Roadmaps

JavaScript

  1. JavaScript Essentials

    1. JavaScript Fundamentals
    2. Variables and Data Types
    3. Operators and Expressions
    4. Conditions and Loops
    5. Functions and Arrow Functions
    6. Scope, Hoisting and Closures
    7. Strings and Numbers
    8. Type Conversion and Coercion
    9. Date and Time
    10. Built-in Objects and Methods
  2. DOM and Browser

    1. JavaScript in HTML
    2. DOM Tree and Element Selection
    3. Creating, Modifying and Removing Elements
    4. DOM Traversal
    5. Events and Event Listeners
    6. Event Bubbling and Delegation
    7. Browser APIs
    8. Timers: setTimeout and setInterval
    9. Browser DevTools and Debugging
  3. Arrays and Objects

    1. Arrays and Array Methods
    2. Objects and Object Methods
    3. Destructuring and Spread Syntax
    4. Rest Parameters
    5. Iteration: for, for...of, for...in
    6. Map, Set and Other Collections
    7. References and Mutability
  4. Strings and Numbers

    1. String Properties and Methods
    2. Template Literals
    3. Searching and Extracting Substrings
    4. Replacing and Splitting Strings
    5. Trimming and Changing Case
    6. String Interpolation and Formatting
    7. Number Types and Precision
    8. Type Conversion and Parsing
    9. Math Operators and Remainder
    10. Number Formatting
    11. Working with BigInt
  5. Loops

    1. for Loop
    2. while and do...while Loops
    3. for...of and for...in Loops
    4. break and continue
    5. Nested Loops
    6. Looping Through Arrays and Objects
    7. Array Iteration Methods: forEach, map, filter, reduce
    8. Loop Control and Common Pitfalls
    9. Performance and Loop Optimization
  6. Date and Time

    1. Date Object Fundamentals
    2. Creating Dates and Timestamps
    3. Getting and Setting Date Components
    4. Date Formatting and Localization
    5. Date Arithmetic and Comparisons
    6. Working with Timezones and UTC
    7. Parsing Date Strings
    8. Measuring Time Intervals
    9. Timers: setTimeout and setInterval
    10. Intl.DateTimeFormat
  7. Built-in Methods

    1. Math Object: round, floor, ceil, abs, min, max, pow, sqrt
    2. Random Numbers: Math.random
    3. Generating Random Integers
    4. Number Methods: toFixed, toPrecision, Number.isNaN
    5. String Methods: includes, startsWith, endsWith, slice, substring, split, replace
    6. Array Methods: push, pop, shift, unshift, splice, slice
    7. Array Methods: includes, indexOf, find, findIndex
    8. Array Methods: map, filter, reduce, forEach, sort
    9. Array Methods: some, every, flat, flatMap
    10. Object Methods: keys, values, entries, assign
    11. Object Methods: fromEntries, hasOwn
    12. JSON: stringify and parse
    13. Set and Map
    14. Optional Chaining and Nullish Coalescing
    15. Spread Syntax and Rest Parameters
  8. Functions in JavaScript

    1. Pure Functions
    2. Higher-order Functions
    3. Callbacks and Function Composition
    4. Immutability
    5. Closures and Currying
    6. Functional Array Methods
    7. Separation of Concerns
  9. Browser Events

    1. Event Fundamentals and addEventListener
    2. Mouse Events: click, dblclick, mousedown, mouseup, mousemove
    3. Pointer Events: pointerdown, pointerup, pointermove
    4. Keyboard Events: keydown, keyup
    5. Keyboard Shortcuts and Key Detection
    6. Input Events: input, change, focus, blur
    7. Form Events: submit, reset
    8. Scroll Events and Scroll Position
    9. Wheel Events
    10. Touch Events and Mobile Interaction
    11. Drag and Drop Events
    12. Clipboard Events
    13. Window Events: load, resize, beforeunload
    14. Event Object and Event Properties
    15. Event Bubbling and Capturing
    16. Event Delegation
    17. preventDefault and stopPropagation
    18. Debouncing and Throttling Event Handlers
    19. Passive Event Listeners
  10. Fetch and API

    1. HTTP Fundamentals
    2. JSON and Serialization
    3. Fetch API
    4. HTTP Methods and Status Codes
    5. Request Headers and Body
    6. Handling API Responses and Errors
    7. Loading and Error States
    8. Working with Public APIs
  11. HTML Forms

    1. Form Elements and Input Types
    2. Reading and Handling Form Data
    3. Client-side Validation
    4. Custom Validation Messages
    5. Form Submission and Reset
    6. Working with FormData
  12. Regular Expressions

    1. Regex Syntax and Patterns
    2. Character Classes and Quantifiers
    3. Matching and Searching
    4. Replacing Text
    5. Form Validation with Regex
  13. Common website components: modals, tabs, burger menus

    1. Modal Windows
    2. Tabs and Accordions
    3. Dropdowns and Burger Menus
    4. Image Sliders and Carousels
    5. Search and Filtering
    6. Sorting and Pagination
    7. Dynamic Lists
    8. Reusable UI Components
  14. Popular JavaScript Libraries

    1. jQuery: DOM Manipulation, Events and AJAX
    2. Bootstrap: Components, Modals, Tooltips and Layout
    3. Swiper: Sliders, Carousels and Touch Navigation
    4. GSAP: Advanced Animations and Timelines
    5. Anime.js: Lightweight Animations
    6. AOS: Scroll-triggered Animations
    7. Chart.js: Charts and Data Visualization
    8. D3.js: Advanced Data Visualization
    9. Lodash: Utility Functions and Data Manipulation
    10. Day.js: Date and Time Manipulation
    11. date-fns: Date Utilities
    12. Axios: HTTP Requests
    13. Zod: Data Validation
    14. SortableJS: Drag and Drop Sorting
    15. Three.js: 3D Graphics
    16. Fabric.js: Interactive Canvas and Drawing
    17. SweetAlert2: Dialogs and Notifications
    18. Select2: Enhanced Select Elements
    19. FullCalendar: Calendar Interfaces
    20. Howler.js: Audio Playback
    21. Library Installation with npm and pnpm
    22. CDN vs Package Installation
    23. Library Documentation and Version Compatibility
    24. Choosing Between Native JavaScript and Libraries
  15. ES6 syntax and features

    1. let, const and Arrow Functions
    2. Template Literals
    3. Optional Chaining and Nullish Coalescing
    4. Default Parameters
    5. Modules: import and export
    6. Classes and Inheritance
    7. Prototypes and the Prototype Chain
    8. this, call, apply and bind
  16. LocalStorage and browser storage

    1. LocalStorage and SessionStorage
    2. Cookies Fundamentals
    3. Saving and Loading JSON Data
    4. Persisting Application State
    5. Browser Storage Limitations
  17. JavaScript Debugger

    1. Browser DevTools Overview
    2. Console: log, warn, error, table and dir
    3. Using debugger and Breakpoints
    4. Step Into, Step Over and Step Out
    5. Inspecting Variables and Scope
    6. Call Stack and Execution Context
    7. Conditional Breakpoints
    8. Watch Expressions
    9. DOM Breakpoints
    10. Debugging Event Handlers
    11. Network Tab and API Debugging
    12. Source Maps
    13. Debugging Asynchronous Code
    14. Handling Exceptions and Stack Traces
    15. Common JavaScript Errors
    16. Performance Profiling and Memory Inspection
  18. TypeScript

    1. TypeScript Fundamentals
    2. Primitive and Complex Types
    3. Type Inference and Type Annotations
    4. Interfaces and Type Aliases
    5. Union and Intersection Types
    6. Narrowing and Type Guards
    7. Generics
    8. Typing Functions and Objects
    9. Typing DOM Elements
    10. Working with API Response Types
    11. TypeScript Configuration
  19. OOP in JavaScript

    1. Objects and Methods
    2. Constructor Functions
    3. Classes and Constructors
    4. Inheritance and Encapsulation
    5. Static Methods and Properties
    6. Prototypes and the Prototype Chain
    7. this, call, apply and bind
  20. Charts and Data Visualization

    1. Working with Chart Libraries
    2. Line, Bar and Pie Charts
    3. Chart Configuration and Customization
    4. Dynamic Data Updates
    5. Interactive Charts
    6. Visualizing API Data
  21. JavaScript animations: from pure to Three.js

    1. CSS Transitions and Animations
    2. Animating with JavaScript
    3. requestAnimationFrame
    4. Scroll-based Animations
    5. Canvas API Fundamentals
    6. Three.js and 3D Web Development
  22. Moving on to frameworks: React

    1. Components and JSX
    2. Props and Component Composition
    3. State and Event Handling
    4. Conditional Rendering
    5. Lists and Keys
    6. Forms in React
    7. useEffect and Side Effects
    8. Custom Hooks
    9. Routing and Navigation
    10. API Integration
    11. TypeScript with React
    12. Project Structure and Reusable Components
  23. Making Games with JavaScript

    1. Game Loops and Timing
    2. Keyboard and Mouse Input
    3. Collision Detection
    4. Canvas-based Games
    5. Sprites and Animation
    6. Physics Fundamentals
    7. Game State Management
  24. OOP in Python

    1. Objects and Methods
    2. Constructor Functions
    3. Classes and Constructors
    4. Inheritance and Encapsulation
    5. Static Methods and Properties
    6. Prototypes and the Prototype Chain
    7. this, call, apply and bind
  25. NPM, packages, pnpm

    1. Node.js Fundamentals
    2. NPM and Package Management
    3. package.json and npm Scripts
    4. Installing and Managing Dependencies
    5. pnpm
    6. Vite and Development Server
    7. Environment Variables
    8. JavaScript Modules and Project Structure
    9. Git and GitHub
  26. Asynchronous JavaScript

    1. Synchronous vs Asynchronous Execution
    2. Callbacks
    3. Promises
    4. async and await
    5. Error Handling: try...catch
    6. Promise Chaining and Promise Combinators
    7. Event Loop and Task Queues
  27. Web Workers and Multithreading

    1. JavaScript Concurrency Fundamentals
    2. Main Thread and Event Loop
    3. What Web Workers Are and When to Use Them
    4. Creating a Worker with the Worker API
    5. Sending and Receiving Messages
    6. postMessage and Message Events
    7. Structured Clone Algorithm
    8. Transferring ArrayBuffers
    9. SharedArrayBuffer and Atomics Fundamentals
    10. Worker Lifecycle and Error Handling
    11. Dedicated Workers vs Shared Workers
    12. Worker Limitations: DOM Access and Browser APIs
    13. Web Workers with Modules
    14. Practical Use Cases: Data Processing, Calculations and File Parsing
    15. Communicating Between the Main Thread and Workers
    16. When to Use Web Workers vs Async JavaScript
  28. Git and Github

    1. What Git Is and Why Version Control Matters
    2. Installing Git and Initial Configuration
    3. Creating a Repository with git init
    4. Cloning Repositories with git clone
    5. Checking Status with git status
    6. Staging Changes with git add
    7. Committing Changes with git commit
    8. Viewing History with git log
    9. Working with .gitignore
    10. Branches and Branch Management
    11. Switching Branches with git switch
    12. Merging Branches with git merge
    13. Handling Merge Conflicts
    14. Connecting Local Repositories to GitHub
    15. Pushing and Pulling Changes
    16. Fetching Remote Changes
    17. Working with Remote Repositories
    18. Creating and Reviewing Pull Requests
    19. Forking and Cloning Repositories
    20. Issues and Discussions
    21. README.md and Project Documentation
    22. GitHub Collaboration Workflow
    23. Resolving Common Git Problems
    24. Reverting Changes with git revert
    25. Undoing Local Changes Safely
    26. Git Tags and Releases
    27. GitHub Pages Fundamentals
    28. GitHub Actions Introduction
  29. Testing and Code Quality

    1. JavaScript Unit Testing
    2. Assertions and Test Structure
    3. Mocking and Test Doubles
    4. Testing Asynchronous Code
    5. ESLint and Code Formatting
    6. Refactoring and Clean Code
    7. Debugging and Error Analysis

React

  1. React Fundamentals

    1. JSX
    2. Components
    3. Props
    4. Children
    5. Rendering
    6. Conditional rendering
    7. Lists and keys
    8. Event handling
    9. Component composition
    10. Fragments
    11. Basic project structure
    12. Vite
    13. React DevTools
  2. State and Interactivity

    1. useState
    2. State updates
    3. Functional state updates
    4. State and component re-rendering
    5. Controlled components
    6. Forms
    7. Form validation
    8. Lifting state up
    9. Derived state
    10. State vs props
    11. Component communication
  3. React Hooks

    1. useEffect
    2. Effect dependencies
    3. Cleanup functions
    4. useRef
    5. useMemo
    6. useCallback
    7. useReducer
    8. Custom hooks
    9. Rules of Hooks
    10. Common hook mistakes
    11. Avoiding unnecessary effects
  4. Working with APIs

    1. HTTP fundamentals
    2. fetch
    3. REST APIs
    4. GET / POST / PUT / PATCH / DELETE
    5. Loading states
    6. Error handling
    7. Async operations
    8. Request cancellation
    9. Environment variables
    10. API service layer
    11. CRUD applications
  5. Routing

    1. React Router
    2. Routes
    3. Nested routes
    4. Dynamic routes
    5. Route parameters
    6. Query parameters
    7. Navigation
    8. Link and NavLink
    9. Programmatic navigation
    10. 404 pages
    11. Protected routes
    12. Route layouts
    13. Authentication flows
  6. Forms and User Input

    1. Controlled inputs
    2. Uncontrolled inputs
    3. Form state
    4. Validation
    5. Reusable form components
    6. File uploads
    7. Multi-step forms
    8. Form libraries
    9. Schema validation
  7. Global State Management

    1. Context API
    2. useContext
    3. When to use Context
    4. Global UI state
    5. Authentication state
    6. State management patterns
    7. Redux
    8. Redux Toolkit
    9. Async Redux logic
    10. Zustand
    11. Choosing a state management solution
  8. Server State and Data Fetching

    1. Server state vs client state
    2. TanStack Query
    3. Queries
    4. Mutations
    5. Caching
    6. Query invalidation
    7. Optimistic updates
    8. Pagination
    9. Infinite queries
    10. Prefetching
    11. Request retries
    12. Error handling
    13. Loading and stale states
  9. Authentication

    1. Authentication concepts
    2. Sessions
    3. JWT
    4. Access tokens
    5. Refresh tokens
    6. Cookies
    7. Login
    8. Registration
    9. Logout
    10. Protected routes
    11. Role-based access
    12. Permissions
    13. OAuth
    14. Google authentication
    15. Frontend security basics
  10. Styling and UI

    1. CSS fundamentals
    2. CSS Modules
    3. Tailwind CSS
    4. Responsive design
    5. Component styling
    6. Design systems
    7. Reusable UI components
    8. Accessibility
    9. Dark mode
    10. Animations
    11. Headless UI libraries
  11. TypeScript with React

    1. TypeScript fundamentals
    2. Typing props
    3. Typing state
    4. Typing events
    5. Typing refs
    6. Typing children
    7. Interfaces and types
    8. Generics
    9. Utility types
    10. API response types
    11. Reusable generic components
    12. Type-safe custom hooks
    13. Type-safe forms
  12. Advanced Component Patterns

    1. Component composition
    2. Compound components
    3. Render props
    4. Higher-order components
    5. Custom hooks
    6. Controlled vs uncontrolled components
    7. State machines
    8. Headless components
    9. Reusable component APIs
    10. Polymorphic components
  13. Performance

    1. React rendering model
    2. Reconciliation
    3. Component re-rendering
    4. React.memo
    5. useMemo
    6. useCallback
    7. Code splitting
    8. Lazy loading
    9. Suspense
    10. Virtualized lists
    11. Bundle optimization
    12. Network optimization
    13. Performance profiling
    14. React DevTools Profiler
    15. Core Web Vitals
  14. Advanced React

    1. Concurrent rendering
    2. Suspense
    3. Error boundaries
    4. Server Components
    5. Server-side rendering
    6. Static rendering
    7. Streaming
    8. Hydration
    9. React Compiler
    10. Advanced rendering patterns
  15. React Frameworks

    1. Next.js
    2. App Router
    3. Server Components
    4. Server Actions
    5. Layouts
    6. Loading UI
    7. Error handling
    8. Metadata
    9. Image optimization
    10. Caching
    11. SSR
    12. SSG
    13. ISR
    14. Middleware
    15. API routes
    16. Full-stack React applications
  16. Testing

    1. Unit testing
    2. Component testing
    3. Vitest
    4. React Testing Library
    5. Mocking APIs
    6. Integration testing
    7. End-to-end testing
    8. Playwright
    9. Testing forms
    10. Testing authentication
    11. Testing user flows
  17. Architecture

    1. Feature-based architecture
    2. Component architecture
    3. Container vs presentational components
    4. Shared components
    5. Design systems
    6. Service layers
    7. API clients
    8. State architecture
    9. Custom hooks architecture
    10. Domain-driven frontend structure
    11. Dependency management
    12. Reusable modules
    13. Scalable folder structures
  18. Production React

    1. Environment configuration
    2. Build process
    3. Deployment
    4. Vercel
    5. Docker
    6. CI/CD
    7. GitHub Actions
    8. Environment variables
    9. Logging
    10. Error monitoring
    11. Performance monitoring
    12. Analytics
    13. Security
    14. Production debugging
  19. Advanced Frontend Engineering

    1. Frontend architecture
    2. Micro-frontends
    3. Monorepos
    4. Module boundaries
    5. Design systems
    6. Advanced caching
    7. Offline applications
    8. PWA
    9. WebSockets
    10. Real-time applications
    11. Web workers
    12. Web performance
    13. Accessibility engineering
    14. Internationalization
    15. Localization
  20. Professional React Development

    1. Code reviews
    2. Git workflows
    3. Clean code
    4. Refactoring
    5. Technical debt
    6. Documentation
    7. Component documentation
    8. Storybook
    9. Design-to-code workflows
    10. API contracts
    11. Frontend/backend collaboration
    12. Security practices
    13. Performance budgets
    14. Production incident debugging
  21. Real-World Projects

    1. Todo application
    2. Weather application
    3. Movie browser
    4. E-commerce frontend
    5. Dashboard
    6. Authentication system
    7. Admin panel
    8. Real-time chat
    9. Social media application
    10. Full-stack SaaS
    11. Production-grade React application

Python

  1. Tkinter for building simple GUI's

  2. Python modules: OS, JSON, datetime

  3. Web Scrapping

  4. Server for a backend: FastAPI

  5. Practicing functions

  6. Encoding and Encryption algorithms in Python

  7. Databases

  8. Telegram bots

  9. Websockets

  10. Keyboard, mouse, events

  11. Pushing libraries to PyPi

  12. Server configuration: error handling, middleware, security

Django for web development

  1. Django Fundamentals

    1. Python fundamentals for Django
    2. Virtual environments
    3. pip
    4. Django installation
    5. Django project structure
    6. Django applications
    7. settings.py
    8. urls.py
    9. manage.py
    10. Django development server
    11. Django configuration
    12. Environment variables
    13. Development vs production settings
  2. Django CLI

    1. django-admin
    2. manage.py
    3. startproject
    4. startapp
    5. runserver
    6. check
    7. shell
    8. dbshell
    9. makemigrations
    10. migrate
    11. showmigrations
    12. sqlmigrate
    13. createsuperuser
    14. changepassword
    15. collectstatic
    16. test
    17. dumpdata
    18. loaddata
    19. inspectdb
    20. makemessages
    21. compilemessages
  3. URLs & Routing

    1. URL patterns
    2. path()
    3. re_path()
    4. URL parameters
    5. Path converters
    6. Named URLs
    7. URL namespaces
    8. include()
    9. URL reversing
    10. reverse()
    11. redirect()
    12. resolve()
    13. URL organization
  4. HTTP & Django Requests

    1. HTTP methods
    2. GET
    3. POST
    4. PUT
    5. PATCH
    6. DELETE
    7. HTTP status codes
    8. Request objects
    9. Response objects
    10. Headers
    11. Cookies
    12. Sessions
    13. Query parameters
    14. Form data
    15. JSON requests
    16. File uploads
  5. Django Views

    1. Function-based views
    2. Class-based views
    3. Generic views
    4. TemplateView
    5. ListView
    6. DetailView
    7. CreateView
    8. UpdateView
    9. DeleteView
    10. View inheritance
    11. Mixins
    12. Decorators
    13. Custom responses
    14. JSON responses
  6. Templates

    1. Django Template Language
    2. Template variables
    3. Template tags
    4. Template filters
    5. Template inheritance
    6. Base templates
    7. Template includes
    8. Custom template tags
    9. Custom template filters
    10. Static files
    11. Template context
  7. Models

    1. Django models
    2. Model fields
    3. Field options
    4. Model metadata
    5. Model methods
    6. Model managers
    7. Model inheritance
    8. Abstract models
    9. Proxy models
    10. Model relationships
    11. One-to-one relationships
    12. Foreign keys
    13. Many-to-many relationships
    14. Choices
    15. Constraints
    16. Indexes
  8. Django ORM

    1. QuerySets
    2. Query expressions
    3. Filtering
    4. Excluding
    5. Ordering
    6. Slicing
    7. get()
    8. create()
    9. update()
    10. delete()
    11. get_or_create()
    12. update_or_create()
    13. exists()
    14. count()
    15. first()
    16. last()
    17. values()
    18. values_list()
    19. annotate()
    20. aggregate()
    21. F expressions
    22. Q objects
    23. Subqueries
    24. Conditional expressions
  9. Database Design

    1. Relational databases
    2. PostgreSQL
    3. Database normalization
    4. Primary keys
    5. Foreign keys
    6. Constraints
    7. Unique constraints
    8. Indexes
    9. Database transactions
    10. Isolation concepts
    11. Query optimization
    12. N+1 queries
  10. Migrations

    1. Migration fundamentals
    2. makemigrations
    3. migrate
    4. Migration files
    5. Migration dependencies
    6. Data migrations
    7. RunPython
    8. Migration conflicts
    9. Squashing migrations
    10. Migration rollback
    11. Safe schema changes
  11. Django Admin

    1. Django Admin
    2. Model registration
    3. ModelAdmin
    4. List display
    5. Search
    6. Filtering
    7. Ordering
    8. Admin actions
    9. Inline models
    10. Custom forms
    11. Permissions
    12. Admin customization
    13. Custom admin pages
  12. Forms

    1. Django Forms
    2. ModelForms
    3. Form fields
    4. Form validation
    5. Custom validation
    6. clean()
    7. clean_field()
    8. Validation errors
    9. Widgets
    10. Form rendering
    11. File uploads
    12. Multiple forms
  13. Authentication

    1. Django authentication
    2. Users
    3. Groups
    4. Permissions
    5. Password hashing
    6. Login
    7. Logout
    8. Authentication middleware
    9. LoginRequiredMixin
    10. PermissionRequiredMixin
    11. Custom user model
    12. User profile
    13. Password reset
    14. Email verification
    15. Social authentication
  14. Authorization

    1. Permissions
    2. Groups
    3. Object-level permissions
    4. Custom permissions
    5. Permission decorators
    6. Permission mixins
    7. Role-based access control
    8. Access control patterns
  15. Sessions & Cookies

    1. Django sessions
    2. Session backends
    3. Cookies
    4. Session security
    5. Session expiration
    6. Session-based authentication
    7. Session storage
  16. Security

    1. CSRF
    2. XSS protection
    3. SQL injection protection
    4. Clickjacking protection
    5. Host validation
    6. Secure cookies
    7. HTTPS
    8. Security headers
    9. Content Security Policy
    10. Secret management
    11. Security middleware
    12. Security checklist
  17. Static & Media Files

    1. Static files
    2. MEDIA_ROOT
    3. MEDIA_URL
    4. STATIC_ROOT
    5. STATIC_URL
    6. collectstatic
    7. FileField
    8. ImageField
    9. Storage backends
    10. User uploads
    11. Cloud storage
  18. Django REST APIs

    1. Django REST Framework
    2. Serializers
    3. ModelSerializer
    4. APIView
    5. Generic API views
    6. ViewSets
    7. Routers
    8. Request parsing
    9. Response rendering
    10. Status codes
    11. Validation
    12. Pagination
    13. Filtering
    14. Ordering
  19. API Authentication

    1. Session authentication
    2. Token authentication
    3. JWT
    4. OAuth 2.0
    5. API keys
    6. Authentication classes
    7. Permission classes
    8. CORS
    9. CSRF in APIs
    10. Rate limiting
  20. API Design

    1. REST principles
    2. Resources
    3. Endpoints
    4. HTTP methods
    5. Status codes
    6. Request validation
    7. Response structure
    8. Error responses
    9. Pagination
    10. Filtering
    11. Sorting
    12. Versioning
    13. API documentation
  21. Django Testing

    1. Django TestCase
    2. pytest
    3. pytest-django
    4. Unit tests
    5. Integration tests
    6. Model tests
    7. View tests
    8. API tests
    9. Form tests
    10. Authentication tests
    11. Test fixtures
    12. Factories
    13. Mocking
    14. Test database
    15. Test coverage
  22. Django Signals

    1. Signals
    2. pre_save
    3. post_save
    4. pre_delete
    5. post_delete
    6. m2m_changed
    7. Custom signals
    8. Signal receivers
    9. Signal design problems
  23. Middleware

    1. Middleware architecture
    2. Request middleware
    3. Response middleware
    4. Authentication middleware
    5. Custom middleware
    6. Middleware ordering
    7. Exception handling middleware
  24. Caching

    1. Django caching
    2. Cache framework
    3. Per-view caching
    4. Template fragment caching
    5. Low-level cache API
    6. Redis
    7. Cache invalidation
    8. Cache keys
    9. Cache strategies
  25. Background Tasks

    1. Background jobs
    2. Celery
    3. Redis
    4. Task queues
    5. Periodic tasks
    6. Retries
    7. Task monitoring
    8. Idempotent tasks
    9. Async tasks
  26. Asynchronous Django

    1. ASGI
    2. WSGI
    3. Async views
    4. async def
    5. sync_to_async
    6. Django async ORM
    7. Async requests
    8. Async consumers
    9. Async limitations
  27. Django Channels

    1. WebSockets
    2. Channels
    3. Consumers
    4. Routing
    5. Channel layers
    6. Redis channel layer
    7. Real-time notifications
    8. Real-time applications
  28. Performance

    1. Query optimization
    2. select_related()
    3. prefetch_related()
    4. Database indexes
    5. Query profiling
    6. N+1 detection
    7. Caching
    8. Lazy QuerySets
    9. Pagination
    10. Connection management
    11. Django Debug Toolbar
    12. Application profiling
  29. Django Management

    1. Custom management commands
    2. Command arguments
    3. Command options
    4. Command output
    5. Command errors
    6. Scheduled commands
    7. Data import
    8. Data export
    9. Automation scripts
  30. Email

    1. Django email
    2. Email backends
    3. SMTP
    4. HTML email
    5. Email templates
    6. Transactional email
    7. Email verification
    8. Password reset emails
    9. Background email tasks
  31. Internationalization

    1. Translations
    2. gettext
    3. gettext_lazy
    4. Locale middleware
    5. Language switching
    6. Translation files
    7. Timezone handling
    8. Localization
  32. Advanced Django Architecture

    1. Fat models
    2. Service layer
    3. Repository pattern
    4. Selectors
    5. Managers
    6. Mixins
    7. Domain logic
    8. Application boundaries
    9. Dependency management
    10. Reusable applications
    11. Modular Django
  33. Production Configuration

    1. Production settings
    2. Environment variables
    3. Secrets
    4. DEBUG
    5. ALLOWED_HOSTS
    6. Database configuration
    7. Static files
    8. Media files
    9. Logging
    10. Error reporting
    11. Security settings
  34. Deployment

    1. Linux server
    2. Gunicorn
    3. Uvicorn
    4. Nginx
    5. ASGI deployment
    6. WSGI deployment
    7. PostgreSQL
    8. Redis
    9. Docker
    10. Docker Compose
    11. HTTPS
    12. SSL certificates
    13. Domain configuration
    14. DNS
    15. CI/CD
  35. Django with Docker

    1. Dockerfile
    2. Docker Compose
    3. Django container
    4. PostgreSQL container
    5. Redis container
    6. Environment variables
    7. Volumes
    8. Networks
    9. Static files
    10. Database migrations
    11. Production containers
  36. CI/CD

    1. Git
    2. GitHub
    3. GitHub Actions
    4. Automated testing
    5. Linting
    6. Formatting
    7. Build pipelines
    8. Deployment pipelines
    9. Database migrations
    10. Static files deployment
    11. Environment management
  37. Observability

    1. Django logging
    2. Structured logging
    3. Error tracking
    4. Sentry
    5. Application metrics
    6. Health checks
    7. Database monitoring
    8. Performance monitoring
    9. Request tracing
  38. Advanced ORM

    1. Advanced QuerySets
    2. Custom managers
    3. Custom QuerySet methods
    4. Expressions
    5. Subqueries
    6. OuterRef
    7. Exists
    8. Window functions
    9. Database functions
    10. Raw SQL
    11. Database-specific features
  39. Advanced Django REST Framework

    1. Custom serializers
    2. Nested serializers
    3. Serializer validation
    4. Custom fields
    5. Custom permissions
    6. Custom authentication
    7. Custom pagination
    8. Custom filters
    9. Custom throttling
    10. API versioning
    11. OpenAPI
    12. Swagger
    13. DRF Spectacular
  40. Django Security in Practice

    1. Authentication attacks
    2. Authorization vulnerabilities
    3. CSRF attacks
    4. XSS
    5. SQL injection
    6. IDOR
    7. Mass assignment
    8. File upload vulnerabilities
    9. Session attacks
    10. JWT security
    11. API security
    12. Rate limiting
    13. Security headers
  41. Professional Django Development

    1. Project structure
    2. Code organization
    3. Reusable components
    4. Configuration management
    5. Database design
    6. API design
    7. Testing strategy
    8. Error handling
    9. Logging
    10. Documentation
    11. Code review
    12. Git workflow
    13. Dependency management
    14. Technical debt
    15. Refactoring
  42. Real Django Projects

    1. CRUD application
    2. Authentication system
    3. REST API
    4. Admin dashboard
    5. Payment integration
    6. Background processing
    7. Real-time application
    8. File storage
    9. Email system
    10. Third-party API integration
    11. Dockerized application
    12. Production deployment
    13. CI/CD pipeline
    14. Monitoring

Backend & Deployment

  1. Backend Fundamentals

    1. Backend Fundamentals
    2. Client-server architecture
    3. HTTP / HTTPS
    4. Request / response lifecycle
    5. URLs, routes and endpoints
    6. HTTP methods
    7. Status codes
    8. Headers
    9. Query parameters
    10. Path parameters
    11. Request body
    12. JSON
    13. Content types
    14. REST API principles
    15. API versioning
    16. Idempotency
    17. Stateless vs stateful systems
    18. WebSockets for real-time applications
  2. Python Backend Fundamentals

    1. Python for backend development
    2. Virtual environments
    3. pip / package management
    4. Project structure
    5. Configuration and environment variables
    6. Logging
    7. Exceptions and error handling
    8. Type hints
    9. Pydantic
    10. Dependency management
    11. Application settings
  3. FastAPI

    1. FastAPI project structure
    2. Routes and path operations
    3. Request validation
    4. Pydantic models
    5. Response models
    6. Dependency injection
    7. Routers
    8. Middleware
    9. Exception handlers
    10. Authentication
    11. Authorization
    12. OpenAPI / Swagger
    13. API documentation
    14. File uploads
    15. Background tasks
    16. Async endpoints
    17. Sync endpoints
    18. ASGI
    19. Uvicorn
  4. Django

    1. Django project structure
    2. Apps
    3. URLs
    4. Views
    5. Request / response
    6. Templates
    7. Middleware
    8. Django settings
    9. Static and media files
    10. Management commands
    11. Django Admin
    12. Authentication
    13. Permissions
    14. Sessions
    15. Django REST Framework
    16. Serializers
    17. API views
    18. ViewSets
    19. Routers
    20. API authentication
    21. Permissions
    22. Pagination
    23. Filtering
    24. API documentation
  5. Sync & Async Programming

    1. Synchronous execution
    2. Asynchronous execution
    3. Blocking operations
    4. Non-blocking operations
    5. Event loop
    6. async / await
    7. Coroutines
    8. Tasks
    9. Concurrency vs parallelism
    10. I/O-bound operations
    11. CPU-bound operations
    12. Threads
    13. Processes
    14. Async database access
    15. Async HTTP requests
    16. When async actually helps
    17. Common async mistakes
  6. Databases Fundamentals

    1. Relational databases
    2. Tables
    3. Rows and columns
    4. Primary keys
    5. Foreign keys
    6. Relationships
    7. One-to-one
    8. One-to-many
    9. Many-to-many
    10. Constraints
    11. Indexes
    12. Transactions
    13. ACID
    14. Normalization
    15. SQL basics
    16. SELECT / INSERT / UPDATE / DELETE
    17. JOINs
    18. Aggregations
    19. Transactions and isolation
  7. SQLite

    1. SQLite architecture
    2. Local development databases
    3. SQLite limitations
    4. Database files
    5. Migrations
    6. When SQLite is appropriate
    7. When to move to PostgreSQL
  8. PostgreSQL

    1. PostgreSQL architecture
    2. Schemas
    3. Roles and permissions
    4. Data types
    5. Indexes
    6. Constraints
    7. Transactions
    8. PostgreSQL-specific features
    9. Query optimization
    10. Connection management
    11. Production databases
  9. ORM

    1. Object-relational mapping
    2. Models
    3. Fields
    4. Relationships
    5. Queries
    6. Querysets
    7. Lazy evaluation
    8. Migrations
    9. Transactions
    10. N+1 query problem
    11. Eager loading
    12. Raw SQL
    13. ORM vs SQL
    14. Django ORM
    15. SQLAlchemy
    16. FastAPI + SQLAlchemy
    17. Database sessions
  10. Users & Authentication

    1. User accounts
    2. Registration
    3. Login / logout
    4. Password hashing
    5. Password reset
    6. Sessions
    7. Cookies
    8. Secure cookies
    9. HTTP-only cookies
    10. SameSite
    11. CSRF
    12. JWT
    13. Access tokens
    14. Refresh tokens
    15. Authentication vs authorization
    16. Roles
    17. Permissions
    18. OAuth
    19. Google / GitHub login
    20. Account security
  11. HTTP & Server Architecture

    1. Web server
    2. Application server
    3. Reverse proxy
    4. Middleware
    5. Request lifecycle
    6. Routing
    7. Authentication middleware
    8. CORS
    9. Rate limiting
    10. Compression
    11. Static files
    12. Error handling
    13. Global exception handling
    14. Logging
    15. Monitoring
    16. Health checks
    17. Graceful shutdown
  12. API Development

    1. REST APIs
    2. Resource-oriented design
    3. CRUD
    4. Request validation
    5. Response serialization
    6. Error responses
    7. Pagination
    8. Filtering
    9. Sorting
    10. Search
    11. File uploads
    12. Webhooks
    13. API authentication
    14. API versioning
    15. OpenAPI
    16. Swagger
    17. Postman / Insomnia
    18. API testing
  13. Background Tasks

    1. Why background processing exists
    2. Long-running operations
    3. Scheduled tasks
    4. Email sending
    5. File processing
    6. Notifications
    7. Data processing
    8. Task queues
    9. Workers
    10. Retries
    11. Failed jobs
    12. Job status
    13. Scheduling
  14. Redis

    1. In-memory data storage
    2. Key-value model
    3. Caching
    4. TTL
    5. Sessions
    6. Rate limiting
    7. Pub/Sub
    8. Redis as a queue
    9. Redis data structures
    10. Cache invalidation
    11. Redis in production
  15. Message Queues

    1. Message brokers
    2. Producer / consumer model
    3. Queues
    4. Messages
    5. Workers
    6. Acknowledgements
    7. Retries
    8. Dead-letter queues
    9. RabbitMQ
    10. Redis-based queues
    11. Celery
    12. Task queues vs message brokers
    13. When to use each approach
  16. Workers

    1. Worker processes
    2. Celery
    3. Celery workers
    4. Celery Beat
    5. Redis / RabbitMQ as brokers
    6. Background jobs
    7. Scheduled jobs
    8. Retries
    9. Monitoring workers
    10. Worker scaling
  17. Testing Backend Applications

    1. Unit tests
    2. Integration tests
    3. API tests
    4. Database tests
    5. Authentication tests
    6. Mocking
    7. Fixtures
    8. Test databases
    9. Pytest
    10. Django Test Framework
    11. FastAPI testing
    12. Test-driven development basics
  18. Docker

    1. Containers
    2. Images
    3. Dockerfile
    4. Docker Compose
    5. Environment variables
    6. Volumes
    7. Networks
    8. Port mapping
    9. Multi-container applications
    10. Backend + PostgreSQL
    11. Backend + Redis
    12. Backend + worker
    13. Production containers
    14. Docker image optimization
  19. Linux & Server Fundamentals

    1. Linux filesystem
    2. Processes
    3. Users and permissions
    4. SSH
    5. Environment variables
    6. Ports
    7. Processes and services
    8. Logs
    9. System resources
    10. Networking basics
    11. DNS
    12. TCP/IP basics
    13. HTTP/HTTPS
    14. Firewall basics
    15. Reverse proxies
    16. Nginx
    17. Systemd
    18. Cron
  20. Deployment Fundamentals

    1. Development vs production
    2. Environment configuration
    3. Secrets
    4. Production databases
    5. Build process
    6. Application startup
    7. Process management
    8. Logs
    9. Health checks
    10. Domain names
    11. DNS
    12. SSL/TLS
    13. HTTPS
    14. Reverse proxy
    15. Backups
    16. Database migrations
    17. Deployment strategies
    18. Zero-downtime deployment
  21. Railway

    1. Railway projects
    2. Services
    3. PostgreSQL
    4. Environment variables
    5. Deployments
    6. GitHub integration
    7. Logs
    8. Domains
    9. Custom domains
    10. Service-to-service communication
    11. Redis
    12. Volumes
    13. Deployment configuration
    14. Production debugging
  22. Cloud Deployment

    1. Cloud computing concepts
    2. Virtual machines
    3. Managed databases
    4. Object storage
    5. Networking
    6. Load balancing
    7. Containers
    8. Serverless concepts
    9. Environment variables
    10. Secrets
    11. Monitoring
  23. AWS

    1. AWS fundamentals
    2. IAM
    3. EC2
    4. RDS
    5. S3
    6. CloudFront
    7. Route 53
    8. Load Balancer
    9. CloudWatch
    10. VPC basics
    11. Security groups
    12. ECS / containers
    13. Lambda overview
    14. Managed services
    15. Cost awareness
  24. Alternative Cloud Platforms

    1. Railway
    2. Render
    3. Fly.io
    4. DigitalOcean
    5. Hetzner
    6. AWS
    7. Cloudflare
    8. Vercel
    9. Choosing the right platform
    10. Managed vs self-managed infrastructure
  25. CI/CD

    1. Git
    2. GitHub
    3. GitHub Actions
    4. Automated testing
    5. Build pipelines
    6. Deployment pipelines
    7. Environment-specific deployments
    8. Secrets
    9. Rollbacks
    10. Database migrations during deployment
    11. Continuous integration
    12. Continuous deployment
  26. Security

    1. OWASP fundamentals
    2. SQL injection
    3. XSS
    4. CSRF
    5. Authentication security
    6. Authorization
    7. Password security
    8. Secrets management
    9. CORS
    10. Rate limiting
    11. Input validation
    12. File upload security
    13. Dependency vulnerabilities
    14. HTTPS
    15. Security headers
    16. Least privilege
    17. Secure database access
  27. Caching & Performance

    1. Why applications become slow
    2. Database bottlenecks
    3. Query optimization
    4. Indexes
    5. N+1 queries
    6. Application caching
    7. Redis caching
    8. HTTP caching
    9. CDN
    10. Connection pooling
    11. Async I/O
    12. Background jobs
    13. Load testing
    14. Profiling
  28. Microservices

    1. Monolith architecture
    2. Modular monolith
    3. Microservice architecture
    4. Service boundaries
    5. Service-to-service communication
    6. REST between services
    7. Internal APIs
    8. Message queues
    9. Event-driven architecture
    10. Service discovery
    11. Independent deployment
    12. Independent databases
    13. Distributed transactions
    14. Eventual consistency
    15. Failure between services
    16. Observability
    17. When NOT to use microservices
  29. Architecture & Design

    1. MVC
    2. Layered architecture
    3. Service layer
    4. Repository pattern
    5. Dependency injection
    6. Separation of concerns
    7. Domain logic
    8. Application logic
    9. Infrastructure layer
    10. SOLID principles
    11. Design patterns
    12. Clean Architecture overview
    13. Modular architecture
    14. Monolith vs microservices
  30. Laravel

    1. PHP backend fundamentals
    2. Laravel project structure
    3. Routing
    4. Controllers
    5. Middleware
    6. Requests / responses
    7. Validation
    8. Blade
    9. Authentication
    10. Authorization
    11. Eloquent ORM
    12. Migrations
    13. Relationships
    14. Query Builder
    15. API development
    16. Laravel Sanctum
    17. Queues
    18. Jobs
    19. Events
    20. Listeners
    21. Scheduling
    22. Cache
    23. Redis
    24. Laravel Artisan
    25. Laravel deployment
    26. Laravel vs Django
    27. Laravel vs FastAPI
  31. Production Project

    1. Design backend architecture
    2. PostgreSQL database
    3. Authentication
    4. REST API
    5. Django or FastAPI backend
    6. Redis
    7. Background worker
    8. Message queue
    9. Docker
    10. Automated tests
    11. GitHub Actions
    12. Production deployment
    13. Domain + HTTPS
    14. Logging
    15. Monitoring
    16. Backups
    17. Documentation
    18. Production debugging
    19. Performance optimization

Client-Server Architecture

  1. Web Fundamentals: HTML, CSS, JS

  2. Fetch and API

  3. Request / Response structure: body, headers, CORS. Preflight request

  4. AJAX

  5. HTTP Methods and Status Codes

  6. Browser console. Network and requests

  7. RESTful API

  8. SQL and NoSQL databases

  9. Sqlite

  10. PostgreSQL

  11. MongoDB

  12. Schema validation. Types

  13. OpenAPI and Swagger

  14. CRUD

  15. Building middleware

  16. Errors Handling

  17. Authentication and Authorization. JWT Tokens

  18. Pagination

  19. States. Async storages

  20. Sync and async code and requests

  21. Retries. Timeouts. Request cancellation

  22. Session, cookies, tokens. JWT

  23. Login with Google

  24. Security Fundamentals. OWASP TOP 10

  25. Password Security

  26. State. Server state. Persistent storage

  27. Queries and caching. Network optimization

  28. Real-time apps. WebSockets, polling, Server-Sent Events

  29. Jobs. Workers. Notifications

  30. Uploading. File types. Multipart form data. Uploading progress

Linux for server development

  1. WSL2

  2. 20 most common Linux commands

  3. Oracle Cloud

  4. Github Actions: automating your deployment

  5. Docker & Docker Containers

Kali Linux for security artisans

  1. Kali Linux Fundamentals

    1. Kali Linux installation
    2. Virtual machines
    3. Kali Linux filesystem
    4. Terminal
    5. Shell
    6. APT package management
    7. Users and permissions
    8. sudo
    9. Processes
    10. Services
    11. Environment variables
    12. SSH
    13. Bash basics
    14. Kali Linux tool organization
    15. Man pages
    16. Kali documentation
    17. Updating Kali
    18. Installing security tools
  2. Linux Skills for Pentesting

    1. Essential Linux commands
    2. File permissions
    3. Processes
    4. Services
    5. Networking commands
    6. ip
    7. ss
    8. ping
    9. traceroute
    10. curl
    11. wget
    12. grep
    13. find
    14. awk
    15. sed
    16. sort
    17. cut
    18. xargs
    19. Pipes and redirection
    20. Bash scripting
  3. Networking for Pentesting

    1. TCP/IP
    2. IPv4
    3. IPv6
    4. MAC addresses
    5. ARP
    6. TCP
    7. UDP
    8. Ports
    9. Sockets
    10. DNS
    11. DHCP
    12. ICMP
    13. Routing
    14. NAT
    15. CIDR
    16. Subnets
    17. Firewalls
    18. Proxies
    19. VPNs
  4. Network Reconnaissance

    1. Passive reconnaissance
    2. Active reconnaissance
    3. OSINT
    4. WHOIS
    5. DNS enumeration
    6. Subdomain enumeration
    7. Certificate Transparency
    8. Search engine reconnaissance
    9. theHarvester
    10. Amass
    11. Subfinder
  5. Network Scanning

    1. Nmap
    2. Host discovery
    3. Port scanning
    4. TCP scanning
    5. UDP scanning
    6. SYN scanning
    7. Service detection
    8. Version detection
    9. OS detection
    10. Nmap NSE
    11. Nmap scripting
    12. Masscan
    13. RustScan
    14. Netcat
  6. Network Traffic Analysis

    1. Wireshark
    2. tcpdump
    3. Packet capture
    4. TCP analysis
    5. UDP analysis
    6. DNS analysis
    7. HTTP analysis
    8. ARP analysis
    9. Network troubleshooting
  7. Vulnerability Scanning

    1. CVE
    2. CVSS
    3. Vulnerability identification
    4. Vulnerability validation
    5. Nuclei
    6. Nikto
    7. Greenbone / OpenVAS
    8. Searchsploit
    9. Exploit-DB
  8. Web Reconnaissance

    1. HTTP
    2. HTTPS
    3. HTTP methods
    4. HTTP headers
    5. Cookies
    6. Sessions
    7. Web technologies
    8. Directory enumeration
    9. File enumeration
    10. ffuf
    11. Gobuster
    12. Feroxbuster
    13. WhatWeb
    14. JavaScript reconnaissance
    15. API endpoint discovery
  9. Web Pentesting with Burp Suite

    1. Burp Suite
    2. Proxy
    3. HTTP interception
    4. Repeater
    5. Intruder
    6. Decoder
    7. Request manipulation
    8. Response analysis
    9. Authentication testing
    10. Authorization testing
    11. Session testing
    12. Parameter testing
    13. Burp extensions
  10. Basic Web Vulnerabilities

    1. SQL Injection
    2. XSS
    3. CSRF
    4. IDOR
    5. Path Traversal
    6. File Inclusion
    7. File Upload
    8. Command Injection
    9. SSRF
    10. SSTI
    11. XXE
    12. Authentication vulnerabilities
    13. Authorization vulnerabilities
    14. Security misconfiguration
  11. Password Attacks

    1. Password hashes
    2. Hash identification
    3. Wordlists
    4. Hashcat
    5. John the Ripper
    6. Hydra
    7. Password spraying
    8. Brute-force concepts
    9. Credential stuffing concepts
  12. Exploitation

    1. Exploit concepts
    2. Exploit-DB
    3. Searchsploit
    4. Metasploit
    5. Metasploit modules
    6. Payloads
    7. Auxiliary modules
    8. Exploit validation
    9. Manual exploitation
    10. Meterpreter
  13. Linux Privilege Escalation

    1. Linux permissions
    2. SUID
    3. SGID
    4. sudo
    5. Capabilities
    6. Cron jobs
    7. PATH hijacking
    8. Writable files
    9. Writable services
    10. Environment variables
    11. Kernel vulnerabilities
    12. LinPEAS
    13. Manual enumeration
  14. Windows Pentesting from Kali

    1. SMB
    2. RDP
    3. WinRM
    4. Windows enumeration
    5. Windows authentication
    6. Windows users
    7. Windows services
    8. PowerShell
    9. CrackMapExec / NetExec
    10. Impacket
    11. Evil-WinRM
    12. BloodHound
  15. Active Directory Basics

    1. Domain enumeration
    2. LDAP
    3. Kerberos
    4. SMB
    5. Domain users
    6. Domain groups
    7. Domain controllers
    8. BloodHound
    9. Kerberoasting
    10. AS-REP Roasting
    11. Password spraying
    12. Lateral movement
  16. Pivoting

    1. Network pivoting
    2. Port forwarding
    3. SSH tunneling
    4. SOCKS proxies
    5. Proxychains
    6. Chisel
    7. Ligolo-ng
    8. Internal network enumeration
  17. Wireless Pentesting

    1. Wireless fundamentals
    2. 802.11
    3. Monitor mode
    4. Wireless interfaces
    5. Packet capture
    6. Aircrack-ng
    7. Wireshark
    8. WPA/WPA2/WPA3
    9. Wireless reconnaissance
  18. Pentesting Automation

    1. Bash scripting
    2. Python for pentesting
    3. Requests
    4. Scapy
    5. Nmap automation
    6. API automation
    7. Custom enumeration scripts
    8. Parsing scan results
    9. Automated reconnaissance
  19. Pentesting Methodology

    1. Scope
    2. Rules of engagement
    3. Reconnaissance
    4. Enumeration
    5. Scanning
    6. Vulnerability identification
    7. Exploitation
    8. Privilege escalation
    9. Lateral movement
    10. Pivoting
    11. Evidence collection
    12. Cleanup
    13. Reporting
  20. Pentest Reporting

    1. Finding identification
    2. Evidence
    3. Proof of Concept
    4. Risk rating
    5. CVSS
    6. Business impact
    7. Remediation
    8. Technical report
    9. Executive summary
    10. Retesting
  21. Practical Pentesting

    1. Vulnerable Linux machines
    2. Vulnerable Windows machines
    3. Web application labs
    4. Network penetration testing labs
    5. OWASP Juice Shop
    6. DVWA
    7. Metasploitable
    8. Hack The Box
    9. TryHackMe
    10. PortSwigger Web Security Academy
    11. Full penetration test simulation

Advanced Cybersecurity

  1. Linux Fundamentals

    1. Kali Linux installation & VM setup
    2. Linux filesystem
    3. Terminal & shell
    4. Essential Linux commands
    5. Users & groups
    6. File permissions
    7. sudo
    8. Processes
    9. Services
    10. Environment variables
    11. Package management with apt
    12. Pipes & redirects
    13. grep
    14. awk
    15. sed
    16. sort
    17. cut
    18. xargs
    19. Bash scripting
    20. SSH
  2. Networking Fundamentals

    1. OSI model
    2. TCP/IP model
    3. IPv4 / IPv6
    4. MAC addresses
    5. ARP
    6. TCP vs UDP
    7. Ports & sockets
    8. DNS
    9. DHCP
    10. ICMP
    11. Routing
    12. NAT
    13. Subnets & CIDR
    14. Firewalls
    15. Proxies
    16. VPNs
  3. Network Analysis

    Network interfaces ip ss route ping traceroute tcpdump Wireshark Packet capture TCP handshake analysis DNS traffic analysis HTTP/HTTPS traffic analysis Network troubleshooting

  4. Reconnaissance

    1. Passive reconnaissance
    2. Active reconnaissance
    3. OSINT
    4. WHOIS
    5. DNS enumeration
    6. Subdomain discovery
    7. Certificate Transparency
    8. Search engine dorking
    9. Amass
    10. Subfinder
    11. theHarvester
    12. Maltego
    13. Attack surface discovery
  5. Port & Service Enumeration

    1. Nmap
    2. TCP scanning
    3. UDP scanning
    4. SYN scanning
    5. Service detection
    6. Version detection
    7. OS detection
    8. NSE scripts
    9. Masscan
    10. RustScan
    11. Banner grabbing
    12. Netcat
    13. Service enumeration methodology
  6. Vulnerability Assessment

    1. Vulnerability vs exploit
    2. CVE
    3. CVSS
    4. Vulnerability scanning
    5. False positives
    6. Vulnerability validation
    7. Nuclei
    8. Nikto
    9. OpenVAS / Greenbone
    10. Searchsploit
    11. Exploit-DB
    12. Manual vulnerability verification
  7. Web Fundamentals

    1. HTTP
    2. HTTPS
    3. HTTP methods
    4. HTTP status codes
    5. HTTP headers
    6. Cookies
    7. Sessions
    8. Authentication
    9. Authorization
    10. REST APIs
    11. JSON
    12. CORS
    13. Same-Origin Policy
    14. TLS
    15. Browser DevTools
  8. Web Reconnaissance

    1. Directory enumeration
    2. File enumeration
    3. ffuf
    4. Gobuster
    5. Feroxbuster
    6. robots.txt
    7. sitemap.xml
    8. Technology fingerprinting
    9. WhatWeb
    10. Wappalyzer
    11. JavaScript analysis
    12. API endpoint discovery
  9. Burp Suite

    1. Proxy
    2. HTTP interception
    3. Repeater
    4. Intruder
    5. Decoder
    6. HTTP request manipulation
    7. HTTP response analysis
    8. Scope configuration
    9. Burp extensions
    10. Automating repetitive tasks
  10. OWASP Top 10

    1. Broken Access Control
    2. Cryptographic Failures
    3. Injection
    4. Insecure Design
    5. Security Misconfiguration
    6. Vulnerable Components
    7. Authentication Failures
    8. Software and Data Integrity Failures
    9. Logging and Monitoring Failures
    10. SSRF
  11. Web Application Pentesting

    1. Authentication testing
    2. Session management testing
    3. Authorization testing
    4. Access control testing
    5. Input validation
    6. Error handling
    7. Business logic testing
    8. Parameter manipulation
    9. Request manipulation
    10. Response manipulation
  12. Web Exploitation

    1. SQL Injection
    2. NoSQL Injection
    3. Cross-Site Scripting
    4. CSRF
    5. SSTI
    6. XXE
    7. SSRF
    8. Path Traversal
    9. Local File Inclusion
    10. Remote File Inclusion
    11. File Upload vulnerabilities
    12. Command Injection
    13. Deserialization vulnerabilities
    14. Prototype Pollution
    15. HTTP Request Smuggling
  13. Password & Authentication Security

    1. Password hashing
    2. Hash identification
    3. Hashcat
    4. John the Ripper
    5. Wordlists
    6. Password mutation
    7. Hash cracking concepts
    8. Password spraying
    9. Brute-force concepts
    10. Credential stuffing
    11. Hydra
    12. Authentication attack methodology
  14. Exploitation Fundamentals

    1. Vulnerability vs exploit
    2. Public exploits
    3. Exploit-DB
    4. Searchsploit
    5. Metasploit Framework
    6. Modules
    7. Payloads
    8. Exploit modules
    9. Auxiliary modules
    10. Meterpreter
    11. Manual exploitation
    12. Exploit validation
  15. Linux Privilege Escalation

    1. Linux permissions
    2. SUID
    3. SGID
    4. sudo misconfigurations
    5. Linux capabilities
    6. Cron jobs
    7. PATH hijacking
    8. Writable files
    9. Writable services
    10. Environment variables
    11. Kernel vulnerabilities
    12. LinPEAS
    13. Manual enumeration
    14. Privilege escalation methodology
  16. Windows Fundamentals

    1. Windows architecture
    2. Windows users and groups
    3. Windows services
    4. Windows Registry
    5. PowerShell
    6. NTFS permissions
    7. Windows networking
    8. SMB
    9. RDP
    10. WinRM
    11. Windows authentication
  17. Windows Privilege Escalation

    1. Service misconfigurations
    2. Unquoted service paths
    3. Weak file permissions
    4. Scheduled tasks
    5. Registry weaknesses
    6. Token privileges
    7. DLL hijacking
    8. Credential discovery
    9. WinPEAS
    10. Manual enumeration
    11. Privilege escalation methodology
  18. Active Directory

    1. Active Directory architecture
    2. Domains
    3. Domain Controllers
    4. Forests
    5. LDAP
    6. Kerberos
    7. NTLM
    8. SMB
    9. Domain users
    10. Domain groups
    11. Group Policy
    12. BloodHound
    13. LDAP enumeration
    14. Kerberos enumeration
    15. Domain attack paths
  19. Active Directory Attacks

    1. Kerberoasting
    2. AS-REP Roasting
    3. NTLM relay concepts
    4. Pass-the-Hash
    5. Pass-the-Ticket
    6. ACL abuse
    7. Delegation attacks
    8. Credential attacks
    9. Lateral movement
    10. Domain privilege escalation
  20. Post-Exploitation

    1. Situational awareness
    2. Local enumeration
    3. Credential discovery
    4. Network discovery
    5. Internal service enumeration
    6. Process enumeration
    7. User enumeration
    8. Network configuration
    9. Persistence concepts
    10. Controlled access
    11. Evidence collection
    12. Cleanup
  21. Network Pivoting

    1. Pivoting concepts
    2. Internal network mapping
    3. Routing through compromised hosts
    4. SOCKS proxies
    5. SSH tunneling
    6. Local port forwarding
    7. Remote port forwarding
    8. Proxychains
    9. Chisel
    10. Ligolo-ng
    11. Multi-hop pivoting
  22. Wireless Security

    1. Wi-Fi architecture
    2. 802.11 fundamentals
    3. Wireless interfaces
    4. Monitor mode
    5. Packet capture
    6. Aircrack-ng
    7. Wireshark
    8. WPA/WPA2/WPA3
    9. Wireless authentication
    10. Rogue access point concepts
    11. Wireless security assessment
  23. API Security

    1. REST APIs
    2. GraphQL
    3. JWT
    4. OAuth 2.0
    5. API authentication
    6. API authorization
    7. BOLA / IDOR
    8. Rate limiting
    9. Mass assignment
    10. API fuzzing
    11. API enumeration
    12. OWASP API Security Top 10
  24. Cloud Security

    1. Cloud fundamentals
    2. IAM
    3. AWS fundamentals
    4. Azure fundamentals
    5. GCP fundamentals
    6. Object storage
    7. Security groups
    8. Cloud metadata services
    9. Access keys
    10. Cloud misconfigurations
    11. ScoutSuite
    12. Trivy
    13. Cloud enumeration
  25. Container Security

    1. Docker architecture
    2. Docker images
    3. Dockerfiles
    4. Container networking
    5. Container privileges
    6. Docker socket
    7. Container secrets
    8. Image vulnerabilities
    9. Trivy
    10. Docker Bench
    11. Container escape concepts
  26. Source Code Security

    1. Git fundamentals
    2. Git history analysis
    3. Secret discovery
    4. API key exposure
    5. Environment variables
    6. Dependency vulnerabilities
    7. SAST
    8. Semgrep
    9. Gitleaks
    10. TruffleHog
  27. Security Automation

    1. Python for security
    2. Bash automation
    3. PowerShell automation
    4. Requests
    5. Scapy
    6. Nmap automation
    7. API automation
    8. Custom enumeration scripts
    9. Result parsing
    10. JSON
    11. CSV
    12. Reusable security tools
  28. Exploit Development

    1. Python for exploit development
    2. C fundamentals
    3. Memory layout
    4. Stack
    5. Heap
    6. Registers
    7. Assembly basics
    8. GDB
    9. Buffer overflows
    10. Shellcode concepts
    11. ASLR
    12. DEP / NX
    13. Stack canaries
    14. Basic binary exploitation
  29. Binary Analysis

    1. ELF
    2. PE
    3. Executable formats
    4. Static analysis
    5. Dynamic analysis
    6. Strings analysis
    7. Ghidra
    8. x64dbg
    9. Process analysis
    10. Debugging
    11. Reverse engineering fundamentals
  30. Malware Analysis

    1. Malware fundamentals
    2. Static malware analysis
    3. Dynamic malware analysis
    4. PE analysis
    5. ELF analysis
    6. Indicators of Compromise
    7. Sandboxing
    8. Process monitoring
    9. Network behavior analysis
    10. Reverse engineering
  31. Professional Pentesting Methodology

    1. Rules of engagement
    2. Scope definition
    3. Asset discovery
    4. Attack surface mapping
    5. Threat modeling
    6. Reconnaissance
    7. Enumeration
    8. Vulnerability analysis
    9. Exploitation
    10. Privilege escalation
    11. Lateral movement
    12. Pivoting
    13. Impact assessment
    14. Evidence collection
    15. Cleanup
    16. Documentation
  32. Pentest Reporting

    1. Executive summary
    2. Technical findings
    3. Evidence
    4. Reproduction steps
    5. Risk rating
    6. CVSS
    7. Business impact
    8. Remediation
    9. Proof of Concept
    10. Retesting
    11. Final report
  33. Real-World Pentesting Workflow

    1. Scope
    2. Reconnaissance
    3. Attack surface discovery
    4. Enumeration
    5. Service identification
    6. Vulnerability discovery
    7. Manual validation
    8. Initial access
    9. Privilege escalation
    10. Credential discovery
    11. Lateral movement
    12. Pivoting
    13. Impact validation
    14. Evidence collection
    15. Cleanup
    16. Reporting
    17. Remediation
    18. Retesting
  34. Practice Labs

    1. OverTheWire
    2. PortSwigger Web Security Academy
    3. TryHackMe
    4. Hack The Box
    5. VulnHub
    6. OWASP Juice Shop
    7. DVWA
    8. Metasploitable
    9. Damn Vulnerable API
    10. Self-hosted vulnerable environments
  35. Advanced Red Team Concepts

    1. Adversary simulation
    2. Initial access
    3. Command and Control
    4. C2 frameworks
    5. Evasion concepts
    6. OPSEC
    7. Identity attacks
    8. Active Directory attack paths
    9. Cloud attack paths
    10. Detection engineering
    11. Purple Team methodology