Windows 10/11
- Windows Server
- Active Directory
- Linux (Ubuntu)
- Kali Linux
Networking
- OSI Model
- TCP/IP
- DNS
- DHCP
- HTTP/HTTPS
- SSH
- FTP
- SMTP
- VPN
- Firewalls
- Routing
- VLAN
- NAT
Tools
- Wireshark
- Nmap
- tcpdump
- PuTTY
- OpenSSH
- VirtualBox
- VMware
Phase 2. Linux Administration
Students should become comfortable using Linux every day.
Topics
- users
- groups
- permissions
- chmod
- chown
- grep
- awk
- sed
- cron
- bash scripting
- services
- systemctl
- journalctl
Tools
- Bash
- Vim
- Nano
- Git
Phase 3. Windows Administration
Topics
- Active Directory
- Group Policy
- DNS
- DHCP
- Certificate Services
- PowerShell
- Windows Event Logs
Tools
- PowerShell
- Active Directory Users and Computers
- Event Viewer
Phase 4. Python
Students do NOT need to become software developers.
Enough to automate.
Topics
- requests
- json
- csv
- API
- file automation
Libraries
- requests
- pandas
- psutil
Phase 5. SIEM (SOC)
This is where companies hire.
Tools
✅ Splunk
✅ Microsoft Sentinel
✅ Elastic SIEM
✅ QRadar
Concepts
- Log ingestion
- Dashboards
- Alerts
- Correlation Rules
- MITRE ATT&CK Mapping
Phase 6. Threat Hunting
Tools
- Sysmon
- Sigma Rules
- Velociraptor
- Chainsaw
- Hayabusa
- KAPE
Students should investigate
- malware
- persistence
- credential dumping
- lateral movement
Phase 7. Incident Response
Tools
- Velociraptor
- FTK Imager
- Autopsy
- Volatility3
- Redline
Students learn
- Memory analysis
- Disk analysis
- Timeline
- IOC creation
Phase 8. Malware Analysis
Beginner level
Tools
- PEStudio
- Detect It Easy
- VirusTotal
- Any.Run
- ProcMon
- Process Explorer
Phase 9. Cloud Security
This is extremely important because many companies are moving workloads to the cloud.
AWS
- IAM
- EC2
- VPC
- Security Groups
- CloudTrail
- GuardDuty
- Security Hub
- Inspector
- Config
- CloudWatch
- S3 Security
- KMS
Azure
- Azure Defender
- Sentinel
- Entra ID
- Key Vault
Phase 10. DevSecOps
Most bootcamps ignore this.
Tools
Git
GitHub
GitHub Actions
Docker
Kubernetes
Terraform
Jenkins
Trivy
OWASP Dependency Check
SonarQube
Semgrep
Checkov
Snyk
Phase 11. Web Security
Tools
Burp Suite
OWASP ZAP
Postman
ffuf
Gobuster
Nikto
SQLMap
Topics
OWASP Top 10
XSS
SQL Injection
CSRF
Authentication
JWT
API Security
Phase 12. Vulnerability Management
Tools
Tenable Nessus
OpenVAS
Qualys
Nuclei
Phase 13. Email Security
Tools
Microsoft Defender
Proofpoint
Mimecast
Topics
SPF
DKIM
DMARC
Phishing
BEC
Phase 14. Identity Security
Tools
Microsoft Entra ID
Okta
Duo
CyberArk
HashiCorp Vault
Phase 15. Threat Intelligence
Tools
MISP
VirusTotal
AbuseIPDB
Shodan
GreyNoise
AlienVault OTX
Phase 16. Detection Engineering
Tools
Sigma
YARA
Suricata
Snort
Zeek
Students should write
- Sigma rules
- YARA rules
- Detection logic
Phase 17. Purple Team
Exactly what your tutor teaches.
Tools
MITRE ATT&CK
Atomic Red Team
Caldera
Metasploit
BloodHound
CrackMapExec
Responder
Impacket
Phase 18. Reporting
Students should know how to write
- Incident Reports
- Executive Summary
- Risk Assessment
- Vulnerability Reports
- Remediation Plans
Phase 19. Professional Skills
Recruiters care about these too.
Students should learn
- Resume
- Technical interview
- Behavioral interview
- STAR method
- Communication
- Documentation
Enterprise Projects (This is what creates "5 years of experience")
Instead of only labs, students should complete projects that resemble real work:
Project 1 – Enterprise SOC
- Build a Windows Active Directory domain
- Generate attack traffic
- Collect logs in Splunk
- Create alerts
- Investigate incidents
Project 2 – Ransomware Incident Response
- Simulate ransomware
- Contain affected hosts
- Recover systems
- Produce an executive report
Project 3 – AWS Cloud Security
- Deploy an application in AWS
- Configure CloudTrail, GuardDuty, Security Hub, IAM least privilege
- Detect and investigate suspicious activity
Project 4 – DevSecOps Pipeline
- Build a CI/CD pipeline with GitHub Actions or Jenkins
- Integrate SonarQube, Trivy, Semgrep, and Checkov
- Deploy to Docker/Kubernetes
- Remediate vulnerabilities and redeploy
Project 5 – Purple Team Capstone
- Use Atomic Red Team or Caldera to emulate attacks
- Detect them with Splunk or Microsoft Sentinel
- Hunt threats, perform incident response, and present findings to "management"
Recommended tool stack for a 2026 job-ready cybersecurity bootcamp
| Category | Primary Tools |
|---|---|
| Operating Systems | Windows Server, Ubuntu, Kali |
| Networking | Wireshark, Nmap |
| SIEM | Splunk, Microsoft Sentinel |
| Threat Hunting | Sysmon, Sigma, Velociraptor |
| Incident Response | Autopsy, FTK Imager, Volatility3 |
| Vulnerability Scanning | Nessus, OpenVAS |
| Web Security | Burp Suite, OWASP ZAP, Postman |
| Cloud Security | AWS (CloudTrail, GuardDuty, Security Hub, IAM) |
| DevSecOps | Git, GitHub, Docker, Kubernetes, Terraform, Jenkins, SonarQube, Trivy, Semgrep, Checkov |
| Threat Intelligence | VirusTotal, MISP, Shodan, AbuseIPDB |
| Detection Engineering | Sigma, YARA, Zeek, Suricata |
This combination gives students exposure to the tools and workflows commonly encountered in SOC Analyst, Incident Response, Cloud Security, Security Engineer, and DevSecOps roles. Combined with strong enterprise-style projects and interview preparation, it provides a much stronger foundation for entering the cybersecurity job market than the Purple Team curriculum alone.
Top comments (0)