// Homelabs for Hackers
Start here
Homelabs for Hackers is also a repository: a practical, free guide to building your own cyber range. No rack required, no prior experience assumed. A laptop and some curiosity is genuinely enough to start.
A cyber range is your own playground for learning how to break into things — and how to spot someone breaking into yours. You build a network, attack it, watch the alerts fire, then burn it down and do it again.
What you end up with
Starting from nothing but VirtualBox on a laptop:
- An isolated network that cannot touch your home LAN or the internet
- An attacker VM — Kali or Parrot — with the essentials on it
- Vulnerable targets you can legally take apart
- A firewall controlling traffic between segments
- Enough logging and detection to actually watch an attack happen
- Repeatable lab scenarios you can run, detect, and reset in minutes
Who it is for
Anyone who would rather learn by doing than read another textbook: students who want hands-on time alongside the certs, career switchers building a portfolio that proves they can do the work, sysadmins moving across to security, CTF players who want a lab that is always there, and people who just like pulling things apart.
If you have ever spun up a VM purely to poke at it, it is aimed at you.
Two ways in
Only a laptop? That is the main path. VirtualBox is free and works better than you would expect. 16 GB of RAM is the comfortable minimum — 8 GB technically runs but you will feel it — plus about 100 GB of free SSD.
Got spare hardware? An old desktop or mini PC means more VMs and things you can leave running. Start on VirtualBox anyway to learn the shape of it, then take the Proxmox upgrade path. If you are buying, the cheap gear guide covers what actually matters second-hand — the RAM ceiling above all — with real prices.
The route through it
- Start here — work out which path you are on, and the pre-flight checklist. Enable virtualisation, pull your ISOs down before you need them, pick a naming scheme
- What is a cyber range? — optional, but it makes the rest land better
- Safety and isolation — not optional
- The VirtualBox starter range — the fun part, and the $0 build
After that it branches into network design and segmentation, the OPNsense firewall, the attacker VM, vulnerable targets, blue team basics, snapshots and resets, and GNS3 if you want to get serious about topology. There is a troubleshooting page for when it goes wrong and a glossary for the jargon.
The labs
Once the range is standing, the lab recipes are where it gets good. Each one is self-contained: a goal, a topology, build steps, the attack, what should show up in your logs, how to reset, and debrief questions worth actually answering.
Four so far — a starter range, a web app range, Windows basics, and a Microsoft Sentinel lab — labelled beginner through advanced, each with an estimate of how long it takes. They also flag what is worth screenshotting: a successful exploit next to the detection alert that caught it is a good thing to have in a portfolio.
Contribute to it
It is MIT licensed and deliberately beginner friendly. Built something, fixed a typo, wrote a lab, or explained a thing better than the page currently does? CONTRIBUTING.md has the details, and there is a blank recipe template to start from.
Stuck on something? Open an issue, or find me on Discord as thelocalfrogman. No question is too basic.