root@rochacrypt:~# ls ~/security-knowledge-base | wc -l
50 # certifications & frameworks, 5 I hold ✔️The 50 security certifications and frameworks that matter, each distilled to the same shape so a visitor can size up any credential in under a minute:
🔎 What it is · 🎯 What it validates · 🧠 Key concepts · 🗺️ Mind map · 🔥 In the field
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#3a0008','primaryTextColor':'#ffffff','primaryBorderColor':'#ff2e4c','lineColor':'#ff2e4c','fontSize':'13px','cScale0':'#ff2e4c','cScale1':'#2e6bff','cScale2':'#8a63ff','cScale3':'#ffb02e','cScale4':'#2ecc71','cScale5':'#3a0008','cScale6':'#a3162e','cScale7':'#6e0f1f','cScale8':'#ff5c73','cScale9':'#4a0d17','cScale10':'#b81f36','cScale11':'#2a0006','cScaleLabel0':'#ffffff','cScaleLabel1':'#ffffff','cScaleLabel2':'#ffffff','cScaleLabel3':'#ffffff','cScaleLabel4':'#ffffff','cScaleLabel5':'#ffffff','cScaleLabel6':'#ffffff','cScaleLabel7':'#ffffff','cScaleLabel8':'#ffffff','cScaleLabel9':'#ffffff','cScaleLabel10':'#ffffff','cScaleLabel11':'#ffffff'}}}%%
mindmap
root((Security))
Offensive
OSCP
OSEP
CRTO
Defensive
Security Plus
GCFA
Blue Team
Cloud
AWS
Azure
Kubernetes
Governance
CISSP
CRISC
Privacy
Frameworks
MITRE ATTACK
NIST CSF
ISO 27001
🔴 Offensive Security (12) · 🔵 Defensive & Blue Team (12) · ☁️ Cloud Security (7) · 📊 Governance, Risk & AI (8) · 🧭 Frameworks & Standards (11)
Level: ⭐ foundation → ⭐⭐⭐⭐⭐ expert · ✔️ = a credential I personally hold
| Cert / Framework | Focus | Level | |
|---|---|---|---|
| ⚔️ | CEH ✔️ | Broad offensive fundamentals | ⭐⭐⭐ |
| 🐣 | eJPT | Beginner practical pentest | ⭐ |
| 🟠 | BSCP | Hands-on web (Burp) | ⭐⭐⭐ |
| 🎯 | PenTest+ | Pentest + engagement mgmt | ⭐⭐⭐ |
| 🎖️ | PNPT | Real-world engagement + debrief | ⭐⭐⭐ |
| 🌐 | GWAPT | Web app pentest (GIAC) | ⭐⭐⭐ |
| 🏰 | CRTP | Active Directory attacks | ⭐⭐⭐ |
| 🗡️ | OSCP | Hands-on pentest benchmark | ⭐⭐⭐⭐ |
| 👹 | CRTO | Red team ops & C2 | ⭐⭐⭐⭐ |
| 🥷 | OSEP | Evasion & advanced attacks | ⭐⭐⭐⭐⭐ |
| 🕷️ | OSWE | White-box web exploitation | ⭐⭐⭐⭐⭐ |
| 🧬 | GXPN | Exploit dev & advanced pentest | ⭐⭐⭐⭐⭐ |
| Cert / Framework | Focus | Level | |
|---|---|---|---|
| 🔰 | EHE & NDE ✔️ | Attack + defence basics | ⭐ |
| 🛡️ | Security+ | Security foundations | ⭐ |
| 🧱 | Fortinet FCA ✔️ | FortiGate fundamentals | ⭐ |
| 🔷 | BTL1 | Practical blue team | ⭐⭐ |
| 📗 | GSEC | Broad security essentials | ⭐⭐ |
| 🔧 | SSCP | Operational security | ⭐⭐⭐ |
| 📈 | CySA+ | SOC & threat analytics | ⭐⭐⭐ |
| 🚨 | GCIH | Incident handling | ⭐⭐⭐ |
| 🦅 | CCFA ✔️ | CrowdStrike Falcon admin | ⭐⭐⭐ |
| 🟦 | SC-200 | Microsoft SOC (Sentinel) | ⭐⭐⭐ |
| 🔬 | GCFA | Forensics & DFIR | ⭐⭐⭐⭐ |
| 🔶 | BTL2 | Advanced blue team | ⭐⭐⭐⭐ |
| Cert / Framework | Focus | Level | |
|---|---|---|---|
| ⛅ | CCSK | Vendor-neutral cloud basics | ⭐⭐ |
| 🟦 | AZ-500 | Azure security engineer | ⭐⭐⭐ |
| 🟧 | AWS Security Specialty | Security across AWS | ⭐⭐⭐⭐ |
| 🟪 | CCSP | Vendor-neutral cloud (ISC2) | ⭐⭐⭐⭐ |
| 🟥 | GCP Security Engineer | Security on Google Cloud | ⭐⭐⭐⭐ |
| ☸️ | CKS | Kubernetes security | ⭐⭐⭐⭐ |
| 🏢 | SC-100 | Cybersecurity architect | ⭐⭐⭐⭐⭐ |
| Cert / Framework | Focus | Level | |
|---|---|---|---|
| 🤖 | CLLMSP ✔️ | LLM application security | ⭐⭐ |
| 📋 | CGRC | Authorisation & RMF | ⭐⭐⭐ |
| 🔐 | CDPSE | Technical data privacy | ⭐⭐⭐ |
| 🇪🇺 | CIPP/E | European privacy law (GDPR) | ⭐⭐⭐ |
| ⚖️ | CRISC | IT risk management | ⭐⭐⭐⭐ |
| 🔍 | CISA | IT audit & assurance | ⭐⭐⭐⭐ |
| 📊 | CISM | Security programme mgmt | ⭐⭐⭐⭐ |
| 🏛️ | CISSP | Senior security management | ⭐⭐⭐⭐ |
| Cert / Framework | Focus | Level | |
|---|---|---|---|
| 🎛️ | MITRE ATT&CK | Adversary tactics matrix | — |
| 🛠️ | MITRE D3FEND | Defensive countermeasures | — |
| ⛓️ | Cyber Kill Chain | 7-stage intrusion model | — |
| 🏗️ | NIST CSF 2.0 | Risk-based framework | — |
| ✅ | CIS Controls | Prioritised safeguards | — |
| 📕 | ISO/IEC 27001 | ISMS standard | — |
| 📑 | SOC 2 | Trust & assurance report | — |
| 💳 | PCI DSS | Payment card security | — |
| 🕸️ | OWASP Top 10 | Web app risks | — |
| 🧩 | PTES | Pentest methodology | — |
| 🌡️ | CVSS | Vulnerability scoring | — |
A living catalog — corrections and additions welcome.
- ⭐ Star it if it's useful — it helps others find it.
- 🐛 Open an issue for corrections or an updated exam code.
- 💬 Ask or discuss in Discussions.
⚠️ Exam formats, codes and framework versions change. Each page links its official source — always verify current details there before booking or citing. Maps for credentials I don't personally hold are study references built from public outlines, and are marked without the ✔️.
