Skip to content
Pentesting and ethical hacking

How to build a cybersecurity home lab (free and low-cost options)

Cybersecurity home lab setup, step by step: VirtualBox or VMware, Kali, Metasploitable 2 and OWASP Juice Shop on an isolated host-only network, all free.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 10 min read

You can build a useful cybersecurity home lab for free on the laptop you already own: a hypervisor (VirtualBox or VMware), an attacker machine (Kali Linux), one or two deliberately vulnerable targets (Metasploitable 2 and OWASP Juice Shop), and a private host-only network that keeps the vulnerable machines away from your home network and the internet. This guide walks through that exact setup, then shows how to grow it once you outgrow the basics.

Everything here runs on your own machine against targets you own. Only test systems you own or have written permission to test.

What you need before you start

Hardware

Component Workable Comfortable
RAM 8 GB 16 GB or more
Free disk space 60 GB 120 GB+ on an SSD
CPU Any 64-bit CPU with virtualisation support 4+ cores

Virtualisation must be switched on in your BIOS/UEFI (Intel VT-x or AMD-V). If VirtualBox complains that hardware virtualisation is unavailable, that’s the first thing to check.

Apple Silicon Macs (M1 and later): Kali has ARM builds and Docker runs fine, so Juice Shop works. Metasploitable 2 is an old 32-bit x86 image and won’t run natively; you’d need emulation (UTM can do it, slowly), or use Juice Shop and other ARM-friendly targets instead.

Software, all free

  • A hypervisor. Oracle VirtualBox is free and open source. VMware Workstation Pro (Windows and Linux) and VMware Fusion (Mac) are also free for personal use; check Broadcom’s download page for current terms.
  • Kali Linux, as a pre-built virtual machine image from kali.org.
  • Metasploitable 2, the intentionally vulnerable Linux VM published by Rapid7. Its documentation links the download.
  • OWASP Juice Shop, a deliberately insecure web shop maintained by OWASP, which we’ll run in Docker.

The lab we’re building

              Your laptop (host)
   +-------------------------------------------+
   |  NAT adapter (internet, for updates only) |
   |        |                                  |
   |   +---------+                             |
   |   |  Kali   | eth0: NAT                   |
   |   |         | eth1: 192.168.56.x          |
   |   | Docker: Juice Shop on 127.0.0.1:3000  |
   |   +---------+                             |
   |        |  host-only network               |
   |        |  vboxnet0  192.168.56.0/24       |
   |   +----------------+                      |
   |   | Metasploitable | host-only ONLY       |
   |   | 192.168.56.x   | (no internet)        |
   |   +----------------+                      |
   +-------------------------------------------+

The rule that matters: the vulnerable machine has no route to the internet or your home network. Kali gets two adapters, one for updates and one for the lab. Metasploitable gets only the host-only adapter.

Step 1: Install the hypervisor

VirtualBox: download the installer for your operating system from virtualbox.org and install with the defaults. On Windows, it will briefly drop your network connection while it installs its virtual adapters; that’s normal. Also install the matching Extension Pack only if you need its features (USB 2/3 passthrough, for example); the lab doesn’t require it.

VMware Workstation Pro: install it, and the host-only network (VMnet1) is created for you. You can view or change it under Edit > Virtual Network Editor. The rest of this guide uses VirtualBox menu names; the VMware equivalents are noted where they differ.

Step 2: Create the host-only network

In VirtualBox 7:

  1. Open File > Tools > Network Manager (on some versions, Tools > Network).
  2. Select the Host-only Networks tab and click Create.
  3. Set the adapter to 192.168.56.1 with mask 255.255.255.0.
  4. On the DHCP Server tab, tick Enable Server. Defaults such as server 192.168.56.100, lower bound 192.168.56.101 and upper bound 192.168.56.254 are fine.

Or from a terminal on the host:

VBoxManage hostonlyif create
VBoxManage hostonlyif ipconfig vboxnet0 --ip 192.168.56.1 --netmask 255.255.255.0
VBoxManage dhcpserver add --ifname vboxnet0 --server-ip 192.168.56.100 \
  --netmask 255.255.255.0 --lower-ip 192.168.56.101 --upper-ip 192.168.56.254 --enable

On Windows hosts the interface will have a longer name, such as “VirtualBox Host-Only Ethernet Adapter”; use whatever name VBoxManage list hostonlyifs shows. On Linux and macOS hosts, VirtualBox only allows host-only addresses in 192.168.56.0/21 by default (controlled by /etc/vbox/networks.conf), which is why we use that range. The VirtualBox manual’s networking chapter covers the details.

On macOS with VirtualBox 7, use Host-only Networks (VBoxManage hostonlynet add --name=lab --netmask=255.255.255.0 --lower-ip=192.168.56.101 --upper-ip=192.168.56.254 --enable) and attach VMs to that network instead of vboxnet0.

Step 3: Import Kali

  1. On kali.org, download the VirtualBox (or VMware) pre-built image. It arrives as a compressed .7z file.
  2. Verify the download against the SHA256 checksum shown on the download page:
# Linux
sha256sum kali-linux-*-virtualbox-amd64.7z
# macOS
shasum -a 256 kali-linux-*-virtualbox-amd64.7z
# Windows PowerShell
Get-FileHash .\kali-linux-*-virtualbox-amd64.7z -Algorithm SHA256

If the hash doesn’t match the one on the site, delete the file and download it again. Checking hashes is a habit worth building now; it’s how you know a file hasn’t been tampered with.

  1. Extract the archive (7-Zip on Windows, 7z x on Linux, or any archive tool on Mac) and double-click the .vbox file, or use Machine > Add in VirtualBox.
  2. Before you start it, open Settings > Network:
    • Adapter 1: NAT (internet for updates).
    • Adapter 2: tick Enable, attach to Host-only Adapter, name vboxnet0.
  3. Give it at least 2 GB of RAM, more if you can spare it.
  4. Start the VM and log in. The pre-built images use the default credentials listed in Kali’s documentation. Change the password immediately and update:
passwd
sudo apt update && sudo apt full-upgrade -y

Check both interfaces are up:

$ ip -brief addr
lo               UNKNOWN        127.0.0.1/8 ::1/128
eth0             UP             10.0.2.15/24 fe80::a00:27ff:fe4e:66a1/64
eth1             UP             192.168.56.101/24 fe80::a00:27ff:fe9c:21b7/64

eth0 on 10.0.2.15 is VirtualBox’s NAT; eth1 is your lab network. If eth1 has no address, run sudo nmcli device connect eth1 (or sudo dhclient eth1 if installed) or check that the DHCP server from Step 2 is enabled.

Step 4: Add Metasploitable 2

Metasploitable 2 is intentionally full of holes. Treat it like something that could bite: never bridge it to your home network and never expose it to the internet.

  1. Download the Metasploitable 2 zip via the link in Rapid7’s documentation and extract it. Inside is a .vmdk virtual disk.
  2. In VirtualBox, click New. Name it metasploitable2, Type Linux, Version Ubuntu (32-bit) or Other Linux (32-bit). 512 MB of RAM is enough.
  3. At the hard disk step, choose Use an existing virtual hard disk file and select the .vmdk.
  4. In Settings > Network, set Adapter 1 to Host-only Adapter, vboxnet0. Make sure no other adapter is enabled.
  5. Start it and log in with the default credentials from Rapid7’s documentation (they’re printed on the login banner too). Find its address:
msfadmin@metasploitable:~$ ifconfig eth0 | grep “inet addr”
          inet addr:192.168.56.102  Bcast:192.168.56.255  Mask:255.255.255.0

(Metasploitable 2 is old enough to still use ifconfig.)

VMware users: Rapid7’s zip includes a .vmx file, so you can open it directly; then set its network adapter to Host-only.

Step 5: Run OWASP Juice Shop in Docker on Kali

Juice Shop is a modern, intentionally insecure web application, a good counterpart to Metasploitable’s older services. Running it in Docker on Kali keeps things light.

sudo apt install -y docker.io
sudo systemctl enable --now docker
sudo docker run -d --name juice-shop -p 127.0.0.1:3000:3000 bkimminich/juice-shop

Binding to 127.0.0.1 means Juice Shop is reachable only from inside Kali, not from your lab network or anywhere else. Open Firefox in Kali and go to http://localhost:3000.

$ sudo docker ps
CONTAINER ID   IMAGE                   COMMAND                  STATUS         PORTS                      NAMES
4f2a9c1e7b3d   bkimminich/juice-shop   “/nodejs/bin/node /j…”   Up 2 minutes   127.0.0.1:3000->3000/tcp   juice-shop

To stop and start it later: sudo docker stop juice-shop and sudo docker start juice-shop. The Juice Shop project also has a free companion guide, Pwning OWASP Juice Shop, linked from its OWASP page.

Step 6: Prove the lab works

From Kali, confirm you can reach Metasploitable and see its services:

$ ping -c 2 192.168.56.102
PING 192.168.56.102 (192.168.56.102) 56(84) bytes of data.
64 bytes from 192.168.56.102: icmp_seq=1 ttl=64 time=0.612 ms
64 bytes from 192.168.56.102: icmp_seq=2 ttl=64 time=0.498 ms

$ sudo nmap -sV 192.168.56.102
Starting Nmap 7.95 ( https://nmap.org )
Nmap scan report for 192.168.56.102
Host is up (0.00051s latency).
Not shown: 977 closed tcp ports (reset)
PORT     STATE SERVICE     VERSION
21/tcp   open  ftp         vsftpd 2.3.4
22/tcp   open  ssh         OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
23/tcp   open  telnet      Linux telnetd
25/tcp   open  smtp        Postfix smtpd
53/tcp   open  domain      ISC BIND 9.4.2
80/tcp   open  http        Apache httpd 2.2.8 ((Ubuntu) DAV/2)
111/tcp  open  rpcbind     2 (RPC #100000)
139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
512/tcp  open  exec        netkit-rsh rexecd
513/tcp  open  login       OpenBSD or Solaris rlogind
514/tcp  open  tcpwrapped
1099/tcp open  java-rmi    GNU Classpath grmiregistry
1524/tcp open  bindshell   Metasploitable root shell
2049/tcp open  nfs         2-4 (RPC #100003)
2121/tcp open  ftp         ProFTPD 1.3.1
3306/tcp open  mysql       MySQL 5.0.51a-3ubuntu5
5432/tcp open  postgresql  PostgreSQL DB 8.3.0 - 8.3.7
5900/tcp open  vnc         VNC (protocol 3.3)
6000/tcp open  X11         (access denied)
6667/tcp open  irc         UnrealIRCd
8009/tcp open  ajp13       Apache Jserv (Protocol v1.3)
8180/tcp open  http        Apache Tomcat/Coyote JSP engine 1.1

Your Nmap version and exact lines may differ slightly. That list is your first assignment: pick one service, research why that version is a problem, and write down how a defender would fix it. Our Nmap commands cheat sheet explains the flags and what to try next.

Now check the isolation. From Metasploitable, ping -c 2 8.8.8.8 should fail. If it succeeds, Metasploitable has a route out; go back and remove any NAT or bridged adapter.

Step 7: Take snapshots before you break things

Snapshots let you roll back in seconds after you’ve wrecked a VM, which you will.

VBoxManage snapshot “kali-lab” take “clean-updated”
VBoxManage snapshot “metasploitable2” take “clean”

Replace kali-lab with the exact name that VBoxManage list vms prints for your Kali VM. In the GUI it’s the Snapshots view for each machine. To roll back: VBoxManage snapshot “metasploitable2” restore “clean” with the VM powered off.

Free vs low-cost: how to grow the lab

Upgrade Cost What it adds
A Windows evaluation VM from Microsoft’s Evaluation Center Free (time-limited) Practise Windows logs, PowerShell and Active Directory basics
An Ubuntu Server VM with logging turned up Free A “defended” server to watch from the blue-team side
An open-source SIEM, such as Wazuh, or a monitoring distribution such as Security Onion Free software, but RAM-hungry Real alerting and log searching, as in a SOC
More RAM in your laptop Low cost Run three or four VMs at once without slowdowns
A second-hand mini PC or old desktop as a dedicated lab box Low cost Leaves your main laptop free; can run a bare-metal hypervisor such as Proxmox
Browser-based labs (PortSwigger’s Web Security Academy) Free Web attack practice with no local setup

Check each tool’s official documentation for current hardware requirements before installing; SIEMs in particular need more memory than a basic lab.

Home lab project ideas

A lab is only useful if you do something with it and write it up. These projects make good CV and interview material.

Offensive (penetration testing path):

  1. Enumerate every service on Metasploitable 2, rank them by risk, and write a short findings report with remediation for each.
  2. Work through Juice Shop’s scoreboard challenges, starting with the one-star ones, and map each to an OWASP Top 10 category.
  3. Capture an FTP or Telnet login to Metasploitable in Wireshark and explain why cleartext protocols are dangerous.

Defensive (SOC path):

  1. Send Metasploitable’s or Ubuntu’s logs to a SIEM and write a detection rule for repeated failed SSH logins.
  2. Run an Nmap scan from Kali, then find the evidence of it in your target’s logs or packet capture. What would a SOC analyst see?
  3. Harden an Ubuntu Server VM (disable root SSH, set up a firewall with ufw, remove unused services), then rescan and compare.

The SOC analyst roadmap suggests which defensive skills to prioritise, and how to become a penetration tester covers the offensive side.

Safety rules for any home lab

  • Keep vulnerable VMs on host-only or internal networks. Never bridged, never port-forwarded.
  • Don’t download “cracked” tools or random exploit binaries. Use your distribution’s package manager and official project pages.
  • Scan only your lab (and scanme.nmap.org for light tests, which the Nmap project allows). Scanning other people’s systems without permission can be illegal, including from home.
  • Snapshot before experiments and restore when you’re done.
  • Keep Kali updated; it’s software like any other.

Questions

Do I need a powerful computer for a cybersecurity home lab?

No. A laptop with 8 GB of RAM can run Kali plus Metasploitable 2 if you give each modest memory. 16 GB makes it much more comfortable, especially once you add a Windows VM or a SIEM.

Is VirtualBox or VMware better for a home lab?

Both work. VirtualBox is open source and the most widely documented in beginner guides. VMware Workstation Pro is now free for personal use and some people find it faster. Pick one and learn it well.

Can I build a home lab in the cloud instead?

Yes, but watch costs and never expose deliberately vulnerable machines to the internet. Cloud providers also have acceptable-use rules about security testing. For a first lab, local is cheaper and safer.

Is it legal to use Kali Linux?

Yes. Kali is a legitimate Linux distribution. What matters legally is what you point it at: only systems you own or have written permission to test.