Skip to content
Back to blog
Home Lab
2026-05-10 7 min read

Building a Virtual Cyber Range: Home Lab Guide

Set up your own cybersecurity home lab with VirtualBox, Kali Linux, and vulnerable target machines for safe, legal hands-on practice.

VirtualBox
Kali Linux
Lab Setup
Practice

One of the best ways to learn cybersecurity is by building your own home lab. A virtual cyber range gives you a safe, isolated environment to practice offensive and defensive techniques without risking real systems or breaking any laws.

What You'll Need

  • Hardware, A computer with at least 8 GB RAM and 100 GB free disk space. 16 GB RAM is recommended.
  • Hypervisor, VirtualBox (free) or VMware Workstation Player (free for personal use).
  • Attacker VM, Kali Linux or Parrot Security OS.
  • Target VMs, Intentionally vulnerable machines like Metasploitable 2, DVWA, or OWASP WebGoat.

Step 1: Install VirtualBox

Download VirtualBox from virtualbox.org and install it. Also install the Extension Pack for USB support and other features.

Step 2: Set Up Kali Linux

Download the pre-built Kali Linux VirtualBox image from kali.org. Import the .ova file into VirtualBox:

File → Import Appliance → Select the .ova file → Import

Default credentials are kali / kali. Change the password immediately after first login.

Step 3: Set Up a Target Machine

Download Metasploitable 2-a deliberately vulnerable Linux VM. Extract the archive and create a new VM in VirtualBox pointing to the extracted .vmdk disk file.

Step 4: Network Configuration

This is the most important step. You want your VMs to communicate with each other but not with the outside world:

  1. In VirtualBox, go to File → Host Network Manager and create a new host-only network (e.g., vboxnet0).
  2. Set both VMs' network adapters to Host-only Adapter using vboxnet0.
  3. Boot both VMs and verify they can ping each other.
# On Kali, find your IP
ip addr show

# Ping the target
ping 192.168.56.101

Step 5: Start Practicing

With your lab running, try these beginner exercises:

  • Nmap scanning, Discover open ports and services on the target.
  • Metasploit, Use the framework to exploit known vulnerabilities on Metasploitable.
  • Web app testing, Set up DVWA on the target and practice SQL injection, XSS, and file upload attacks.
  • Wireshark, Capture and analyze the traffic between your attacker and target.

Safety Reminders

  • Never connect vulnerable VMs to your real network or the internet.
  • Always use host-only or internal networking for your lab.
  • Take VM snapshots before making changes so you can revert easily.
  • Only practice on systems you own or have explicit permission to test.