Home labs

Practice ranges you can build today

Isolated labs for your own network and devices, intentional vulnerable targets, and purple-team loops. Start with Lab Zero before anything noisy. Mark labs complete in Progress when you finish.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Own gear only

Home LAN audits and personal APs are fair game. Neighbors and employers are not.

Isolate targets

Host-only networks, localhost-bound Docker ports, snapshots before every experiment.

Write it down

Every lab ends with notes and a remediation thought — that is how experts train.

LAB 01
beginner
1–2 hours

Lab Zero: Isolated attack range

Build a safe home range: hypervisor, attacker VM, host-only networking, and snapshots. Everything else depends on this.

Goals

  • Install a hypervisor and create a host-only network
  • Deploy Kali (or Parrot) as the attacker
  • Verify isolation from your home LAN/WAN
  • Establish a snapshot habit

Requirements

  • A computer with 16GB RAM recommended (8GB minimum)
  • 40GB+ free disk
  • VirtualBox, VMware, or Proxmox

Steps

  1. 1.Install the hypervisor

    Install VirtualBox/VMware Workstation Player/Proxmox. Enable virtualization in BIOS if needed. Create a dedicated folder for lab VMs and ISOs.

  2. 2.Create a host-only / internal network

    Configure a network that VMs can share with each other but that does not route to your home Wi-Fi or the internet. In VirtualBox this is Host-Only Adapter; attach only lab VMs to it. Optionally give the attacker a second NAT adapter for updates while targets stay isolated.

  3. 3.Deploy the attacker VM

    Download Kali Linux (or Parrot). Create a VM with 2–4 CPU cores, 4GB+ RAM, and attach it to NAT + host-only. Install Guest Additions/tools. Run full system update while on NAT.

  4. 4.Validate isolation

    From the attacker on host-only, note its IP. Confirm target VMs (next labs) cannot reach the public internet. Never port-forward vulnerable labs to 0.0.0.0 on your router.

  5. 5.Snapshot clean state

    Power off cleanly and take a snapshot named 'clean-attacker'. Repeat for every new target after first boot configuration.

Safety

  • Vulnerable targets must not be internet-facing
  • Do not attack devices you do not own or administer
  • Keep personal browsing off the attacker VM
LAB 02
beginner
2–4 hours

Web starter: Juice Shop + Burp

Stand up OWASP Juice Shop, configure an intercepting proxy, and solve your first vulnerabilities with proper notes.

Goals

  • Run Juice Shop locally (Docker preferred)
  • Configure browser + Burp/ZAP
  • Solve at least 5 challenges with evidence
  • Write one finding in professional format

Requirements

  • Lab Zero complete
  • Docker or Node
  • Burp Community or OWASP ZAP

Steps

  1. 1.Launch Juice Shop bound to localhost

    docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop — then open http://127.0.0.1:3000 only from your machine/attacker VM.

  2. 2.Proxy setup

    Start Burp or ZAP on 127.0.0.1:8080. Install the CA certificate in your browser. Use FoxyProxy so only lab traffic is intercepted.

  3. 3.Map the application

    Browse as a guest and registered user. Note authentication, search, feedback, and score board. Build a simple site map in notes.

  4. 4.Hack with methodology

    Pick challenges from the score board. For each: hypothesis → intercept/modify → proof → screenshot → note remediation. Prefer understanding over writeup spoiling.

  5. 5.Report one issue properly

    Write Title, Severity, Description, Steps to Reproduce, Impact, Remediation. This is more valuable than twenty undocumented flags.

Safety

  • Bind lab apps to localhost when possible
  • Do not expose Juice Shop on public interfaces
LAB 03
beginner
3–5 hours

Network ops: Metasploitable enum & exploit

Practice staged scanning, service enumeration, and controlled exploitation against Metasploitable on an isolated network.

Goals

  • Produce a complete service inventory
  • Enumerate at least three services deeply
  • Gain a shell via a known vuln in lab
  • Document the path and fixes

Requirements

  • Lab Zero
  • Metasploitable 2 or 3 VM
  • Kali with Nmap/Metasploit

Steps

  1. 1.Place target on host-only network

    Import Metasploitable, attach only to host-only adapter, boot, and confirm IP (often DHCP). Snapshot immediately.

  2. 2.Staged Nmap

    Host discovery if needed, then nmap -sV -sC on discovered ports, then full port scan. Save -oA outputs into a dated folder.

  3. 3.Service enumeration

    For each interesting port, follow a checklist (HTTP: whatweb/nikto/ffuf; SMB: smbmap/enum4linux; etc.). Resist jumping to Metasploit first.

  4. 4.Exploitation with evidence

    Pick one high-confidence vulnerability. Exploit only in lab. Capture proof (whoami, hostname, ip a). Prefer manual understanding even if MSF is used.

  5. 5.Remediation mindset

    For each finding write how a defender would prevent or detect it. Experts dual-wield offense and defense notes.

Safety

  • Metasploitable is extremely insecure — isolation is mandatory
  • Never bridge this VM to production networks
LAB 04
beginner
3–5 hours

Audit your own home network

Full authorized self-assessment of your LAN: inventory, mDNS/IoT discovery, router/WAN exposure, shares, cameras, and hardening.

Goals

  • Build a complete device inventory (IP, MAC, vendor, role)
  • Find unnecessary open ports and shares on your own gear
  • Check router admin, UPnP, WPS, and WAN exposure
  • Segment or plan IoT isolation and document fixes

Requirements

  • Permission: this is your network / devices you own
  • Kali or scanning tools on a trusted machine
  • Optional: phone app (Fing) for a second opinion

Steps

  1. 1.Baseline inventory

    Pull DHCP leases from the router UI. Run arp-scan/nmap -sn and Fing. Lookup MAC OUIs. Start an asset sheet: hostname, IP, MAC, vendor, segment, trust tier.

  2. 2.Discover silent IoT (mDNS / NetBIOS)

    avahi-browse -a -r and nbtscan on your subnet. Note Chromecasts, printers, HomeKit, NAS names that ICMP might miss. Label every new device.

  3. 3.Service scan (gentle on IoT)

    nmap -sV --top-ports 100 on live hosts; use lighter timing on fragile cameras/bulbs. Check SMB shares (smbclient -L), RTSP cameras (Cameradar only on yours), and HTTP titles on routers/NAS.

  4. 4.Router, UPnP, and WAN view

    Review admin settings: WPS off, remote admin off, strong Wi-Fi, firmware current. List UPnP mappings (upnpc -l). Check your public IP on Shodan/ShieldsUP for accidental exposure.

  5. 5.Hardening pass

    Change defaults, close unused ports, disable UPnP if unused, plan guest/IoT VLAN or SSID isolation, consider Pi-hole/AdGuard + WireGuard/Tailscale for remote access instead of open ports. Update the inventory with what you fixed.

Safety

  • Only scan networks and devices you own or have approval to test
  • IoT devices can crash under aggressive scanning — start gentle
  • Do not attack ISP equipment beyond your authorization
  • RouterSploit/Cameradar: owned hardware only; have a recovery plan
LAB 05
intermediate
half weekend

IoT & smart-home hardening sprint

Focus day for cameras, MQTT, smart hubs, and segmentation so a compromised bulb cannot reach your NAS.

Goals

  • Enumerate cameras and automation services on the LAN
  • Find default-cred and open MQTT/API issues on owned devices
  • Design or implement IoT/guest isolation
  • Replace WAN port-forwards with VPN access

Requirements

  • Completed home network audit inventory
  • Admin access to router/AP

Steps

  1. 1.Camera and RTSP review

    Identify camera IPs from inventory. Check for default credentials and open RTSP. Change passwords, disable UPnP/cloud features you do not need, put cams on IoT VLAN.

  2. 2.Automation stack check

    If you run Home Assistant / MQTT: test anonymous MQTT subscribe, review exposed ports, enforce auth, and prefer Tailscale/WireGuard over raw 8123/1883 on WAN.

  3. 3.Segment

    Create guest/IoT SSID or VLAN. Block IoT → trusted LAN. Allow trusted → IoT only for admin. Re-test with nmap from a trusted host and an IoT host.

  4. 4.DNS + monitoring

    Optional: Pi-hole/AdGuard for query logs. Optional: ntopng or iftop on a span/gateway to see which devices talk unusually often.

Safety

  • Do not lock yourself out of the router — keep a wired admin path
  • Snapshot/export router config before major VLAN changes
  • Never test neighbors' cameras or smart devices
LAB 06
advanced
1–2 weekends

Active Directory starter path

Deploy or join a vulnerable AD lab (GOAD / guided alternatives), collect BloodHound data, and practice a full identity attack narrative.

Goals

  • Understand domain enumeration after a foothold
  • Roast and crack a weak service account in lab
  • Map a path in BloodHound
  • Practice one lateral movement technique

Requirements

  • Solid Linux/Windows fundamentals
  • 16GB+ RAM strongly recommended
  • GOAD or HTB/TryHackMe AD labs

Steps

  1. 1.Choose a lab source

    GOAD for full local realism; DetectionLab for purple team; TryHackMe/HTB AD modules if hardware is limited.

  2. 2.Gain an initial foothold (lab storyline)

    Follow the lab’s intended entry (often a web app or shared creds). Do not skip notes — AD chains are long.

  3. 3.Enumerate intentionally

    Users, groups, SMB shares, sessions, SPNs, interesting ACLs. Use NetExec/Impacket/ldapsearch before random exploits.

  4. 4.BloodHound analysis

    Collect with SharpHound/rusthound/bloodhound-python. Import. Find paths to high-value targets. Explain the path in writing.

  5. 5.Execute one chain cleanly

    Example: Kerberoast → crack → lateral → DA. Reset lab afterward. Write defenses for each step.

Safety

  • Never run AD attack tools against a production domain without a contract
  • Credential dumping and relays can be disruptive — lab only until authorized
LAB 07
intermediate
half weekend

Purple loop: attack and detect

Run noisy and quiet techniques against a lab while collecting logs. Learn what defenders see.

Goals

  • Generate authentication failures and find them in logs
  • Capture attack traffic in Wireshark/Suricata
  • Write one detection idea mapped to ATT&CK

Requirements

  • Lab with logging (Wazuh/DetectionLab or even raw auth.log)
  • Attacker VM

Steps

  1. 1.Baseline logs

    Before attacking, note normal log volume. Ensure time sync. Identify where SSH/Windows security logs live.

  2. 2.Run a controlled technique

    Example: Hydra against lab SSH with 20 passwords, or Nmap -sV against a lab host. Record start/stop times.

  3. 3.Hunt your activity

    Find events in auth.log, Windows Security, Suricata, or Wazuh. Screenshot evidence of detection.

  4. 4.Detection note

    Write: data source, condition, false positive risks, and ATT&CK technique ID. This is professional-grade practice.

Safety

  • Keep detection labs isolated
  • Do not stress production logging pipelines