Case file

Twenty YouTube channels on the Sentinel's watch list

Reading about a technique is theory; watching someone drive it in a lab is apprenticeship. These twenty channels are the Sentinel’s editorial selection of the best hands-on security teaching on YouTube, chosen by one criterion: does the creator show real work, in a real environment, with the mistakes left in? Links go to each channel’s official presence; the list is reviewed yearly per the disclosures policy.

Hands-on offensive craft.

  1. John Hammond — malware analysis and CTF walkthroughs at a working professional’s pace; the channel a defender can copy from line by line.
  2. IppSec — the HackTheBox walkthrough canon. If a box teaches a technique, IppSec has a video that teaches it better.
  3. LiveOverflow — binary exploitation and hardware, explained from first principles with rare intellectual honesty about what he doesn’t know.
  4. NahamSec — bug-bounty methodology in public; recon workflows and collaborative hunting.
  5. STÖK — bug-bounty culture and craft, filmed like a documentary; the videos that made recon feel like a discipline.
  6. InsiderPhD — Katie Paxton-Fear teaches API-focused bug hunting the way a lecturer would, with weekly “how to start” energy for newcomers.
  7. TCM Security — Heath Adams and the TCM team; the most approachable full-course pipeline (PEH, PJPT) on free YouTube.

Networks, infrastructure, and the trade’s plumbing.

  1. David Bombal — networking first, then everything that attacks it; interviews with the people who found the flaws.
  2. NetworkChuck — the gateway drug: networking and security concepts with maximum energy; recommended to every newcomer first.
  3. Network Direction — clean, diagram-driven networking fundamentals that the security field quietly assumes everyone has.
  4. Grant Collins — structured cyber-career curricula, from fundamentals through purple-team labs.

Defense, forensics, and malware.

  1. 13Cubed — Richard Davis’s digital-forensics and incident-response videos; quietly the best DFIR teaching on the platform.
  2. OALabs — malware-analysis sessions on real samples, with the unpacking shown step by step.
  3. HackerSploit — full offensive-security courses and red-team tooling walkthroughs, free and systematic.
  4. Seytonic — hardware hacking, firmware, and “how the bad gadget works” teardowns.

Culture, conferences, and the human layer.

  1. DEF CON Channel — the talk archive itself. Twenty years of the field’s most influential presentations, primary-source and free.
  2. Computerphile — not a security channel, but Dr. Mike Pound’s explanations of hashing, TLS, and cryptanalysis are the best short lectures on the internet.
  3. Jim Browning — scam-baiting turned inside out: actual remote-access forensics applied to the call-center scam industry, with receipts.
  4. PwnFunction — animated explainers (XSS, CSRF, sandbox escapes) in five minutes flat; the fastest conceptual on-ramps on the list.
  5. Simply Cyber — Gerald Auger’s daily news brief and career tracks; the daily habit channel for people entering the field.

How the Sentinel keeps this honest

Same rules as the podcast list: editorial selection, dated 20 September 2026, re-verified annually, no sponsorship, no pitch-driven placements. Channels retire or change direction; when one no longer meets the “real work, mistakes left in” bar, it comes off the list with a dated note.

Sources & attributions

  1. Each channel links to its official YouTube presence; descriptions reflect the channels’ own stated focus.
  2. Curation criteria and update policy: Disclosures — editorial & sourcing policy.
  3. Cross-references: Twenty podcasts on rotation, Twenty sites in scope.