Installing Kali Linux gives you access to cybersecurity tools. A home lab gives you a safe place to understand what those tools are doing.

If you followed our Kali Linux installation guide for Windows and Mac, you already completed the most difficult part.

This guide adds an intentionally vulnerable practice application to that Kali virtual machine. You do not need additional hardware, several virtual machines, or previous lab experience.

By the end, you will be able to:

  • Start and stop your own local practice target
  • Identify the service and port it uses
  • Perform a first authorized local scan
  • Record what you observed
  • Create a clean recovery snapshot
  • Understand how to expand toward a two-machine lab later
Beginner Lab Architecture

Your First Cybersecurity Home Lab

Start with one Kali virtual machine and a safe local target. No additional hardware, complicated networking, or previous lab experience required.

1 Virtual Machine Free Setup 20–30 Minutes AMD64 + ARM64
💻
Your ComputerWindows or Mac host
🐉
Kali Linux VMYour controlled environment
▣
DockerRuns the local container
🧪
Juice ShopIntentionally vulnerable target
Safe by design: the practice application will listen only on 127.0.0.1 inside Kali. It will not be exposed to your home network.

This is not a complete corporate network simulation. It is a controlled first lab where you can connect ports, services, web applications, security tools, and observations without managing several operating systems.

You should already have Kali Linux running in a virtual machine.

If you have not installed it, follow our Kali Linux virtual machine guide for Windows and Mac first.

For this lab, use:

  • ✅ At least 8 GB of total system RAM
  • ✅ 4 GB of RAM assigned to Kali
  • ✅ 2 virtual processors assigned to Kali
  • ✅ 40 GB or more of virtual storage
  • ✅ NAT networking
  • ✅ An internet connection for installation and updates

The setup works with Kali AMD64 on Windows and Intel Mac, and Kali ARM64 on Apple Silicon. The current official Juice Shop Docker image supports both linux/amd64 and linux/arm64.

OWASP Juice Shop is intentionally insecure. That makes it useful for learning, but it should not be exposed to the internet or your physical network.

This guide uses:

127.0.0.1

This is Kali’s local loopback address. The application will be accessible from the browser inside Kali, but not from other devices on your network.

Keep the Kali VM in NAT mode. Do not use Bridged networking for this lab, and do not change the Docker binding to 0.0.0.0.

Only test systems you own or environments for which you have explicit authorization.

Start Kali, sign in, and open a terminal.

Run:

sudo apt update
sudo apt full-upgrade -y

Restart Kali after a major update:

sudo reboot

Sign in again and reopen the terminal.

Docker will run the practice application inside Kali without requiring another virtual machine.

Install it from Kali’s repositories:

sudo apt install docker.io -y

Start Docker and configure it to start automatically:

sudo systemctl enable --now docker

Confirm the installation:

sudo docker --version

You should see a Docker version number. You do not need to create a Docker account.

OWASP Juice Shop is an intentionally vulnerable web application created for security training and awareness.

Download its official image:

sudo docker pull bkimminich/juice-shop

Wait until the download finishes and the command prompt returns.

Run:

sudo docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop

Leave this terminal open.

The command performs four actions:

  1. docker run starts the container.
  2. --rm removes the temporary container when it stops.
  3. 127.0.0.1:3000:3000 restricts the service to Kali on port 3000.
  4. bkimminich/juice-shop identifies the official image.

The terminal will display activity while Juice Shop starts. This is normal.

Open the web browser inside Kali and enter:

http://127.0.0.1:3000

The Juice Shop interface should appear.

You now have a working cybersecurity home lab: the target runs inside Docker, and Docker runs inside the Kali virtual machine.

To stop Juice Shop, return to its terminal and press:

Ctrl + C

The temporary container is removed, but the downloaded image remains available.

To restart the lab later, run:

sudo docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop

Keep the terminal open and return to http://127.0.0.1:3000 in Kali’s browser.

Stop Juice Shop with Ctrl + C, then shut down Kali:

sudo poweroff

Create a snapshot in VirtualBox, VMware Fusion, or UTM named:

Kali Lab — Juice Shop Ready

This recovery point preserves the updated Kali installation, Docker configuration, and downloaded Juice Shop image.

Snapshots make experimentation easier, but they do not replace backups.

Do not begin by trying random exploits. Start by understanding the environment you created.

Start Juice Shop and open a second terminal:

curl -I http://127.0.0.1:3000

Observe the response headers. The objective is simply to confirm that a web service responds.

sudo ss -lntp | grep 3000

Look for 127.0.0.1:3000. This confirms that the application is listening locally rather than on every network interface.

nmap -sV -p 3000 127.0.0.1

Identify:

  • Whether the port is open
  • Which service Nmap recognizes
  • How the result relates to the Docker command

Document:

  • 📝 The objective
  • 🎯 The address and port tested
  • 🛠️ The tool or command used
  • 🔎 What the output meant
  • ⚖️ Why the activity was authorized

The goal is not only to run a command. It is to explain why you used it and what the result means.

Build in Stages

Start Simple. Expand When Ready.

A useful lab grows with your understanding. Complete the first environment before adding more machines and networking.

Level 1 — Build Now

One-VM Practice Lab

Kali and Juice Shop provide the shortest path from installation to safe practice.

  • One Kali virtual machine
  • Local Docker target
  • No complex network setup
  • Works on AMD64 and ARM64
Level 2 — Expand Later

Two-VM Network Lab

Add a separate target only after you understand the first environment.

  • Kali analysis VM
  • Separate target VM
  • Host-only or Internal network
  • Independent clean snapshots

A future two-machine lab could use this architecture:

Host computer
├── Kali Linux VM
└── Vulnerable target VM

Both machines should use the same Host-only or Internal virtual network. The vulnerable target should not use Bridged networking.

Before expanding, make sure you can:

  • Start and stop the current lab
  • Explain what 127.0.0.1 means
  • Identify a listening service
  • Interpret basic Nmap output
  • Restore a clean snapshot
  • Document an authorized exercise

Start Docker:

sudo systemctl start docker

Confirm that:

  • The terminal running Juice Shop remains open.
  • The Docker command did not stop with an error.
  • You entered http://127.0.0.1:3000 inside Kali—not in the host browser.

Check the port:

sudo ss -lntp | grep 3000

Stop the earlier container or application before restarting Juice Shop.

Close unnecessary applications on the host. Give Kali approximately 4 GB of RAM and 2 virtual processors, but never assign all the host computer’s resources to the VM.

  • ❌ Do not replace 127.0.0.1 with 0.0.0.0.
  • ❌ Do not use Bridged networking for an intentionally vulnerable beginner lab.
  • ❌ Do not attack the public Juice Shop demonstration server.
  • ❌ Do not scan websites, school networks, company systems, or other devices without authorization.
  • ❌ Do not install dozens of tools before understanding the first exercises.
  • ❌ Do not skip snapshots before major changes.
Your Learning Environment Is Ready

Turn Your Lab Into Structured Progress

A home lab gives you an environment. A clear learning path helps you understand what to practise, why it matters, and how each concept connects.

Understand first. Build your lab. Practice next.

All ethical hacking techniques must only be used with explicit authorization and in legal practice environments.

Trademark notice: CEH® is a registered trademark of EC-Council. Back2Skills is an independent training provider and is not affiliated with, endorsed by, or sponsored by EC-Council.