You can build a useful cybersecurity home lab for free on the laptop you already own: a hypervisor (VirtualBox or VMware), an attacker machine (Kali Linux), one or two deliberately vulnerable targets (Metasploitable 2 and OWASP Juice Shop), and a private host-only network that keeps the vulnerable machines away from your home network and the internet. This guide walks through that exact setup, then shows how to grow it once you outgrow the basics.
Everything here runs on your own machine against targets you own. Only test systems you own or have written permission to test.
What you need before you start
Hardware
| Component | Workable | Comfortable |
|---|---|---|
| RAM | 8 GB | 16 GB or more |
| Free disk space | 60 GB | 120 GB+ on an SSD |
| CPU | Any 64-bit CPU with virtualisation support | 4+ cores |
Virtualisation must be switched on in your BIOS/UEFI (Intel VT-x or AMD-V). If VirtualBox complains that hardware virtualisation is unavailable, that’s the first thing to check.
Apple Silicon Macs (M1 and later): Kali has ARM builds and Docker runs fine, so Juice Shop works. Metasploitable 2 is an old 32-bit x86 image and won’t run natively; you’d need emulation (UTM can do it, slowly), or use Juice Shop and other ARM-friendly targets instead.
Software, all free
- A hypervisor. Oracle VirtualBox is free and open source. VMware Workstation Pro (Windows and Linux) and VMware Fusion (Mac) are also free for personal use; check Broadcom’s download page for current terms.
- Kali Linux, as a pre-built virtual machine image from kali.org.
- Metasploitable 2, the intentionally vulnerable Linux VM published by Rapid7. Its documentation links the download.
- OWASP Juice Shop, a deliberately insecure web shop maintained by OWASP, which we’ll run in Docker.
The lab we’re building
Your laptop (host)
+-------------------------------------------+
| NAT adapter (internet, for updates only) |
| | |
| +---------+ |
| | Kali | eth0: NAT |
| | | eth1: 192.168.56.x |
| | Docker: Juice Shop on 127.0.0.1:3000 |
| +---------+ |
| | host-only network |
| | vboxnet0 192.168.56.0/24 |
| +----------------+ |
| | Metasploitable | host-only ONLY |
| | 192.168.56.x | (no internet) |
| +----------------+ |
+-------------------------------------------+
The rule that matters: the vulnerable machine has no route to the internet or your home network. Kali gets two adapters, one for updates and one for the lab. Metasploitable gets only the host-only adapter.
Step 1: Install the hypervisor
VirtualBox: download the installer for your operating system from virtualbox.org and install with the defaults. On Windows, it will briefly drop your network connection while it installs its virtual adapters; that’s normal. Also install the matching Extension Pack only if you need its features (USB 2/3 passthrough, for example); the lab doesn’t require it.
VMware Workstation Pro: install it, and the host-only network (VMnet1) is created for you. You can view or change it under Edit > Virtual Network Editor. The rest of this guide uses VirtualBox menu names; the VMware equivalents are noted where they differ.
Step 2: Create the host-only network
In VirtualBox 7:
- Open File > Tools > Network Manager (on some versions, Tools > Network).
- Select the Host-only Networks tab and click Create.
- Set the adapter to
192.168.56.1with mask255.255.255.0. - On the DHCP Server tab, tick Enable Server. Defaults such as server
192.168.56.100, lower bound192.168.56.101and upper bound192.168.56.254are fine.
Or from a terminal on the host:
VBoxManage hostonlyif create
VBoxManage hostonlyif ipconfig vboxnet0 --ip 192.168.56.1 --netmask 255.255.255.0
VBoxManage dhcpserver add --ifname vboxnet0 --server-ip 192.168.56.100 \
--netmask 255.255.255.0 --lower-ip 192.168.56.101 --upper-ip 192.168.56.254 --enable
On Windows hosts the interface will have a longer name, such as “VirtualBox Host-Only Ethernet Adapter”; use whatever name VBoxManage list hostonlyifs shows. On Linux and macOS hosts, VirtualBox only allows host-only addresses in 192.168.56.0/21 by default (controlled by /etc/vbox/networks.conf), which is why we use that range. The VirtualBox manual’s networking chapter covers the details.
On macOS with VirtualBox 7, use Host-only Networks (VBoxManage hostonlynet add --name=lab --netmask=255.255.255.0 --lower-ip=192.168.56.101 --upper-ip=192.168.56.254 --enable) and attach VMs to that network instead of vboxnet0.
Step 3: Import Kali
- On kali.org, download the VirtualBox (or VMware) pre-built image. It arrives as a compressed
.7zfile. - Verify the download against the SHA256 checksum shown on the download page:
# Linux
sha256sum kali-linux-*-virtualbox-amd64.7z
# macOS
shasum -a 256 kali-linux-*-virtualbox-amd64.7z
# Windows PowerShell
Get-FileHash .\kali-linux-*-virtualbox-amd64.7z -Algorithm SHA256
If the hash doesn’t match the one on the site, delete the file and download it again. Checking hashes is a habit worth building now; it’s how you know a file hasn’t been tampered with.
- Extract the archive (7-Zip on Windows,
7z xon Linux, or any archive tool on Mac) and double-click the.vboxfile, or use Machine > Add in VirtualBox. - Before you start it, open Settings > Network:
- Adapter 1: NAT (internet for updates).
- Adapter 2: tick Enable, attach to Host-only Adapter, name
vboxnet0.
- Give it at least 2 GB of RAM, more if you can spare it.
- Start the VM and log in. The pre-built images use the default credentials listed in Kali’s documentation. Change the password immediately and update:
passwd
sudo apt update && sudo apt full-upgrade -y
Check both interfaces are up:
$ ip -brief addr
lo UNKNOWN 127.0.0.1/8 ::1/128
eth0 UP 10.0.2.15/24 fe80::a00:27ff:fe4e:66a1/64
eth1 UP 192.168.56.101/24 fe80::a00:27ff:fe9c:21b7/64
eth0 on 10.0.2.15 is VirtualBox’s NAT; eth1 is your lab network. If eth1 has no address, run sudo nmcli device connect eth1 (or sudo dhclient eth1 if installed) or check that the DHCP server from Step 2 is enabled.
Step 4: Add Metasploitable 2
Metasploitable 2 is intentionally full of holes. Treat it like something that could bite: never bridge it to your home network and never expose it to the internet.
- Download the Metasploitable 2 zip via the link in Rapid7’s documentation and extract it. Inside is a
.vmdkvirtual disk. - In VirtualBox, click New. Name it
metasploitable2, Type Linux, Version Ubuntu (32-bit) or Other Linux (32-bit). 512 MB of RAM is enough. - At the hard disk step, choose Use an existing virtual hard disk file and select the
.vmdk. - In Settings > Network, set Adapter 1 to Host-only Adapter,
vboxnet0. Make sure no other adapter is enabled. - Start it and log in with the default credentials from Rapid7’s documentation (they’re printed on the login banner too). Find its address:
msfadmin@metasploitable:~$ ifconfig eth0 | grep “inet addr”
inet addr:192.168.56.102 Bcast:192.168.56.255 Mask:255.255.255.0
(Metasploitable 2 is old enough to still use ifconfig.)
VMware users: Rapid7’s zip includes a .vmx file, so you can open it directly; then set its network adapter to Host-only.
Step 5: Run OWASP Juice Shop in Docker on Kali
Juice Shop is a modern, intentionally insecure web application, a good counterpart to Metasploitable’s older services. Running it in Docker on Kali keeps things light.
sudo apt install -y docker.io
sudo systemctl enable --now docker
sudo docker run -d --name juice-shop -p 127.0.0.1:3000:3000 bkimminich/juice-shop
Binding to 127.0.0.1 means Juice Shop is reachable only from inside Kali, not from your lab network or anywhere else. Open Firefox in Kali and go to http://localhost:3000.
$ sudo docker ps
CONTAINER ID IMAGE COMMAND STATUS PORTS NAMES
4f2a9c1e7b3d bkimminich/juice-shop “/nodejs/bin/node /j…” Up 2 minutes 127.0.0.1:3000->3000/tcp juice-shop
To stop and start it later: sudo docker stop juice-shop and sudo docker start juice-shop. The Juice Shop project also has a free companion guide, Pwning OWASP Juice Shop, linked from its OWASP page.
Step 6: Prove the lab works
From Kali, confirm you can reach Metasploitable and see its services:
$ ping -c 2 192.168.56.102
PING 192.168.56.102 (192.168.56.102) 56(84) bytes of data.
64 bytes from 192.168.56.102: icmp_seq=1 ttl=64 time=0.612 ms
64 bytes from 192.168.56.102: icmp_seq=2 ttl=64 time=0.498 ms
$ sudo nmap -sV 192.168.56.102
Starting Nmap 7.95 ( https://nmap.org )
Nmap scan report for 192.168.56.102
Host is up (0.00051s latency).
Not shown: 977 closed tcp ports (reset)
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.3.4
22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
23/tcp open telnet Linux telnetd
25/tcp open smtp Postfix smtpd
53/tcp open domain ISC BIND 9.4.2
80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2)
111/tcp open rpcbind 2 (RPC #100000)
139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
512/tcp open exec netkit-rsh rexecd
513/tcp open login OpenBSD or Solaris rlogind
514/tcp open tcpwrapped
1099/tcp open java-rmi GNU Classpath grmiregistry
1524/tcp open bindshell Metasploitable root shell
2049/tcp open nfs 2-4 (RPC #100003)
2121/tcp open ftp ProFTPD 1.3.1
3306/tcp open mysql MySQL 5.0.51a-3ubuntu5
5432/tcp open postgresql PostgreSQL DB 8.3.0 - 8.3.7
5900/tcp open vnc VNC (protocol 3.3)
6000/tcp open X11 (access denied)
6667/tcp open irc UnrealIRCd
8009/tcp open ajp13 Apache Jserv (Protocol v1.3)
8180/tcp open http Apache Tomcat/Coyote JSP engine 1.1
Your Nmap version and exact lines may differ slightly. That list is your first assignment: pick one service, research why that version is a problem, and write down how a defender would fix it. Our Nmap commands cheat sheet explains the flags and what to try next.
Now check the isolation. From Metasploitable, ping -c 2 8.8.8.8 should fail. If it succeeds, Metasploitable has a route out; go back and remove any NAT or bridged adapter.
Step 7: Take snapshots before you break things
Snapshots let you roll back in seconds after you’ve wrecked a VM, which you will.
VBoxManage snapshot “kali-lab” take “clean-updated”
VBoxManage snapshot “metasploitable2” take “clean”
Replace kali-lab with the exact name that VBoxManage list vms prints for your Kali VM. In the GUI it’s the Snapshots view for each machine. To roll back: VBoxManage snapshot “metasploitable2” restore “clean” with the VM powered off.
Free vs low-cost: how to grow the lab
| Upgrade | Cost | What it adds |
|---|---|---|
| A Windows evaluation VM from Microsoft’s Evaluation Center | Free (time-limited) | Practise Windows logs, PowerShell and Active Directory basics |
| An Ubuntu Server VM with logging turned up | Free | A “defended” server to watch from the blue-team side |
| An open-source SIEM, such as Wazuh, or a monitoring distribution such as Security Onion | Free software, but RAM-hungry | Real alerting and log searching, as in a SOC |
| More RAM in your laptop | Low cost | Run three or four VMs at once without slowdowns |
| A second-hand mini PC or old desktop as a dedicated lab box | Low cost | Leaves your main laptop free; can run a bare-metal hypervisor such as Proxmox |
| Browser-based labs (PortSwigger’s Web Security Academy) | Free | Web attack practice with no local setup |
Check each tool’s official documentation for current hardware requirements before installing; SIEMs in particular need more memory than a basic lab.
Home lab project ideas
A lab is only useful if you do something with it and write it up. These projects make good CV and interview material.
Offensive (penetration testing path):
- Enumerate every service on Metasploitable 2, rank them by risk, and write a short findings report with remediation for each.
- Work through Juice Shop’s scoreboard challenges, starting with the one-star ones, and map each to an OWASP Top 10 category.
- Capture an FTP or Telnet login to Metasploitable in Wireshark and explain why cleartext protocols are dangerous.
Defensive (SOC path):
- Send Metasploitable’s or Ubuntu’s logs to a SIEM and write a detection rule for repeated failed SSH logins.
- Run an Nmap scan from Kali, then find the evidence of it in your target’s logs or packet capture. What would a SOC analyst see?
- Harden an Ubuntu Server VM (disable root SSH, set up a firewall with
ufw, remove unused services), then rescan and compare.
The SOC analyst roadmap suggests which defensive skills to prioritise, and how to become a penetration tester covers the offensive side.
Safety rules for any home lab
- Keep vulnerable VMs on host-only or internal networks. Never bridged, never port-forwarded.
- Don’t download “cracked” tools or random exploit binaries. Use your distribution’s package manager and official project pages.
- Scan only your lab (and
scanme.nmap.orgfor light tests, which the Nmap project allows). Scanning other people’s systems without permission can be illegal, including from home. - Snapshot before experiments and restore when you’re done.
- Keep Kali updated; it’s software like any other.