Festival Season Offer15% off on all our programmes — claim it before you enrol
← All Career InsightsCyber Security

How do I set up a safe home lab to practise ethical hacking?

A safe home lab is a small, isolated set of virtual machines that you own and are allowed to attack. You need a virtualisation tool, one attacker machine such as Kali Linux, a few deliberately vulnerable targets, and a private virtual network that cannot reach your home devices or the internet unless you choose. Snapshots let you break things and reset in seconds.

Why a lab comes before any real target

Ethical hacking is only ethical when you have permission. Scanning or attacking a system you do not own, or have not been authorised in writing to test, can break the law even if you mean no harm. A home lab removes that risk: every machine in it is yours, so you can practise reconnaissance, exploitation and clean-up as often as you like.

A lab also teaches things a video cannot. You see how a misconfigured service really behaves, what your tools send over the network, and what traces an attack leaves in logs. That defensive view is what makes lab practice useful in interviews for both offensive and SOC roles.

What you need before you start

Most learners can start on the laptop they already have:

  • A computer with enough memory to run two or three virtual machines at once. 16 GB of RAM is comfortable; 8 GB works if you run one target at a time.
  • A free virtualisation tool such as VirtualBox or VMware Workstation Player, with hardware virtualisation switched on in the BIOS.
  • An attacker machine. Kali Linux and Parrot OS ship with the common tools already installed.
  • Deliberately vulnerable targets made for practice, such as Metasploitable 2, DVWA (Damn Vulnerable Web Application) or OWASP Juice Shop.
  • A notebook or document where you record each exercise: the goal, the commands you ran, what worked and how you would detect or fix it.

Building the lab step by step

Set the network up first. Most lab mistakes come from a vulnerable machine that can be reached from outside the lab.

  1. Create a private virtual network

    In your virtualisation tool, create a host-only or internal network. Machines on it can talk to each other but not to your home router or other devices. Do not attach vulnerable targets to a bridged network.

  2. Install the attacker machine

    Import the Kali Linux virtual machine image, give it two network adapters if you need updates (one NAT for the internet, one on the private network), and update it before you disconnect the NAT adapter.

  3. Add one vulnerable target

    Import Metasploitable 2 or run DVWA, and connect it only to the private network. Never give these machines internet access; they are insecure by design.

  4. Confirm the isolation

    From the target, check that it cannot reach the internet. From your normal computer, check that you cannot reach the target. Only the attacker machine should see it.

  5. Take clean snapshots

    Snapshot every machine in its fresh state. After each exercise, roll back so you always start from a known point and practise the same attack cleanly.

  6. Add a way to watch the traffic

    Run Wireshark on the attacker machine, or add a small logging target, so you can see what each scan and exploit looks like from the defender's side.

First exercises worth doing in order

Work through these slowly and write up each one:

  • Discover the target and its open services with a network scan, then explain what each open port is for.
  • Identify the versions of those services and look up their known weaknesses.
  • Exploit one weakness in a controlled way, then list what changed on the target.
  • Practise common web flaws such as SQL injection and cross-site scripting in DVWA, starting at the lowest difficulty.
  • For every exploit, write the fix and how a defender would spot the attack in logs.

Quick answers about ethical hacking home labs

Short answers to what learners ask most.

Is it legal to practise hacking at home?

It is legal to practise on systems you own, such as the virtual machines in your own lab, and on platforms that give you explicit permission. Testing any other system without written authorisation can be illegal, even for learning.

Can I build a hacking lab without buying anything?

Yes. VirtualBox, Kali Linux, Metasploitable 2, DVWA and OWASP Juice Shop are free. The only real cost is a computer with enough memory to run a few virtual machines.

How much RAM do I need for a home lab?

16 GB lets you run an attacker and one or two targets together comfortably. With 8 GB you can still learn by running the attacker and a single small target at a time.

Should my lab machines be connected to the internet?

Vulnerable targets should never be. Keep them on a host-only or internal network. Give the attacker machine internet access only when you need updates, then switch it back.

Are online practice platforms a replacement for a home lab?

They are a good addition, because they offer ready-made challenges. Your own lab still teaches you to build, isolate and reset an environment, which is a useful skill in itself.

Where to go next after your first lab

See how lab work fits into the full syllabus, or read the guides that take these exercises further.

See the Cyber Security programmeRead: what is ethical hacking and how to learn itRead: how to become a pentesterRead: cyber security portfolio projectsRead: threat modeling with STRIDEBrowse all Career Insights

Isolate first, then experiment

Build the private network before you add a single vulnerable machine, snapshot everything, and write up every exercise. A small, well documented lab is worth more than a large one you cannot explain.

Train for a Cyber Security role

The same programme, duration and fees, with the learning path built around one job role.

Penetration TesterSecurity AnalystEthical HackerIncident Response AnalystCloud Security Engineer

Practise cyber security in guided labs

Ask our team how the Cyber Security programme uses hands-on lab work.

Our admissions team will call you back within 90 minutes.
AddressLR Towers, No. 3-535, 3rd Floor A Section, 100 Feet Road, Ayappa Society, Madhapur, Hyderabad, Telangana, India