Online Training Resources

Curated free and low-cost platforms, DoD tools, and reference databases to sharpen your skills.

Free Training Platforms

TryHackMe
Free Tier

Browser-based CTF-style labs covering networking, web, forensics, and more. Beginner-friendly with guided learning paths. Military subscription available.

Visit
Hack The Box
Free Tier

Intermediate-to-advanced penetration testing labs and challenges. Strong community and active tracks for OSCP prep.

Visit
OverTheWire
Free

Classic wargame server with Bandit (Linux basics) through Vortex. Essential for building command-line and scripting fundamentals.

Visit
PicoCTF
Free

Carnegie Mellon's capture-the-flag platform. Excellent for binary exploitation, reverse engineering, and crypto fundamentals.

Visit
SANS Cyber Aces
Free

SANS Institute free introductory courses covering OS internals, networking, and system security. Great foundation before pursuing GIAC certs.

Visit
Cybrary
Free Tier

Video-based courses covering Security+, CEH, OSCP prep, and more. Free tier available; military discount on Pro plans.

Visit

DoD & Government Resources

DoD Cyber Exchange (Public)

Official DoD resource hub: STIGs, Security Requirements Guides, SCAP tools, and training resources. Essential for hardening and compliance work.

Visit
CISA Training & Exercises

Free DHS/CISA cybersecurity training including ICS/SCADA security, incident response, and workforce development courses.

Visit
Joint Knowledge Online (JKO)

DoD's primary e-learning platform. Hosts mandatory training, PMK courses, and joint warfighting curricula. Use your CAC to log in.

Visit
Navy e-Learning (NeL)

Navy's official online learning portal. Access IT, leadership, and technical courses. Tuition assistance for select college courses also managed here.

Visit
NSA Codebreaker Challenge

Annual NSA competition with realistic reverse engineering and exploitation tasks. Excellent resume builder; top performers noted by NSA recruiters.

Visit
DISA STIG Viewer

Download the official STIG Viewer and automated SCAP tools for auditing and hardening DoD systems — core skill for defensive CWT NECs.

Visit

Threat Intel & Reference Databases

MITRE ATT&CK

The definitive adversary tactics and techniques knowledge base. Used for threat hunting, red/blue team planning, and incident response correlation.

Visit
MITRE D3FEND

Counterpart to ATT&CK focused on defensive techniques. Maps defensive countermeasures to specific attacker TTPs.

Visit
CVE / NVD

NIST National Vulnerability Database. Search CVEs by product, severity (CVSS), and publication date. Essential for vulnerability analysis.

Visit
Exploit DB

Offensive Security's public exploit archive. Useful for understanding real-world exploitation techniques and researching disclosed vulnerabilities.

Visit
NIST SP 800 Series

NIST Special Publications covering risk management (800-37), incident response (800-61), access control (800-53), and more.

Visit
VirusTotal

Aggregate malware scanning platform. Submit files, URLs, and hashes across 70+ AV engines. Invaluable for malware triage and threat hunting.

Visit

Certification Exam Prep

Professor Messer (Security+)
Security+

Free video course and study notes for the SY0-701 Security+ exam. One of the most recommended free resources for the DoD baseline cert.

Visit
Jason Dion Courses
Security+ / CySA+ / CASP+

Affordable Udemy/online courses for CompTIA certifications with strong practice exams. Widely used by military members.

Visit
OWASP Top 10
CEH / Web Apps

The canonical list of critical web application security risks. Required reading for anyone pursuing CEH, OSCP, or web application testing.

Visit
PortSwigger Web Security Academy
Web / OSCP

Completely free, hands-on web security labs from the makers of Burp Suite. Covers SQLi, XSS, SSRF, OAuth, and advanced topics.

Visit
Offensive Security Training
OSCP / GPEN

Official OffSec courses including PEN-200 (OSCP). Paid, but widely funded through Navy COOL for OCO-track CWTs.

Visit
GIAC Certification Prep
GIAC Family

Official GIAC cert catalog. Review exam objectives and index creation tips. GCIH, GCFE, GPEN, GNFA, and GXPN are all relevant to CWT tracks.

Visit
Learning Path Recommendations
OCO Track
  1. OverTheWire Bandit → Narnia
  2. TryHackMe "Jr Penetration Tester" path
  3. PortSwigger Web Security Academy
  4. Hack The Box — Starting Point
  5. OSCP / PEN-200
DCO Track
  1. SANS Cyber Aces (OS & Networking)
  2. TryHackMe "SOC Level 1" path
  3. DISA STIG Viewer — practice hardening
  4. MITRE ATT&CK for threat hunting
  5. GCIH or CySA+ certification