Build a Cybersecurity Home Lab with Kali Linux in 2026
Installing Kali Linux gives you access to cybersecurity tools. A home lab gives you a safe place to understand what those tools are doing.
If you followed our Kali Linux installation guide for Windows and Mac, you already completed the most difficult part.
This guide adds an intentionally vulnerable practice application to that Kali virtual machine. You do not need additional hardware, several virtual machines, or previous lab experience.
By the end, you will be able to:
- Start and stop your own local practice target
- Identify the service and port it uses
- Perform a first authorized local scan
- Record what you observed
- Create a clean recovery snapshot
- Understand how to expand toward a two-machine lab later
Your First Cybersecurity Home Lab
Start with one Kali virtual machine and a safe local target. No additional hardware, complicated networking, or previous lab experience required.
127.0.0.1 inside Kali. It will not be exposed to your home network.This is not a complete corporate network simulation. It is a controlled first lab where you can connect ports, services, web applications, security tools, and observations without managing several operating systems.
🧰 What You Need Before Starting
You should already have Kali Linux running in a virtual machine.
If you have not installed it, follow our Kali Linux virtual machine guide for Windows and Mac first.
For this lab, use:
- ✅ At least 8 GB of total system RAM
- ✅ 4 GB of RAM assigned to Kali
- ✅ 2 virtual processors assigned to Kali
- ✅ 40 GB or more of virtual storage
- ✅ NAT networking
- ✅ An internet connection for installation and updates
The setup works with Kali AMD64 on Windows and Intel Mac, and Kali ARM64 on Apple Silicon. The current official Juice Shop Docker image supports both linux/amd64 and linux/arm64.
⚠️ Keep the Lab Safe
OWASP Juice Shop is intentionally insecure. That makes it useful for learning, but it should not be exposed to the internet or your physical network.
This guide uses:
127.0.0.1This is Kali’s local loopback address. The application will be accessible from the browser inside Kali, but not from other devices on your network.
Keep the Kali VM in NAT mode. Do not use Bridged networking for this lab, and do not change the Docker binding to 0.0.0.0.
Only test systems you own or environments for which you have explicit authorization.
🚀 Step 1: Update Kali Linux
Start Kali, sign in, and open a terminal.
Run:
sudo apt update
sudo apt full-upgrade -yRestart Kali after a major update:
sudo rebootSign in again and reopen the terminal.
🐳 Step 2: Install Docker
Docker will run the practice application inside Kali without requiring another virtual machine.
Install it from Kali’s repositories:
sudo apt install docker.io -yStart Docker and configure it to start automatically:
sudo systemctl enable --now dockerConfirm the installation:
sudo docker --versionYou should see a Docker version number. You do not need to create a Docker account.
🧪 Step 3: Download OWASP Juice Shop
OWASP Juice Shop is an intentionally vulnerable web application created for security training and awareness.
Download its official image:
sudo docker pull bkimminich/juice-shopWait until the download finishes and the command prompt returns.
▶️ Step 4: Start Your Practice Target
Run:
sudo docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shopLeave this terminal open.
The command performs four actions:
docker runstarts the container.--rmremoves the temporary container when it stops.127.0.0.1:3000:3000restricts the service to Kali on port 3000.bkimminich/juice-shopidentifies the official image.
The terminal will display activity while Juice Shop starts. This is normal.
🌐 Step 5: Open the Lab
Open the web browser inside Kali and enter:
http://127.0.0.1:3000The Juice Shop interface should appear.
You now have a working cybersecurity home lab: the target runs inside Docker, and Docker runs inside the Kali virtual machine.
⏹️ Step 6: Stop and Restart the Lab
To stop Juice Shop, return to its terminal and press:
Ctrl + CThe temporary container is removed, but the downloaded image remains available.
To restart the lab later, run:
sudo docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shopKeep the terminal open and return to http://127.0.0.1:3000 in Kali’s browser.
📸 Step 7: Create a Clean Snapshot
Stop Juice Shop with Ctrl + C, then shut down Kali:
sudo poweroffCreate a snapshot in VirtualBox, VMware Fusion, or UTM named:
Kali Lab — Juice Shop ReadyThis recovery point preserves the updated Kali installation, Docker configuration, and downloaded Juice Shop image.
Snapshots make experimentation easier, but they do not replace backups.
🔍 Your First Safe Exercises
Do not begin by trying random exploits. Start by understanding the environment you created.
Exercise 1: Confirm the web service
Start Juice Shop and open a second terminal:
curl -I http://127.0.0.1:3000Observe the response headers. The objective is simply to confirm that a web service responds.
Exercise 2: Identify the listening port
sudo ss -lntp | grep 3000Look for 127.0.0.1:3000. This confirms that the application is listening locally rather than on every network interface.
Exercise 3: Run an authorized local scan
nmap -sV -p 3000 127.0.0.1Identify:
- Whether the port is open
- Which service Nmap recognizes
- How the result relates to the Docker command
Exercise 4: Write a short lab note
Document:
- 📝 The objective
- 🎯 The address and port tested
- 🛠️ The tool or command used
- 🔎 What the output meant
- ⚖️ Why the activity was authorized
The goal is not only to run a command. It is to explain why you used it and what the result means.
Start Simple. Expand When Ready.
A useful lab grows with your understanding. Complete the first environment before adding more machines and networking.
One-VM Practice Lab
Kali and Juice Shop provide the shortest path from installation to safe practice.
- One Kali virtual machine
- Local Docker target
- No complex network setup
- Works on AMD64 and ARM64
Two-VM Network Lab
Add a separate target only after you understand the first environment.
- Kali analysis VM
- Separate target VM
- Host-only or Internal network
- Independent clean snapshots
A future two-machine lab could use this architecture:
Host computer
├── Kali Linux VM
└── Vulnerable target VMBoth machines should use the same Host-only or Internal virtual network. The vulnerable target should not use Bridged networking.
Before expanding, make sure you can:
- Start and stop the current lab
- Explain what
127.0.0.1means - Identify a listening service
- Interpret basic Nmap output
- Restore a clean snapshot
- Document an authorized exercise
🛠️ Common Problems and Fixes
Docker cannot connect to the daemon
Start Docker:
sudo systemctl start dockerThe browser cannot open Juice Shop
Confirm that:
- The terminal running Juice Shop remains open.
- The Docker command did not stop with an error.
- You entered
http://127.0.0.1:3000inside Kali—not in the host browser.
Port 3000 is already in use
Check the port:
sudo ss -lntp | grep 3000Stop the earlier container or application before restarting Juice Shop.
Kali becomes slow
Close unnecessary applications on the host. Give Kali approximately 4 GB of RAM and 2 virtual processors, but never assign all the host computer’s resources to the VM.
Mistakes to Avoid
- ❌ Do not replace
127.0.0.1with0.0.0.0. - ❌ Do not use Bridged networking for an intentionally vulnerable beginner lab.
- ❌ Do not attack the public Juice Shop demonstration server.
- ❌ Do not scan websites, school networks, company systems, or other devices without authorization.
- ❌ Do not install dozens of tools before understanding the first exercises.
- ❌ Do not skip snapshots before major changes.
Turn Your Lab Into Structured Progress
A home lab gives you an environment. A clear learning path helps you understand what to practise, why it matters, and how each concept connects.
Build Your Foundations
Learn ethical hacking, Linux, and penetration-testing fundamentals through three connected courses.
Explore the 3-Course Bundle →Prepare for CEH AI
Move into structured CEH AI v13-aligned learning when your technical foundations are ready.
Explore the CEH AI Program →Understand first. Build your lab. Practice next.
All ethical hacking techniques must only be used with explicit authorization and in legal practice environments.
Frequently Asked Questions
Official Resources
Trademark notice: CEH® is a registered trademark of EC-Council. Back2Skills is an independent training provider and is not affiliated with, endorsed by, or sponsored by EC-Council.
