11 · Life Plan
Tasks
What I am actively working on, with status, published so the list itself becomes accountability. Smaller than goals, more granular than the Master Plan's artifact backlog. Edits flow through the vault — the public read-only view is here.
Lifetime
- Cybersecurity Ethics andopencybersecurity
Scope Policy A personal code of conduct for legal and ethical testing.
Done means:
- authorization rules written
- scope rules written
- responsible disclosure rules written
- stopping conditions defined
Priority: Very high
- Security Lab Setup Manualopencybersecurity
A guide for VMs, snapshots, isolated networks, Kali/Parrot, vulnerable labs, and safe practice environments.
Done means:
- lab architecture documented
- VM setup steps included
- reset/snapshot process included
- legal-only reminder included
Priority: Very high
- Linux and Networkingopencybersecurity
Security Notebook A combined notebook for Linux permissions, processes, services, logs, TCP/IP, DNS, HTTP, TLS, ports, subnetting, and packet captures.
Done means:
- notes exist
- practice labs completed
- Wireshark examples included
- common commands documented
Priority: Very high
- Web Security Foundationsopencybersecurity
Notebook A notebook on HTTP, cookies, sessions, auth, authorization, CORS, browser security, APIs, SQL basics, and common web failure points.
Done means:
- concepts explained
- examples included
- developer prevention notes included
Priority: High
- OWASP / PortSwigger Labopencybersecurity
Archive A structured archive of web security lab notes and vulnerability-class explanations.
Done means:
- labs categorized
- root causes explained
- remediation included
- no unauthorized material included
Priority: High
- Enumeration Methodologyopencybersecurity
Playbook A repeatable legal-lab methodology for enumeration, service analysis, note-taking, attack-path mapping, and evidence collection.
Done means:
- checklist exists
- service notes exist
- attack-path template exists
- dead-end review process exists
Priority: Very high
- HTB Academy Penetrationopencybersecurity
Tester Tracker A tracker for HTB modules, notes, exercises, weak areas, checklists, and CPTS readiness.
Done means:
- all modules listed
- progress tracked
- notes linked
- weak areas marked
Priority: High
- Vulnerability Reportopencybersecurity
Template Pack A professional set of report templates for lab findings, executive summaries, evidence, impact, remediation, and retesting.
Done means:
- templates exist
- sample lab report exists
- severity explanation included
- evidence handling rules included
Priority: High
- CPTS / OSCP Readinessopencybersecurity
Portfolio A private or semi-private portfolio of practice reports, methodology, checklists, weak-area reviews, and exam readiness evidence.
Done means:
- readiness checklist exists
- practice reports exist
- weak areas listed
- revision plan exists
Priority: Later high
- Bug Bounty Scopeopencybersecurity
Analysis Template A template for reading program scope, exclusions, safe harbor, assets, testing limits, and report requirements.
Done means:
- template exists
- at least one sample public program analyzed safely
- rules of engagement section exists
Priority: Medium-high after labs