Learn the vulnerabilities scanners actually find.
Three practical paths for practitioners and service members moving into cybersecurity. Every topic links to free resources from the people who define the field (OWASP, MITRE, PortSwigger and NIST), and many add a hands-on HTB Academy module.
Guided learning paths
Each path below groups topics in the order most teams meet them, and every topic links only to verified external resources from the people who define the field — OWASP, MITRE, PortSwigger, NIST, CISA and FIRST — with a hands-on HTB Academy module where one fits. These free paths mirror the guided learning paths inside CVERiskPilot, where your own scan findings pick the right path for each person and the platform tracks assignments, knowledge checks and completions.
Want your findings to drive the plan? See findings-driven training.
Developers and AppSec engineers
Web app security path
The weaknesses scanners report most often in web applications, in the order most teams meet them. Each topic pairs the MITRE CWE definition with a prevention cheat sheet and a hands-on lab topic.
01SQL injection
CWE-89How untrusted input reaches a query, and why parameterized queries are the fix.
02Cross-site scripting
CWE-79Reflected, stored and DOM XSS, and output encoding by context.
03OS command injection
CWE-78Shelling out with user input, and the safer APIs to use instead.
04Broken access control
CWE-862 · CWE-639Missing authorization checks, IDOR and privilege escalation.
05Server-side request forgery
CWE-918Making the server fetch attacker-chosen URLs, including cloud metadata endpoints.
06Hard-coded credentials and secrets
CWE-798Keys and passwords in source and config, and how to move them to a secrets manager.
07Vulnerable dependencies
CWE-1104Reading a CVE against your dependency tree and deciding what to upgrade first.
SOC analysts, vulnerability analysts and people moving into blue-team roles
SOC analyst path
Prioritizing what scanners report, reading logs, and handling incidents. A practical route for transitioning service members with operations, intelligence or comms backgrounds.
01Vulnerability prioritization
Why CVSS alone is not enough: exploit probability (EPSS) and known exploitation (KEV).
02Adversary techniques with MITRE ATT&CK
How attackers use the weaknesses you find, from initial access onward.
03Security logging and monitoring
CWE-778What to log, what to alert on, and the failures that hide an intrusion.
04Incident response
Preparation, detection, containment and lessons learned.
Engineers and GRC staff who need to speak both languages
Compliance for engineers
How a finding in a scan report becomes a control gap, a POAM item and a training requirement. Useful for defense-industrial-base teams preparing for CMMC.
01The CWE Top 25
The weakness classes behind most findings, and the IDs compliance mappings use.
02NIST 800-171 and CMMC Level 2
The 110 requirements behind CMMC Level 2, including the 3.2 awareness and training family.
03Secure software development (SSDF)
The practices auditors expect from a development team, including role-based training.
04For transitioning service members
Use SkillBridge time to build hands-on security experience before separation.
How we choose what to link
We link to free, public material first. Where a hands-on course covers a topic well, such as a module on HTB Academy, we list it next to the free resources. Which module goes with which topic is our own CWE-to-course mapping; providers do not review or endorse it, and some modules need a paid subscription with the provider.
Content policy. We only publish write-ups for retired Hack The Box content, in line with HTB's rules: retired machines, challenges and Sherlocks, plus the content HTB makes free (Starting Point machines and Tier 0 HTB Academy modules). We never publish solutions for active content or for paid Academy modules and skills assessments.
Training your team? Let your findings pick the topics.
CVERiskPilot reads the weaknesses in your scan findings and recommends the training that covers them, then records verified completions as audit evidence.
