Setting Up Your Security Lab
Why You Need a Lab
Security is a hands-on skill. A lab is a safe, legal environment where you can run tools, break things, and make mistakes without harming anyone. Never practise on systems you do not own or have written permission to test.
You need three things:
- A virtual machine running Kali Linux (your toolbox)
- A TryHackMe account (legal targets to practise on)
- A handful of essential tools you will learn over this course
Part 1: Kali Linux on VirtualBox
Kali Linux is a free Linux distribution that comes with hundreds of security tools pre-installed. VirtualBox lets you run it inside a window on your normal computer, so it cannot damage your main system.
What you need
- 8 GB RAM or more (4 GB minimum)
- 40 GB of free disk space
- A 64-bit computer with virtualisation enabled
Steps (Windows, Linux, or Intel Mac)
- Download and install VirtualBox from virtualbox.org.
- Go to kali.org/get-kali and choose Virtual Machines. Download the pre-built VirtualBox image (it is large, so use a good connection or a cybercafe with fast internet).
- Extract the downloaded archive.
- In VirtualBox, choose File > Import Appliance (or double-click the .vbox file) and select the Kali image.
- Give it 4 GB RAM and 2 CPUs if you can.
- Start the VM. The default login for pre-built images is username
kaliand passwordkali. Change the password after first login by runningpasswd. - Open a terminal and update:
sudo apt update && sudo apt full-upgrade -y.
Apple Silicon Macs (M1, M2, M3)
VirtualBox does not run the standard Kali images on Apple Silicon. Use UTM (free) with the ARM64 Kali image from the same download page instead, or skip the VM and use TryHackMe's AttackBox, a Kali-like machine in your browser.
If your laptop is too weak
Use the TryHackMe AttackBox (browser-based). It works on nearly any computer and needs no installation. Free users get limited AttackBox time per day, which is enough for this course.
Lab safety rules
- Keep the VM's network on NAT (the default) so it is isolated.
- Take a snapshot after setup so you can roll back.
- Only scan machines you own or that a platform gives you as targets.
Part 2: Create a TryHackMe Account
TryHackMe offers guided, browser-based rooms with legal targets, ideal for beginners.
- Go to tryhackme.com and sign up (free).
- Choose a username that does not reveal personal information.
- Complete the Tutorial room to learn the interface.
- Start the Pre Security learning path.
Part 3: Essential Tools
You do not need to master these today, just know what they are for:
| Tool | Purpose |
|---|---|
| Nmap | Discover devices and open ports on a network |
| Wireshark | Capture and inspect network traffic |
| Burp Suite | Intercept and test web application requests |
| Metasploit | Framework for testing known vulnerabilities |
| John the Ripper / Hashcat | Test password strength by cracking hashes (on your own lab data) |
| Nikto / OWASP ZAP | Scan web applications for weaknesses |
| CyberChef | Encode, decode, and analyse data |
Try these commands in your Kali terminal to confirm things work:
whoami # shows your username
ip a # shows your network interfaces
nmap --version # confirms Nmap is installed
PRACTICE LAB
Complete these on TryHackMe. Each one applies what you learnt in this module.
Lab 1: Get comfortable with the platform
- Room: Tutorial (tryhackme.com/room/tutorial)
- Goal: Learn how to start a machine, use the AttackBox, and submit answers.
- What to do: Deploy the machine, follow the tasks, and answer the questions.
Lab 2: Connect to the network
- Room: OpenVPN (tryhackme.com/room/openvpn)
- Goal: Understand how your machine reaches TryHackMe's lab network.
- What to do: Follow the instructions to connect, or skip if you are using the AttackBox.
Lab 3: Spot phishing
- Room: search TryHackMe for Phishing Emails (for example "Phishing Emails 1")
- Goal: Analyse suspicious emails and identify red flags in headers and links.
- What to do: Work through the tasks and note the indicators you find.
Lab 4: Start the learning path
- Path: Pre Security (tryhackme.com/path/outline/presecurity)
- Goal: Build networking and Linux foundations that the next modules rely on.
- What to do: Complete the first two rooms before moving on.
Room names and links can change. If a link does not open, search for the room name on TryHackMe.
Deliverable
Write five sentences in a notes file: what you learnt, one tool you used, and one thing that confused you. Keep it. You will use these notes as a portfolio.
Interactive Exercise: Spot the Phishing Email
The editor beside this lesson contains a fake email. Click every suspicious element (sender, link, greeting, urgency, and so on), then press Check my answers. The email is fictional and uses a made-up look-alike domain for teaching purposes.
Try to find all the red flags before checking. In real life, you will often have seconds to decide.
Checklist Before Module 2
- VirtualBox (or UTM / AttackBox) working
- Kali Linux boots and is updated
- TryHackMe account created
- Tutorial room completed
- Phishing exercise completed
Try it yourself
Key Takeaways
- A security lab gives you a safe, legal place to practise. Never test systems without authorisation.
- Kali Linux on VirtualBox (or UTM on Apple Silicon) gives you a ready-made toolbox; TryHackMe AttackBox works if your laptop is weak.
- TryHackMe provides legal targets and guided learning paths ideal for beginners.
- Nmap, Wireshark, Burp Suite, and Metasploit are core tools you will learn in later modules.
- Phishing emails share patterns: fake domains, urgency, generic greetings, requests for sensitive data, and suspicious attachments.
Quick Quiz
1.Why might you use the TryHackMe AttackBox instead of a local Kali VM?
2.Which is the safest way to practise hacking skills?
3.Which tool would you use to capture and inspect network traffic?
4.In the phishing email exercise, why is 'accessbank-secure-verify.com' suspicious?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx