Online Training Resources
Curated free and low-cost platforms, DoD tools, and reference databases to sharpen your skills.
Free Training Platforms
TryHackMe
Free TierBrowser-based CTF-style labs covering networking, web, forensics, and more. Beginner-friendly with guided learning paths. Military subscription available.
VisitHack The Box
Free TierIntermediate-to-advanced penetration testing labs and challenges. Strong community and active tracks for OSCP prep.
VisitOverTheWire
FreeClassic wargame server with Bandit (Linux basics) through Vortex. Essential for building command-line and scripting fundamentals.
VisitPicoCTF
FreeCarnegie Mellon's capture-the-flag platform. Excellent for binary exploitation, reverse engineering, and crypto fundamentals.
VisitSANS Cyber Aces
FreeSANS Institute free introductory courses covering OS internals, networking, and system security. Great foundation before pursuing GIAC certs.
VisitCybrary
Free TierVideo-based courses covering Security+, CEH, OSCP prep, and more. Free tier available; military discount on Pro plans.
VisitDoD & Government Resources
DoD Cyber Exchange (Public)
Official DoD resource hub: STIGs, Security Requirements Guides, SCAP tools, and training resources. Essential for hardening and compliance work.
VisitCISA Training & Exercises
Free DHS/CISA cybersecurity training including ICS/SCADA security, incident response, and workforce development courses.
VisitJoint Knowledge Online (JKO)
DoD's primary e-learning platform. Hosts mandatory training, PMK courses, and joint warfighting curricula. Use your CAC to log in.
VisitNavy e-Learning (NeL)
Navy's official online learning portal. Access IT, leadership, and technical courses. Tuition assistance for select college courses also managed here.
VisitNSA Codebreaker Challenge
Annual NSA competition with realistic reverse engineering and exploitation tasks. Excellent resume builder; top performers noted by NSA recruiters.
VisitDISA STIG Viewer
Download the official STIG Viewer and automated SCAP tools for auditing and hardening DoD systems — core skill for defensive CWT NECs.
VisitThreat Intel & Reference Databases
MITRE ATT&CK
The definitive adversary tactics and techniques knowledge base. Used for threat hunting, red/blue team planning, and incident response correlation.
VisitMITRE D3FEND
Counterpart to ATT&CK focused on defensive techniques. Maps defensive countermeasures to specific attacker TTPs.
VisitCVE / NVD
NIST National Vulnerability Database. Search CVEs by product, severity (CVSS), and publication date. Essential for vulnerability analysis.
VisitExploit DB
Offensive Security's public exploit archive. Useful for understanding real-world exploitation techniques and researching disclosed vulnerabilities.
VisitNIST SP 800 Series
NIST Special Publications covering risk management (800-37), incident response (800-61), access control (800-53), and more.
VisitVirusTotal
Aggregate malware scanning platform. Submit files, URLs, and hashes across 70+ AV engines. Invaluable for malware triage and threat hunting.
VisitCertification Exam Prep
Professor Messer (Security+)
Security+Free video course and study notes for the SY0-701 Security+ exam. One of the most recommended free resources for the DoD baseline cert.
VisitJason Dion Courses
Security+ / CySA+ / CASP+Affordable Udemy/online courses for CompTIA certifications with strong practice exams. Widely used by military members.
VisitOWASP Top 10
CEH / Web AppsThe canonical list of critical web application security risks. Required reading for anyone pursuing CEH, OSCP, or web application testing.
VisitPortSwigger Web Security Academy
Web / OSCPCompletely free, hands-on web security labs from the makers of Burp Suite. Covers SQLi, XSS, SSRF, OAuth, and advanced topics.
VisitOffensive Security Training
OSCP / GPENOfficial OffSec courses including PEN-200 (OSCP). Paid, but widely funded through Navy COOL for OCO-track CWTs.
VisitGIAC Certification Prep
GIAC FamilyOfficial GIAC cert catalog. Review exam objectives and index creation tips. GCIH, GCFE, GPEN, GNFA, and GXPN are all relevant to CWT tracks.
VisitLearning Path Recommendations
OCO Track
- OverTheWire Bandit → Narnia
- TryHackMe "Jr Penetration Tester" path
- PortSwigger Web Security Academy
- Hack The Box — Starting Point
- OSCP / PEN-200
DCO Track
- SANS Cyber Aces (OS & Networking)
- TryHackMe "SOC Level 1" path
- DISA STIG Viewer — practice hardening
- MITRE ATT&CK for threat hunting
- GCIH or CySA+ certification