Free pentester course from scratch — Pentester Path
Learn penetration testing from zero. The free Pentester Path at BreachRoad Academy: 13 modules, Kali Linux, knowledge tests, XP and ranks. Watch the video.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 23 July 2026
- READING TIME
- 6 min read
- TOPIC
- Careers and Certifications
Want to become a penetration tester but don’t know where to start? Most material online either assumes you already know Linux and networking, or stops at flashy “hacking” with no real understanding. The Pentester Path at BreachRoad Academy takes you from your first terminal command to thinking like a professional security tester — calmly, and completely free.
The two videos below show how the Academy works: the progress system (XP and ranks) and a learning model built on scenarios rather than downloadable labs.
What you’ll learn on the pentester course
The program is 13 modules, ordered so each skill builds on the last:
- Fundamentals — what a pentest is, assets, threats, vulnerabilities and risk, the CIA triad, and the boundaries of legal testing.
- Workbench — Kali Linux in a virtual machine, first steps in the terminal, systems and networks (IP, TCP/UDP, DNS, HTTP, SMB).
- Reconnaissance — OSINT and passive recon, network enumeration with Nmap, footprinting common services.
- Web applications — information gathering, vulnerability assessment, authentication testing and common bug classes.
- Access and escalation — file transfers, shells and payloads, password attacks, and Active Directory enumeration and attacks.
We don’t teach “clicking a tool.” We teach understanding the mechanism: why something is vulnerable, how to confirm it safely, what the impact is, and how to fix and detect it.
How learning works — knowledge, not lab setup
Every module is built on solved, original scenarios around a fictional logistics company, Helios Freight. Instead of downloading packages and fighting environment setup, you work on ready material and learn to make decisions like on a real engagement:
- Mechanism — what happens and why.
- Decision — the smallest, safe evidence that confirms a hypothesis.
- Fix and detection — how to close the gap and how to spot it in logs.
Each module ends with a scenario-based knowledge test with an explanation for every answer — you check that you truly understand, not just memorize.
XP, ranks and visible progress
Learning should feel rewarding, so the Academy works a little like a game. Completed lessons and passed tests earn XP points, which map to nine ranks — from Recruit, through Operator and Hunter, to Legend. On your dashboard you see a progress ring, completed sections, and the path to your next rank.
Who this course is for
- People switching careers into cybersecurity.
- Students and enthusiasts who want a structured path instead of tutorial chaos.
- Administrators and developers who want to think like an attacker to defend their own systems.
How to start
Go to breachroad.com/en/academy, sign in with a magic link (no password), and open the first module. There’s nothing to buy or install beyond your own Kali virtual machine. Your first knowledge module is ready right away.
You learn offensive security legally and from the ground up. First you understand the mechanism — then you make the decision.
Frequently asked questions
- Is the pentester course really free?
- Yes. The entire Pentester Path at BreachRoad Academy is free. You sign in with a magic link (no password), and your progress, XP and ranks are saved to your account.
- Do I need prior knowledge or a CS degree?
- No. The course starts from zero: installing Kali Linux in a virtual machine and your first commands. No prior knowledge of Linux, networking or programming is assumed.
- Do I have to download labs or ZIP packages?
- No. The Academy is knowledge-based: you learn from solved, original scenarios, and each module ends with a scenario-based knowledge test with explanations. There is nothing to download or configure.
- What does the Pentester Path cover?
- 13 modules: from cybersecurity fundamentals through Kali, networking, OSINT, enumeration and Nmap, to web application testing, password attacks and Active Directory. The program keeps growing toward a full pentester path.
- Will I get a certificate?
- You earn XP and ranks (from Recruit to Legend) shown on your profile, and progress is saved. The course prepares you for certifications such as OSCP or PNPT, but does not issue them itself.


