Cybersecurity Home Lab Setup Guide for Beginners

    A step-by-step guide to building a safe, free practice lab on your own computer: VirtualBox, Kali Linux or Ubuntu, Wireshark, Nmap and a Splunk trial. Includes requirements, legal rules, a troubleshooting table and five first exercises.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations, examples and exercises are original. Confirm current course content on the official Coursera page.

    1. Why build a home lab

    Reading about packets, scans and logs only goes so far. A lab lets you generate real traffic, scan a machine, break things and fix them, all inside a safe, disposable environment. It also gives you material for a resume and portfolio.

    What you will build

    One or two virtual machines (VMs) on your own computer, with a packet analyser, a port scanner and a log search tool.

    Cost

    Free. Every tool here has a free edition or trial. Check each vendor’s current terms before you download.

    Time needed

    About two to four hours for setup, depending on download speed and your hardware.

    2. Safety and legal rules (read first)

    Only test systems you own or have written permission to test. Scanning or probing other people’s computers, networks, websites or Wi-Fi without permission can be illegal and can get you banned by your internet provider, even if you mean no harm.

    • Keep targets inside your lab. Scan your own VMs and your own devices only.
    • Public practice targets: the Nmap project hosts scanme.nmap.org for light, polite test scans. Read its notice on nmap.org first and keep scans gentle.
    • Never scan your school, workplace or neighbours. Shared networks are not your lab.
    • Protect your real data. Do not store personal files, real passwords or work data inside lab VMs.
    • Isolate risky experiments. Use host-only or internal networks for anything involving intentionally weak systems or suspicious files.
    • Capture only your own traffic. Sniffing other people’s traffic on shared Wi-Fi is not acceptable.
    • Laws vary by country. If you are unsure what is allowed where you live, ask before you test.

    3. System requirements

    ComponentMinimumComfortable
    RAM8 GB16 GB or more
    CPU4 cores with virtualisation support6 or more cores
    Free disk space60 GB120 GB or more (SSD preferred)
    Host OSWindows, Linux or Intel-based macOSSame, kept fully updated
    InternetNeeded for downloads and updatesStable broadband
    BIOS/UEFI settingIntel VT-x or AMD-V (often called “SVM”) must be switched on

    Apple Silicon (M-series) Macs: VirtualBox runs only Arm guests on these machines, so choose an Arm64 build of Ubuntu or Kali, or use another hypervisor such as UTM. Check the VirtualBox download page for the current status.

    Suggested resource split for a 16 GB host: Kali or Ubuntu VM with 4 GB RAM and 2 CPUs; a second target VM with 2 GB RAM and 1 CPU. On an 8 GB host, run one VM at a time with 3 to 4 GB.

    4. Setup steps

    Work through the parts in order. Each one ends with a quick check so you know it worked.

    Step 1: Prepare your computer
    1. Update your operating system and restart.
    2. Turn on virtualisation in BIOS/UEFI if it is off. On Windows, Task Manager → Performance → CPU shows “Virtualization: Enabled” when ready.
    3. Create a folder for lab files, such as CyberLab, with subfolders isos and notes.
    4. Free at least 60 GB of disk space.

    Check: virtualisation shows as enabled and you have the free space.

    Step 2: Install VirtualBox
    1. Download the installer for your host system from virtualbox.org.
    2. Run the installer with default options. Allow the network driver prompt if shown.
    3. Optional: install the matching Extension Pack from the same page if you need USB 2.0/3.0 support. Read its licence first, since it has its own terms.
    4. Open VirtualBox and confirm the main window loads.

    Check: VirtualBox opens and shows the “Tools” and “New” buttons.

    Step 3: Choose and install your Linux VM (Ubuntu or Kali)
    OptionBest forNotes
    UbuntuAbsolute beginners, stable daily use, Splunk hostFriendly, well documented, easy to keep clean
    Kali LinuxSecurity tools ready to useMany tools preinstalled; built for testing, not general use

    Simple recommendation: start with Ubuntu for learning Linux, logs and Splunk. Add Kali later as a second VM when you want a testing toolkit.

    Ubuntu

    1. Download an Ubuntu Desktop LTS ISO from ubuntu.com.
    2. In VirtualBox click New. Name it ubuntu-lab, pick the ISO, tick “Skip unattended installation” if you prefer a manual install.
    3. Give it 4 GB RAM (4096 MB), 2 CPUs and a 40 GB disk (dynamically allocated).
    4. Start the VM and follow the installer. Create a user with a strong password you will remember.
    5. After the first boot, update the system:
    sudo apt update
    sudo apt upgrade -y

    Kali Linux

    1. From kali.org choose the Virtual Machines download for VirtualBox. It is pre-built, so you import it instead of installing.
    2. Verify the download using the checksum shown on the page if you can. This confirms the file was not damaged or tampered with.
    3. In VirtualBox use File → Import Appliance (or open the provided VirtualBox file) and follow the prompts.
    4. Check the official Kali documentation for the current default login, and change the password at first login.
    5. Update packages:
    sudo apt update
    sudo apt full-upgrade -y

    Check: the VM boots to a desktop, has internet access, and the update commands finish without errors.

    Step 4: Take your first snapshot

    A snapshot saves the exact state of a VM so you can roll back after a mistake or experiment.

    1. Shut the VM down cleanly.
    2. In VirtualBox select the VM → Snapshots → Take.
    3. Name it clean-install-updated with today’s date.

    Habit: snapshot before installing new tools and before any risky test.

    Step 5: Install Wireshark

    Wireshark captures and displays network traffic so you can see packets for yourself.

    sudo apt install wireshark -y
    1. When asked whether non-superusers can capture packets, choose Yes. If you missed the prompt, run sudo dpkg-reconfigure wireshark-common.
    2. Add your user to the capture group, then log out and back in:
    sudo usermod -aG wireshark $USER
    1. Start Wireshark from the menu, choose the main network interface (often enp0s3 or eth0) and click the blue shark-fin button.

    Check: packets scroll by while you open a web page in the VM.

    Step 6: Install Nmap

    Nmap finds hosts on a network and shows which ports are open.

    sudo apt install nmap -y
    nmap --version

    Kali includes Nmap already, so on Kali only run the version check.

    Test it on your own VM first:

    nmap 127.0.0.1

    Check: the scan completes and lists any open ports on your own machine (possibly none).

    Step 7: Install the Splunk free trial

    Splunk collects and searches log data. It is widely used in security operations centres (SOCs), so it is worth learning early.

    1. Create a free account and download Splunk Enterprise (Linux .deb package) from splunk.com. Trial length and daily data limits can change, so read the current terms on the download page.
    2. Install the package from the folder where it downloaded (replace the filename with yours):
    sudo dpkg -i splunk-*.deb
    sudo /opt/splunk/bin/splunk start --accept-license
    1. Create the admin username and password when prompted.
    2. Open a browser inside the VM and go to http://localhost:8000. Sign in.
    3. Optional: have Splunk start with the VM:
    sudo /opt/splunk/bin/splunk enable boot-start

    Resource tip: Splunk is heavy. Give the VM at least 4 GB RAM, and close other apps while it runs. Install it on the Ubuntu VM rather than Kali to keep things tidy.

    Check: the Splunk home page loads and the Search & Reporting app opens.

    5. Lab networking in plain English

    VirtualBox modeWhat it doesWhen to use it
    NATVM reaches the internet through your host. Other machines cannot reach the VM.Default. Updates and downloads.
    NAT NetworkSeveral VMs share a private network and also get internet access.Two VMs that need to talk to each other.
    Host-onlyVMs and your host can talk, but there is no internet.Isolated practice with weak or untrusted systems.
    Internal networkVMs talk only to each other, not even to the host.Strictest isolation.
    BridgedVM appears as a separate device on your real network.Avoid for beginners. It exposes the VM, and your scans can reach real devices.

    Good starter design: put both VMs on one NAT Network. Find each VM’s address with ip a, then scan the other VM from the first.

    6. Troubleshooting table

    ProblemLikely causeFix
    VM will not start, error about VT-x or AMD-VVirtualisation is off in BIOS/UEFIEnable it in firmware settings and restart the computer.
    Only 32-bit options in the OS type listVirtualisation off, or another hypervisor is blocking itEnable virtualisation. On Windows, check whether features like Hyper-V or WSL are conflicting, and follow VirtualBox’s documentation.
    VM is very slowToo little RAM or too many programs openClose other apps, raise VM RAM within your limits, use an SSD, and keep video memory at the recommended level.
    Black screen after bootGraphics controller or video memory settingSettings → Display: raise video memory and use the recommended graphics controller.
    Screen will not resize, no copy and pasteGuest Additions not installedInstall Guest Additions from the VM’s Devices menu and restart the VM.
    No internet inside the VMWrong network mode or disconnected adapterSet the adapter to NAT, tick “Cable connected”, then reboot the VM.
    Wireshark shows no interfacesCapture permission missingRun sudo dpkg-reconfigure wireshark-common, choose Yes, add yourself to the wireshark group, then log out and in.
    Nmap shows every port filteredA firewall is blocking probes, or the target is downCheck the target is running and reachable with ping, and review the target’s firewall settings.
    Splunk page will not load on port 8000Service not running or still startingRun sudo /opt/splunk/bin/splunk status, then start if needed. Wait a minute and refresh.
    Splunk install stalls or the VM freezesNot enough RAM or disk spaceGive the VM more memory, free space, and close other programs.
    Disk fills up quicklyMany snapshots and large log filesDelete old snapshots you no longer need, and clear downloads.

    7. Five first exercises

    Do these in order. Write a few lines of notes for each one. These notes become your first portfolio entries.

    Exercise 1: Build, update, snapshot

    Goal: a clean, updated VM with a rollback point.

    Do: finish Steps 1 to 4. Then install one harmless package, take a second snapshot, restore the first snapshot, and confirm the package is gone.

    You learn: how snapshots protect you from mistakes.

    Exercise 2: Capture and read your own traffic

    Goal: see what a simple request looks like on the wire.

    Do: start a Wireshark capture, run ping -c 4 example.com, then stop the capture. Apply the display filter icmp and note the source, destination and protocol of each packet. Repeat with a DNS lookup using the filter dns.

    You learn: reading packet lists, filters, and the difference between request and reply.

    Exercise 3: Scan your own second VM

    Goal: map open ports on a machine you own.

    Do: start a second VM on the same NAT Network and install a simple web server (sudo apt install apache2 -y). From the first VM, find its address with ip a on the target, then run:

    nmap TARGET-IP
    nmap -sV TARGET-IP

    Record which ports are open and which service version Nmap reports. Stop the web server and scan again to compare.

    You learn: ports, services, and how a change on the target shows up in a scan.

    Exercise 4: Search failed logins in Splunk

    Goal: turn raw logs into evidence.

    Do: in Splunk go to Settings → Add Data → Monitor and add the file /var/log/auth.log. If Splunk cannot read the file, check its permissions or follow Splunk’s documentation on log access. Make a few deliberate wrong-password attempts on your VM, then search:

    index=main source="/var/log/auth.log" "Failed password"

    Note the times, usernames and counts. Try narrowing the time range.

    You learn: loading data, basic searches, and how a SOC analyst spots suspicious activity.

    Exercise 5: Write a one-page lab report

    Goal: practise clear communication.

    Do: combine Exercises 2 to 4 into one page: what you did, what you saw, what it means, and one improvement. Use plain language a manager could follow. Remove usernames, IP addresses and anything private before sharing it.

    You learn: summarising technical work, a key skill for portfolios and interviews.

    8. YouTube search links

    9. One-screen revision summary

    • Rule one: test only systems you own or have written permission to test.
    • Hardware: 8 GB RAM minimum (16 GB better), 60 GB free disk, virtualisation enabled.
    • Order of setup: VirtualBox, Ubuntu or Kali, snapshot, Wireshark, Nmap, Splunk.
    • Networking: NAT for internet, NAT Network for VM-to-VM, host-only or internal for isolation, avoid bridged.
    • Snapshots before every new tool or risky experiment.
    • Exercises: snapshot, packet capture, own-VM scan, Splunk log search, one-page report.
    • Keep notes: sanitised write-ups become portfolio pieces.

    10. What you should be able to do

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Software versions, trial terms and download pages change, so verify details on each vendor’s official site. Last reviewed: October 2026.