Cybersecurity Home Lab Setup Guide for Beginners
A step-by-step guide to building a safe, free practice lab on your own computer: VirtualBox, Kali Linux or Ubuntu, Wireshark, Nmap and a Splunk trial. Includes requirements, legal rules, a troubleshooting table and five first exercises.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations, examples and exercises are original. Confirm current course content on the official Coursera page.
1. Why build a home lab
Reading about packets, scans and logs only goes so far. A lab lets you generate real traffic, scan a machine, break things and fix them, all inside a safe, disposable environment. It also gives you material for a resume and portfolio.
What you will build
One or two virtual machines (VMs) on your own computer, with a packet analyser, a port scanner and a log search tool.
Cost
Free. Every tool here has a free edition or trial. Check each vendor’s current terms before you download.
Time needed
About two to four hours for setup, depending on download speed and your hardware.
2. Safety and legal rules (read first)
Only test systems you own or have written permission to test. Scanning or probing other people’s computers, networks, websites or Wi-Fi without permission can be illegal and can get you banned by your internet provider, even if you mean no harm.
- Keep targets inside your lab. Scan your own VMs and your own devices only.
- Public practice targets: the Nmap project hosts
scanme.nmap.orgfor light, polite test scans. Read its notice on nmap.org first and keep scans gentle. - Never scan your school, workplace or neighbours. Shared networks are not your lab.
- Protect your real data. Do not store personal files, real passwords or work data inside lab VMs.
- Isolate risky experiments. Use host-only or internal networks for anything involving intentionally weak systems or suspicious files.
- Capture only your own traffic. Sniffing other people’s traffic on shared Wi-Fi is not acceptable.
- Laws vary by country. If you are unsure what is allowed where you live, ask before you test.
3. System requirements
| Component | Minimum | Comfortable |
|---|---|---|
| RAM | 8 GB | 16 GB or more |
| CPU | 4 cores with virtualisation support | 6 or more cores |
| Free disk space | 60 GB | 120 GB or more (SSD preferred) |
| Host OS | Windows, Linux or Intel-based macOS | Same, kept fully updated |
| Internet | Needed for downloads and updates | Stable broadband |
| BIOS/UEFI setting | Intel VT-x or AMD-V (often called “SVM”) must be switched on | |
Apple Silicon (M-series) Macs: VirtualBox runs only Arm guests on these machines, so choose an Arm64 build of Ubuntu or Kali, or use another hypervisor such as UTM. Check the VirtualBox download page for the current status.
Suggested resource split for a 16 GB host: Kali or Ubuntu VM with 4 GB RAM and 2 CPUs; a second target VM with 2 GB RAM and 1 CPU. On an 8 GB host, run one VM at a time with 3 to 4 GB.
4. Setup steps
Work through the parts in order. Each one ends with a quick check so you know it worked.
Step 1: Prepare your computer
- Update your operating system and restart.
- Turn on virtualisation in BIOS/UEFI if it is off. On Windows, Task Manager → Performance → CPU shows “Virtualization: Enabled” when ready.
- Create a folder for lab files, such as
CyberLab, with subfoldersisosandnotes. - Free at least 60 GB of disk space.
Check: virtualisation shows as enabled and you have the free space.
Step 2: Install VirtualBox
- Download the installer for your host system from virtualbox.org.
- Run the installer with default options. Allow the network driver prompt if shown.
- Optional: install the matching Extension Pack from the same page if you need USB 2.0/3.0 support. Read its licence first, since it has its own terms.
- Open VirtualBox and confirm the main window loads.
Check: VirtualBox opens and shows the “Tools” and “New” buttons.
Step 3: Choose and install your Linux VM (Ubuntu or Kali)
| Option | Best for | Notes |
|---|---|---|
| Ubuntu | Absolute beginners, stable daily use, Splunk host | Friendly, well documented, easy to keep clean |
| Kali Linux | Security tools ready to use | Many tools preinstalled; built for testing, not general use |
Simple recommendation: start with Ubuntu for learning Linux, logs and Splunk. Add Kali later as a second VM when you want a testing toolkit.
Ubuntu
- Download an Ubuntu Desktop LTS ISO from ubuntu.com.
- In VirtualBox click New. Name it
ubuntu-lab, pick the ISO, tick “Skip unattended installation” if you prefer a manual install. - Give it 4 GB RAM (4096 MB), 2 CPUs and a 40 GB disk (dynamically allocated).
- Start the VM and follow the installer. Create a user with a strong password you will remember.
- After the first boot, update the system:
sudo apt update
sudo apt upgrade -y
Kali Linux
- From kali.org choose the Virtual Machines download for VirtualBox. It is pre-built, so you import it instead of installing.
- Verify the download using the checksum shown on the page if you can. This confirms the file was not damaged or tampered with.
- In VirtualBox use File → Import Appliance (or open the provided VirtualBox file) and follow the prompts.
- Check the official Kali documentation for the current default login, and change the password at first login.
- Update packages:
sudo apt update
sudo apt full-upgrade -y
Check: the VM boots to a desktop, has internet access, and the update commands finish without errors.
Step 4: Take your first snapshot
A snapshot saves the exact state of a VM so you can roll back after a mistake or experiment.
- Shut the VM down cleanly.
- In VirtualBox select the VM → Snapshots → Take.
- Name it
clean-install-updatedwith today’s date.
Habit: snapshot before installing new tools and before any risky test.
Step 5: Install Wireshark
Wireshark captures and displays network traffic so you can see packets for yourself.
sudo apt install wireshark -y
- When asked whether non-superusers can capture packets, choose Yes. If you missed the prompt, run
sudo dpkg-reconfigure wireshark-common. - Add your user to the capture group, then log out and back in:
sudo usermod -aG wireshark $USER
- Start Wireshark from the menu, choose the main network interface (often
enp0s3oreth0) and click the blue shark-fin button.
Check: packets scroll by while you open a web page in the VM.
Step 6: Install Nmap
Nmap finds hosts on a network and shows which ports are open.
sudo apt install nmap -y
nmap --version
Kali includes Nmap already, so on Kali only run the version check.
Test it on your own VM first:
nmap 127.0.0.1
Check: the scan completes and lists any open ports on your own machine (possibly none).
Step 7: Install the Splunk free trial
Splunk collects and searches log data. It is widely used in security operations centres (SOCs), so it is worth learning early.
- Create a free account and download Splunk Enterprise (Linux
.debpackage) from splunk.com. Trial length and daily data limits can change, so read the current terms on the download page. - Install the package from the folder where it downloaded (replace the filename with yours):
sudo dpkg -i splunk-*.deb
sudo /opt/splunk/bin/splunk start --accept-license
- Create the admin username and password when prompted.
- Open a browser inside the VM and go to
http://localhost:8000. Sign in. - Optional: have Splunk start with the VM:
sudo /opt/splunk/bin/splunk enable boot-start
Resource tip: Splunk is heavy. Give the VM at least 4 GB RAM, and close other apps while it runs. Install it on the Ubuntu VM rather than Kali to keep things tidy.
Check: the Splunk home page loads and the Search & Reporting app opens.
5. Lab networking in plain English
| VirtualBox mode | What it does | When to use it |
|---|---|---|
| NAT | VM reaches the internet through your host. Other machines cannot reach the VM. | Default. Updates and downloads. |
| NAT Network | Several VMs share a private network and also get internet access. | Two VMs that need to talk to each other. |
| Host-only | VMs and your host can talk, but there is no internet. | Isolated practice with weak or untrusted systems. |
| Internal network | VMs talk only to each other, not even to the host. | Strictest isolation. |
| Bridged | VM appears as a separate device on your real network. | Avoid for beginners. It exposes the VM, and your scans can reach real devices. |
Good starter design: put both VMs on one NAT Network. Find each VM’s address with ip a, then scan the other VM from the first.
6. Troubleshooting table
| Problem | Likely cause | Fix |
|---|---|---|
| VM will not start, error about VT-x or AMD-V | Virtualisation is off in BIOS/UEFI | Enable it in firmware settings and restart the computer. |
| Only 32-bit options in the OS type list | Virtualisation off, or another hypervisor is blocking it | Enable virtualisation. On Windows, check whether features like Hyper-V or WSL are conflicting, and follow VirtualBox’s documentation. |
| VM is very slow | Too little RAM or too many programs open | Close other apps, raise VM RAM within your limits, use an SSD, and keep video memory at the recommended level. |
| Black screen after boot | Graphics controller or video memory setting | Settings → Display: raise video memory and use the recommended graphics controller. |
| Screen will not resize, no copy and paste | Guest Additions not installed | Install Guest Additions from the VM’s Devices menu and restart the VM. |
| No internet inside the VM | Wrong network mode or disconnected adapter | Set the adapter to NAT, tick “Cable connected”, then reboot the VM. |
| Wireshark shows no interfaces | Capture permission missing | Run sudo dpkg-reconfigure wireshark-common, choose Yes, add yourself to the wireshark group, then log out and in. |
| Nmap shows every port filtered | A firewall is blocking probes, or the target is down | Check the target is running and reachable with ping, and review the target’s firewall settings. |
| Splunk page will not load on port 8000 | Service not running or still starting | Run sudo /opt/splunk/bin/splunk status, then start if needed. Wait a minute and refresh. |
| Splunk install stalls or the VM freezes | Not enough RAM or disk space | Give the VM more memory, free space, and close other programs. |
| Disk fills up quickly | Many snapshots and large log files | Delete old snapshots you no longer need, and clear downloads. |
7. Five first exercises
Do these in order. Write a few lines of notes for each one. These notes become your first portfolio entries.
Exercise 1: Build, update, snapshot
Goal: a clean, updated VM with a rollback point.
Do: finish Steps 1 to 4. Then install one harmless package, take a second snapshot, restore the first snapshot, and confirm the package is gone.
You learn: how snapshots protect you from mistakes.
Exercise 2: Capture and read your own traffic
Goal: see what a simple request looks like on the wire.
Do: start a Wireshark capture, run ping -c 4 example.com, then stop the capture. Apply the display filter icmp and note the source, destination and protocol of each packet. Repeat with a DNS lookup using the filter dns.
You learn: reading packet lists, filters, and the difference between request and reply.
Exercise 3: Scan your own second VM
Goal: map open ports on a machine you own.
Do: start a second VM on the same NAT Network and install a simple web server (sudo apt install apache2 -y). From the first VM, find its address with ip a on the target, then run:
nmap TARGET-IP
nmap -sV TARGET-IP
Record which ports are open and which service version Nmap reports. Stop the web server and scan again to compare.
You learn: ports, services, and how a change on the target shows up in a scan.
Exercise 4: Search failed logins in Splunk
Goal: turn raw logs into evidence.
Do: in Splunk go to Settings → Add Data → Monitor and add the file /var/log/auth.log. If Splunk cannot read the file, check its permissions or follow Splunk’s documentation on log access. Make a few deliberate wrong-password attempts on your VM, then search:
index=main source="/var/log/auth.log" "Failed password"
Note the times, usernames and counts. Try narrowing the time range.
You learn: loading data, basic searches, and how a SOC analyst spots suspicious activity.
Exercise 5: Write a one-page lab report
Goal: practise clear communication.
Do: combine Exercises 2 to 4 into one page: what you did, what you saw, what it means, and one improvement. Use plain language a manager could follow. Remove usernames, IP addresses and anything private before sharing it.
You learn: summarising technical work, a key skill for portfolios and interviews.
8. YouTube search links
- VirtualBox and Ubuntu install for beginners
- Importing a Kali Linux VirtualBox image
- Wireshark beginner tutorial and display filters
- Nmap beginner tutorial
- Installing Splunk Enterprise on Ubuntu
9. One-screen revision summary
- Rule one: test only systems you own or have written permission to test.
- Hardware: 8 GB RAM minimum (16 GB better), 60 GB free disk, virtualisation enabled.
- Order of setup: VirtualBox, Ubuntu or Kali, snapshot, Wireshark, Nmap, Splunk.
- Networking: NAT for internet, NAT Network for VM-to-VM, host-only or internal for isolation, avoid bridged.
- Snapshots before every new tool or risky experiment.
- Exercises: snapshot, packet capture, own-VM scan, Splunk log search, one-page report.
- Keep notes: sanitised write-ups become portfolio pieces.
10. What you should be able to do
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Software versions, trial terms and download pages change, so verify details on each vendor’s official site. Last reviewed: October 2026.
