Why a lab comes before any real target
Ethical hacking is only ethical when you have permission. Scanning or attacking a system you do not own, or have not been authorised in writing to test, can break the law even if you mean no harm. A home lab removes that risk: every machine in it is yours, so you can practise reconnaissance, exploitation and clean-up as often as you like.
A lab also teaches things a video cannot. You see how a misconfigured service really behaves, what your tools send over the network, and what traces an attack leaves in logs. That defensive view is what makes lab practice useful in interviews for both offensive and SOC roles.
What you need before you start
Most learners can start on the laptop they already have:
- A computer with enough memory to run two or three virtual machines at once. 16 GB of RAM is comfortable; 8 GB works if you run one target at a time.
- A free virtualisation tool such as VirtualBox or VMware Workstation Player, with hardware virtualisation switched on in the BIOS.
- An attacker machine. Kali Linux and Parrot OS ship with the common tools already installed.
- Deliberately vulnerable targets made for practice, such as Metasploitable 2, DVWA (Damn Vulnerable Web Application) or OWASP Juice Shop.
- A notebook or document where you record each exercise: the goal, the commands you ran, what worked and how you would detect or fix it.
Building the lab step by step
Set the network up first. Most lab mistakes come from a vulnerable machine that can be reached from outside the lab.
Create a private virtual network
In your virtualisation tool, create a host-only or internal network. Machines on it can talk to each other but not to your home router or other devices. Do not attach vulnerable targets to a bridged network.
Install the attacker machine
Import the Kali Linux virtual machine image, give it two network adapters if you need updates (one NAT for the internet, one on the private network), and update it before you disconnect the NAT adapter.
Add one vulnerable target
Import Metasploitable 2 or run DVWA, and connect it only to the private network. Never give these machines internet access; they are insecure by design.
Confirm the isolation
From the target, check that it cannot reach the internet. From your normal computer, check that you cannot reach the target. Only the attacker machine should see it.
Take clean snapshots
Snapshot every machine in its fresh state. After each exercise, roll back so you always start from a known point and practise the same attack cleanly.
Add a way to watch the traffic
Run Wireshark on the attacker machine, or add a small logging target, so you can see what each scan and exploit looks like from the defender's side.
First exercises worth doing in order
Work through these slowly and write up each one:
- Discover the target and its open services with a network scan, then explain what each open port is for.
- Identify the versions of those services and look up their known weaknesses.
- Exploit one weakness in a controlled way, then list what changed on the target.
- Practise common web flaws such as SQL injection and cross-site scripting in DVWA, starting at the lowest difficulty.
- For every exploit, write the fix and how a defender would spot the attack in logs.
Quick answers about ethical hacking home labs
Short answers to what learners ask most.
Is it legal to practise hacking at home?
It is legal to practise on systems you own, such as the virtual machines in your own lab, and on platforms that give you explicit permission. Testing any other system without written authorisation can be illegal, even for learning.
Can I build a hacking lab without buying anything?
Yes. VirtualBox, Kali Linux, Metasploitable 2, DVWA and OWASP Juice Shop are free. The only real cost is a computer with enough memory to run a few virtual machines.
How much RAM do I need for a home lab?
16 GB lets you run an attacker and one or two targets together comfortably. With 8 GB you can still learn by running the attacker and a single small target at a time.
Should my lab machines be connected to the internet?
Vulnerable targets should never be. Keep them on a host-only or internal network. Give the attacker machine internet access only when you need updates, then switch it back.
Are online practice platforms a replacement for a home lab?
They are a good addition, because they offer ready-made challenges. Your own lab still teaches you to build, isolate and reset an environment, which is a useful skill in itself.
Where to go next after your first lab
See how lab work fits into the full syllabus, or read the guides that take these exercises further.
Isolate first, then experiment
Build the private network before you add a single vulnerable machine, snapshot everything, and write up every exercise. A small, well documented lab is worth more than a large one you cannot explain.

