Case file
Twenty YouTube channels on the Sentinel's watch list
Reading about a technique is theory; watching someone drive it in a lab is apprenticeship. These twenty channels are the Sentinel’s editorial selection of the best hands-on security teaching on YouTube, chosen by one criterion: does the creator show real work, in a real environment, with the mistakes left in? Links go to each channel’s official presence; the list is reviewed yearly per the disclosures policy.
Hands-on offensive craft.
- John Hammond — malware analysis and CTF walkthroughs at a working professional’s pace; the channel a defender can copy from line by line.
- IppSec — the HackTheBox walkthrough canon. If a box teaches a technique, IppSec has a video that teaches it better.
- LiveOverflow — binary exploitation and hardware, explained from first principles with rare intellectual honesty about what he doesn’t know.
- NahamSec — bug-bounty methodology in public; recon workflows and collaborative hunting.
- STÖK — bug-bounty culture and craft, filmed like a documentary; the videos that made recon feel like a discipline.
- InsiderPhD — Katie Paxton-Fear teaches API-focused bug hunting the way a lecturer would, with weekly “how to start” energy for newcomers.
- TCM Security — Heath Adams and the TCM team; the most approachable full-course pipeline (PEH, PJPT) on free YouTube.
Networks, infrastructure, and the trade’s plumbing.
- David Bombal — networking first, then everything that attacks it; interviews with the people who found the flaws.
- NetworkChuck — the gateway drug: networking and security concepts with maximum energy; recommended to every newcomer first.
- Network Direction — clean, diagram-driven networking fundamentals that the security field quietly assumes everyone has.
- Grant Collins — structured cyber-career curricula, from fundamentals through purple-team labs.
Defense, forensics, and malware.
- 13Cubed — Richard Davis’s digital-forensics and incident-response videos; quietly the best DFIR teaching on the platform.
- OALabs — malware-analysis sessions on real samples, with the unpacking shown step by step.
- HackerSploit — full offensive-security courses and red-team tooling walkthroughs, free and systematic.
- Seytonic — hardware hacking, firmware, and “how the bad gadget works” teardowns.
Culture, conferences, and the human layer.
- DEF CON Channel — the talk archive itself. Twenty years of the field’s most influential presentations, primary-source and free.
- Computerphile — not a security channel, but Dr. Mike Pound’s explanations of hashing, TLS, and cryptanalysis are the best short lectures on the internet.
- Jim Browning — scam-baiting turned inside out: actual remote-access forensics applied to the call-center scam industry, with receipts.
- PwnFunction — animated explainers (XSS, CSRF, sandbox escapes) in five minutes flat; the fastest conceptual on-ramps on the list.
- Simply Cyber — Gerald Auger’s daily news brief and career tracks; the daily habit channel for people entering the field.
How the Sentinel keeps this honest
Same rules as the podcast list: editorial selection, dated 20 September 2026, re-verified annually, no sponsorship, no pitch-driven placements. Channels retire or change direction; when one no longer meets the “real work, mistakes left in” bar, it comes off the list with a dated note.
Sources & attributions
- Each channel links to its official YouTube presence; descriptions reflect the channels’ own stated focus.
- Curation criteria and update policy: Disclosures — editorial & sourcing policy.
- Cross-references: Twenty podcasts on rotation, Twenty sites in scope.