Building a Virtual Cyber Range: Home Lab Guide
Set up your own cybersecurity home lab with VirtualBox, Kali Linux, and vulnerable target machines for safe, legal hands-on practice.
One of the best ways to learn cybersecurity is by building your own home lab. A virtual cyber range gives you a safe, isolated environment to practice offensive and defensive techniques without risking real systems or breaking any laws.
What You'll Need
- Hardware, A computer with at least 8 GB RAM and 100 GB free disk space. 16 GB RAM is recommended.
- Hypervisor, VirtualBox (free) or VMware Workstation Player (free for personal use).
- Attacker VM, Kali Linux or Parrot Security OS.
- Target VMs, Intentionally vulnerable machines like Metasploitable 2, DVWA, or OWASP WebGoat.
Step 1: Install VirtualBox
Download VirtualBox from virtualbox.org and install it. Also install the Extension Pack for USB support and other features.
Step 2: Set Up Kali Linux
Download the pre-built Kali Linux VirtualBox image from kali.org. Import the .ova file into VirtualBox:
File → Import Appliance → Select the .ova file → Import
Default credentials are kali / kali. Change the password immediately after first login.
Step 3: Set Up a Target Machine
Download Metasploitable 2-a deliberately vulnerable Linux VM. Extract the archive and create a new VM in VirtualBox pointing to the extracted .vmdk disk file.
Step 4: Network Configuration
This is the most important step. You want your VMs to communicate with each other but not with the outside world:
- In VirtualBox, go to File → Host Network Manager and create a new host-only network (e.g.,
vboxnet0). - Set both VMs' network adapters to Host-only Adapter using
vboxnet0. - Boot both VMs and verify they can ping each other.
# On Kali, find your IP
ip addr show
# Ping the target
ping 192.168.56.101
Step 5: Start Practicing
With your lab running, try these beginner exercises:
- Nmap scanning, Discover open ports and services on the target.
- Metasploit, Use the framework to exploit known vulnerabilities on Metasploitable.
- Web app testing, Set up DVWA on the target and practice SQL injection, XSS, and file upload attacks.
- Wireshark, Capture and analyze the traffic between your attacker and target.
Safety Reminders
- Never connect vulnerable VMs to your real network or the internet.
- Always use host-only or internal networking for your lab.
- Take VM snapshots before making changes so you can revert easily.
- Only practice on systems you own or have explicit permission to test.