Open-source project
farhanashrafdev/90DaysOfCyberSecurity avatar
farhanashrafdev/90DaysOfCyberSecurity

90DaysOfCyberSecurity: a 90-day study plan that is mostly a link list

This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, covering topics such as Network+, Security+, Linux, Python, Traffic Analysis, Git, ELK, AWS, Azure, and Hacking. The repository also includes a `LEARN.md

19,714 stars2,253 forksUnknownMIT

At a glance

What is it?
farhanashrafdev/90DaysOfCyberSecurity is a day-by-day cybersecurity curriculum pointing at free external courses, from Network+ through ELK and ethical hacking. The plan is the value; the repository is the index.
Who is it for?
Adopt it if you want a dated, ordered checklist pointing at free courses and you accept that the actual teaching happens on YouTube, Linux Journey, Wireshark's site and Cisco NetAcad, not here. Do not adopt it if you want graded labs, a certificate, or a single self-contained course; the README states certifications are optional and the plan is self-paced, so nothing verifies your work.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 24 days ago.
What is it written in?
GitHub does not report a main language for this repository.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the 90-day plan actually gives you

This repository is a curriculum skeleton, not a course. The README describes a "structured, 90-day self-paced study plan" whose daily modules cover networking fundamentals, security principles, Linux basics and shell scripting, Python for security tasks, traffic analysis and packet inspection, Git, SIEM log analysis with the ELK stack, cloud security across GCP, AWS and Azure, and penetration testing. Each day is a pointer: a playlist, a tutorial site, a lab platform, or a reading link, plus an instruction to complete related practice questions.

The audience is stated plainly. Aspiring security professionals preparing for entry-level roles or certifications, IT staff moving into security, students, self-learners, and developers or DevOps engineers who want to understand secure infrastructure. The README says no prior experience is required, though basic familiarity with computers, networks or programming helps.

The honest framing is that the repository's contribution is sequencing and curation. Professor Messer's N10-009 and SY0-701 playlists, Linux Journey, Cisco NetAcad's Linux Unhatched, LabEx labs, freeCodeCamp's Python course, Wireshark University, the guru99 Wireshark tutorial, Daniel Miessler's tcpdump tutorial and the Suricata quickstart guide are all public. What the plan adds is an order, a time budget and a reason not to skip ahead.

How the 95-day schedule is structured

The README's table of contents splits the plan into contiguous day ranges. Days 1-7 are Network+ via Professor Messer's N10-009 playlist. Days 8-14 are Security+ via the SY0-701 playlist, with Pete Zerger's SY0-701 playlist listed as an alternative. Days 15-28 are Linux, using Linux Journey, Linux Unhatched on Cisco NetAcad and Linux hands-on labs on LabEx. Days 29-42 are Python, anchored on freeCodeCamp's roughly 4.5-hour beginner course plus Codecademy, Real Python, HackerRank and LabEx. Days 43-56 are traffic analysis: Wireshark University, a guru99 tutorial, a tcpdump tutorial and the Suricata quickstart. Days 57-63 are Git, 64-70 ELK, 71-77 a cloud platform (GCP, AWS or Azure), 78-84 review and practice, and 85-90 hacking.

Two things stand out. First, the numbering runs past 90: the bonus section adds Day 91-92 on a one-page resume and Day 93-95 on where and how to apply, so the advertised 90 days is really 95 days of material. Second, the cloud block asks you to pick one of three providers rather than covering all three, which keeps the week realistic but means the plan's cloud coverage is a week deep at most.

The repository layout matches this structure: README.md, learn.md, License.md, translations/, and an .all-contributorsrc file. There is no code, no scripts and no test harness to run.

Start Here: the README's own rules for using it

The Start Here section is the most concrete part of the repository, and it is worth following literally. The time budget is 1 to 2 focused hours a day, and the README says the day numbers are a guide, not a deadline. The order matters: Days 1-28 (networking, security basics, Linux) are described as the foundation everything else builds on, with an explicit instruction not to skip ahead to hacking. Certifications are optional: the README states you do not have to sit the Network+ or Security+ exams to follow the plan or to get a first job. Everything is free, and if a site puts content behind a paywall, the README says to use the alternatives listed in the same section or in learn.md. Progress tracking is manual: fork the repo or copy the plan into a notes file and tick off each day. Questions go to GitHub Discussions; issues are reserved for broken links and content fixes.

That last distinction is a useful signal about what the maintainers expect. The repository is treated as a document to be corrected, not a program to be debugged.

Installing nothing: forking the plan and starting Day 1

There is nothing to install. The repository is Markdown plus a translations directory, so the first real use is cloning or forking it and opening the plan. If you have Git, the clone is one command.

bash
git clone https://github.com/farhanashrafdev/90DaysOfCyberSecurity.git
cd 90DaysOfCyberSecurity

After the clone you should see README.md, learn.md, License.md, translations/ and .all-contributorsrc at the top level. The README is the plan itself; learn.md is the full resource list the README points to. Open learn.md before you start.

If you would rather not use Git, the README's own instruction is to fork the repo or copy the plan into a notes file and tick off each day as you finish it. That is the whole setup.

The first task is Day 1-7: Network+. The README gives one action and one follow-up.

text
- Watch videos from Professor Messer's N10-009 Playlist
- Complete any related practice questions or exercises.

What you should see is a YouTube playlist of Network+ videos and a set of practice questions. The README does not prescribe a specific question bank, so the choice is yours. The same pattern repeats for every block: a named resource or two, then practice.

Where the plan breaks down

The main limitation is verification. Nothing in the repository checks whether you understood a topic. There are no exercises authored in-repo, no answer keys, no labs to submit, and no assessment at the end of a block. The README's instruction to "complete any related practice questions or exercises" leaves the source of those questions open. For a self-learner with discipline this is fine; for someone who needs external accountability, it is the weak point.

The second limitation is link dependency. Almost every day is an outbound URL, and the README already anticipates one failure mode: paywalled content, with the advice to use alternatives in the same section or in learn.md. Dead links are the other, which is presumably why the README routes link fixes to issues and everything else to Discussions.

The third is depth. A week for Network+ and a week for Security+ is enough to watch a playlist, not enough to sit either exam comfortably. The README concedes this by calling certifications optional. The cloud block is one week for one provider, and the hacking block is six days at the very end. If your goal is hands-on offensive skill, six days of videos after 84 days of fundamentals is the wrong shape, and the README's own warning against skipping ahead would push you away from the part you came for.

Finally, the plan is not a substitute for a lab environment. The README points at LabEx and Cisco NetAcad for hands-on Linux, and at Wireshark and Suricata material that implies packet captures to inspect, but the repository itself ships no capture files, no VM images and no configuration.

How this differs from TryHackMe and similar platforms

The obvious alternative is a hosted learning platform such as TryHackMe, which appears in the related searches around this project. The difference is architectural. TryHackMe runs the environment: you connect to machines it hosts, complete tasks inside a browser, and the platform records completion. This repository runs nothing. It is a static Markdown plan that sends you to third-party sites, and your progress lives in your own fork or notes file.

That trade has real consequences in both directions. A hosted platform gives you graded tasks, a progress record and a consistent interface, but you are tied to its catalogue, its pricing and its account. This plan is free by design ("Everything is free" in the README) and portable: nothing stops you from swapping Professor Messer for Pete Zerger, or Linux Journey for Linux Unhatched, because the plan names alternatives rather than locking you in. The cost is that you assemble the environment yourself and nothing tells you when you are done with a topic.

A second difference is scope. The plan deliberately spans networking, Linux, Python, Git, ELK, cloud and hacking, plus a job-search tail on resume writing and applications. A platform focused on offensive security will not spend two weeks on Python fundamentals or a week on Git. Whether that breadth is a feature depends on whether you are building a base or sharpening a specialty.

Licence, maintenance and what a fork costs you

The repository is MIT licensed, with the licence text in License.md. For a study plan that means you can copy it, adapt it, translate it and redistribute it, including commercially, provided the licence terms are met. The translations/ directory shows that reuse already happens in practice. This is not legal advice; read License.md if you plan to redistribute.

On maintenance, the last push was on 2026-09-06, which is recent. The repository is not archived. There are no releases, which fits a document-only project: there is nothing to version and nothing to upgrade. The upgrade cost of adopting this plan is therefore near zero in the software sense and non-trivial in the content sense. Every external link is a dependency you did not pin, and course URLs, playlists and free tiers change without notice. The README's fallback rule (use the alternatives in the same section or learn.md) is the only mitigation offered.

If you fork it for a cohort or a study group, budget time for link checking. The repository's own contribution model treats broken links as issues, which tells you the maintainers expect them.

Editorial conclusion

Adopt it if you want a dated, ordered checklist pointing at free courses and you accept that the actual teaching happens on YouTube, Linux Journey, Wireshark's site and Cisco NetAcad, not here. Do not adopt it if you want graded labs, a certificate, or a single self-contained course; the README states certifications are optional and the plan is self-paced, so nothing verifies your work. Before day one, open learn.md and click the Day 1-7 Network+ playlist, the Day 15-28 Linux Journey link and the Day 43-56 Wireshark University link, and confirm each still loads; the README's own guidance says to use the alternatives in the same section when a site paywalls content.

Frequently asked questions

Can I learn cybersecurity in 90 days with this plan?

The README frames the plan as building a strong foundation, not as producing a job-ready specialist in 90 days. It also says the day numbers are a guide rather than a deadline, and that certifications such as Network+ and Security+ are optional. Treat the schedule as a structure for consistent study, not a guarantee.

Is 90DaysOfCyberSecurity still worth following in 2026?

The repository is not archived and the last push was on 2026-09-06, so the plan is being touched. Its content is a set of links to free external courses, which is the part that ages; the README tells you to use the alternatives in the same section or in learn.md when a resource is paywalled or unavailable.

Does 90DaysOfCyberSecurity award a certification?

No. The README states that certifications are optional and that the Network+ and Security+ playlists teach the concepts you need without requiring you to sit the exams. The repository is a study plan, and its licence is MIT.

How much time per day does the 90DaysOfCyberSecurity plan require?

The Start Here section gives a time budget of 1 to 2 focused hours a day, and says it is fine to spend longer on a topic. It also says to follow the order, because Days 1-28 are the foundation for everything after them.

What should I do if a link in 90DaysOfCyberSecurity is broken or paywalled?

The README says that if a site puts content behind a paywall, use the alternatives listed in the same section or in learn.md. Broken links and content fixes are handled through issues; general questions go to GitHub Discussions.

Official sources

  1. farhanashrafdev/90DaysOfCyberSecurity on GitHub
  2. Issues
  3. License: MIT
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/farhanashrafdev-90daysofcybersecurity.svg)](https://hysenlabs.com/projects/farhanashrafdev-90daysofcybersecurity)