Home labs
Practice ranges you can build today
Isolated labs for your own network and devices, intentional vulnerable targets, and purple-team loops. Start with Lab Zero before anything noisy. Mark labs complete in Progress when you finish.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Own gear only
Home LAN audits and personal APs are fair game. Neighbors and employers are not.
Isolate targets
Host-only networks, localhost-bound Docker ports, snapshots before every experiment.
Write it down
Every lab ends with notes and a remediation thought — that is how experts train.
Lab Zero: Isolated attack range
Build a safe home range: hypervisor, attacker VM, host-only networking, and snapshots. Everything else depends on this.
Goals
- Install a hypervisor and create a host-only network
- Deploy Kali (or Parrot) as the attacker
- Verify isolation from your home LAN/WAN
- Establish a snapshot habit
Requirements
- A computer with 16GB RAM recommended (8GB minimum)
- 40GB+ free disk
- VirtualBox, VMware, or Proxmox
Steps
1.Install the hypervisor
Install VirtualBox/VMware Workstation Player/Proxmox. Enable virtualization in BIOS if needed. Create a dedicated folder for lab VMs and ISOs.
2.Create a host-only / internal network
Configure a network that VMs can share with each other but that does not route to your home Wi-Fi or the internet. In VirtualBox this is Host-Only Adapter; attach only lab VMs to it. Optionally give the attacker a second NAT adapter for updates while targets stay isolated.
3.Deploy the attacker VM
Download Kali Linux (or Parrot). Create a VM with 2–4 CPU cores, 4GB+ RAM, and attach it to NAT + host-only. Install Guest Additions/tools. Run full system update while on NAT.
4.Validate isolation
From the attacker on host-only, note its IP. Confirm target VMs (next labs) cannot reach the public internet. Never port-forward vulnerable labs to 0.0.0.0 on your router.
5.Snapshot clean state
Power off cleanly and take a snapshot named 'clean-attacker'. Repeat for every new target after first boot configuration.
Safety
- Vulnerable targets must not be internet-facing
- Do not attack devices you do not own or administer
- Keep personal browsing off the attacker VM
Web starter: Juice Shop + Burp
Stand up OWASP Juice Shop, configure an intercepting proxy, and solve your first vulnerabilities with proper notes.
Goals
- Run Juice Shop locally (Docker preferred)
- Configure browser + Burp/ZAP
- Solve at least 5 challenges with evidence
- Write one finding in professional format
Requirements
- Lab Zero complete
- Docker or Node
- Burp Community or OWASP ZAP
Steps
1.Launch Juice Shop bound to localhost
docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop — then open http://127.0.0.1:3000 only from your machine/attacker VM.
2.Proxy setup
Start Burp or ZAP on 127.0.0.1:8080. Install the CA certificate in your browser. Use FoxyProxy so only lab traffic is intercepted.
3.Map the application
Browse as a guest and registered user. Note authentication, search, feedback, and score board. Build a simple site map in notes.
4.Hack with methodology
Pick challenges from the score board. For each: hypothesis → intercept/modify → proof → screenshot → note remediation. Prefer understanding over writeup spoiling.
5.Report one issue properly
Write Title, Severity, Description, Steps to Reproduce, Impact, Remediation. This is more valuable than twenty undocumented flags.
Safety
- Bind lab apps to localhost when possible
- Do not expose Juice Shop on public interfaces
Network ops: Metasploitable enum & exploit
Practice staged scanning, service enumeration, and controlled exploitation against Metasploitable on an isolated network.
Goals
- Produce a complete service inventory
- Enumerate at least three services deeply
- Gain a shell via a known vuln in lab
- Document the path and fixes
Requirements
- Lab Zero
- Metasploitable 2 or 3 VM
- Kali with Nmap/Metasploit
Steps
1.Place target on host-only network
Import Metasploitable, attach only to host-only adapter, boot, and confirm IP (often DHCP). Snapshot immediately.
2.Staged Nmap
Host discovery if needed, then nmap -sV -sC on discovered ports, then full port scan. Save -oA outputs into a dated folder.
3.Service enumeration
For each interesting port, follow a checklist (HTTP: whatweb/nikto/ffuf; SMB: smbmap/enum4linux; etc.). Resist jumping to Metasploit first.
4.Exploitation with evidence
Pick one high-confidence vulnerability. Exploit only in lab. Capture proof (whoami, hostname, ip a). Prefer manual understanding even if MSF is used.
5.Remediation mindset
For each finding write how a defender would prevent or detect it. Experts dual-wield offense and defense notes.
Safety
- Metasploitable is extremely insecure — isolation is mandatory
- Never bridge this VM to production networks
Audit your own home network
Full authorized self-assessment of your LAN: inventory, mDNS/IoT discovery, router/WAN exposure, shares, cameras, and hardening.
Goals
- Build a complete device inventory (IP, MAC, vendor, role)
- Find unnecessary open ports and shares on your own gear
- Check router admin, UPnP, WPS, and WAN exposure
- Segment or plan IoT isolation and document fixes
Requirements
- Permission: this is your network / devices you own
- Kali or scanning tools on a trusted machine
- Optional: phone app (Fing) for a second opinion
Steps
1.Baseline inventory
Pull DHCP leases from the router UI. Run arp-scan/nmap -sn and Fing. Lookup MAC OUIs. Start an asset sheet: hostname, IP, MAC, vendor, segment, trust tier.
2.Discover silent IoT (mDNS / NetBIOS)
avahi-browse -a -r and nbtscan on your subnet. Note Chromecasts, printers, HomeKit, NAS names that ICMP might miss. Label every new device.
3.Service scan (gentle on IoT)
nmap -sV --top-ports 100 on live hosts; use lighter timing on fragile cameras/bulbs. Check SMB shares (smbclient -L), RTSP cameras (Cameradar only on yours), and HTTP titles on routers/NAS.
4.Router, UPnP, and WAN view
Review admin settings: WPS off, remote admin off, strong Wi-Fi, firmware current. List UPnP mappings (upnpc -l). Check your public IP on Shodan/ShieldsUP for accidental exposure.
5.Hardening pass
Change defaults, close unused ports, disable UPnP if unused, plan guest/IoT VLAN or SSID isolation, consider Pi-hole/AdGuard + WireGuard/Tailscale for remote access instead of open ports. Update the inventory with what you fixed.
Tools
Safety
- Only scan networks and devices you own or have approval to test
- IoT devices can crash under aggressive scanning — start gentle
- Do not attack ISP equipment beyond your authorization
- RouterSploit/Cameradar: owned hardware only; have a recovery plan
IoT & smart-home hardening sprint
Focus day for cameras, MQTT, smart hubs, and segmentation so a compromised bulb cannot reach your NAS.
Goals
- Enumerate cameras and automation services on the LAN
- Find default-cred and open MQTT/API issues on owned devices
- Design or implement IoT/guest isolation
- Replace WAN port-forwards with VPN access
Requirements
- Completed home network audit inventory
- Admin access to router/AP
Steps
1.Camera and RTSP review
Identify camera IPs from inventory. Check for default credentials and open RTSP. Change passwords, disable UPnP/cloud features you do not need, put cams on IoT VLAN.
2.Automation stack check
If you run Home Assistant / MQTT: test anonymous MQTT subscribe, review exposed ports, enforce auth, and prefer Tailscale/WireGuard over raw 8123/1883 on WAN.
3.Segment
Create guest/IoT SSID or VLAN. Block IoT → trusted LAN. Allow trusted → IoT only for admin. Re-test with nmap from a trusted host and an IoT host.
4.DNS + monitoring
Optional: Pi-hole/AdGuard for query logs. Optional: ntopng or iftop on a span/gateway to see which devices talk unusually often.
Tools
Safety
- Do not lock yourself out of the router — keep a wired admin path
- Snapshot/export router config before major VLAN changes
- Never test neighbors' cameras or smart devices
Active Directory starter path
Deploy or join a vulnerable AD lab (GOAD / guided alternatives), collect BloodHound data, and practice a full identity attack narrative.
Goals
- Understand domain enumeration after a foothold
- Roast and crack a weak service account in lab
- Map a path in BloodHound
- Practice one lateral movement technique
Requirements
- Solid Linux/Windows fundamentals
- 16GB+ RAM strongly recommended
- GOAD or HTB/TryHackMe AD labs
Steps
1.Choose a lab source
GOAD for full local realism; DetectionLab for purple team; TryHackMe/HTB AD modules if hardware is limited.
2.Gain an initial foothold (lab storyline)
Follow the lab’s intended entry (often a web app or shared creds). Do not skip notes — AD chains are long.
3.Enumerate intentionally
Users, groups, SMB shares, sessions, SPNs, interesting ACLs. Use NetExec/Impacket/ldapsearch before random exploits.
4.BloodHound analysis
Collect with SharpHound/rusthound/bloodhound-python. Import. Find paths to high-value targets. Explain the path in writing.
5.Execute one chain cleanly
Example: Kerberoast → crack → lateral → DA. Reset lab afterward. Write defenses for each step.
Tools
Safety
- Never run AD attack tools against a production domain without a contract
- Credential dumping and relays can be disruptive — lab only until authorized
Purple loop: attack and detect
Run noisy and quiet techniques against a lab while collecting logs. Learn what defenders see.
Goals
- Generate authentication failures and find them in logs
- Capture attack traffic in Wireshark/Suricata
- Write one detection idea mapped to ATT&CK
Requirements
- Lab with logging (Wazuh/DetectionLab or even raw auth.log)
- Attacker VM
Steps
1.Baseline logs
Before attacking, note normal log volume. Ensure time sync. Identify where SSH/Windows security logs live.
2.Run a controlled technique
Example: Hydra against lab SSH with 20 passwords, or Nmap -sV against a lab host. Record start/stop times.
3.Hunt your activity
Find events in auth.log, Windows Security, Suricata, or Wazuh. Screenshot evidence of detection.
4.Detection note
Write: data source, condition, false positive risks, and ATT&CK technique ID. This is professional-grade practice.
Safety
- Keep detection labs isolated
- Do not stress production logging pipelines