Career Changer's Lab: Build the Machine You'll Learn On
A practical guide to building your first security lab as a career changer, with hardware, VM, and network choices that actually matter.
Most career changers skip the lab and go straight to buying certification vouchers. That's backwards. You need a place to break things before you pay to prove you can fix them. This piece walks through what to actually build, not the fantasy rack you'll never touch.
Why a real lab beats a subscription
TryHackMe and HTB Academy are good for guided exercises, but they don't teach you what happens when your VM's network adapter is misconfigured and nothing resolves. A local lab forces you to solve infrastructure problems nobody wrote a walkthrough for. That friction is where the learning actually happens. When you're troubleshooting why your Kali box can't reach your Windows target, you're practicing the exact skill a junior SOC analyst uses when a sensor goes dark.
The hardware question, answered honestly
You don't need a rack server. A machine with 32GB RAM and a 6-core CPU handles three or four VMs comfortably. If you're buying used, look at Dell Optiplex or ThinkCentre small-form-factor boxes on the secondary market — they're cheap, quiet, and take standard RAM upgrades. Avoid laptops as your only host; thermal throttling under sustained VM load will drive you crazy during a long Nessus scan or a Metasploit brute-force session.
If your current machine only has 16GB, don't panic. Run one attacker VM and one target VM at a time instead of a full network. You'll learn the same concepts, just sequentially instead of in parallel.
Choosing your hypervisor
VirtualBox is free and fine for a first lab. VMware Workstation Pro is now free for personal use and handles nested virtualization and snapshotting more reliably, which matters once you're testing malware samples or running Active Directory labs with multiple domain controllers. Proxmox is worth learning if you want the lab itself to double as a resume item — running your own hypervisor on bare metal is a legitimate DevOps and sysadmin skill, and it's what a lot of home-lab-to-SOC-analyst stories have in common.
Whatever you pick, learn snapshots immediately. Before every risky change — installing a new tool, running an exploit, editing a Windows registry key — snapshot. This habit alone will save you dozens of hours of rebuilding.
What actually belongs in the network
Build toward this minimum topology:
- Kali Linux as your attacker box
- A vulnerable target — Metasploitable2 for early practice, then something from VulnHub or a retired HTB box for more depth
- A Windows 10 or Server 2019 evaluation VM — Microsoft gives these away for 90-180 days, free, for exactly this purpose
- pfSense or OPNsense as a virtual router/firewall separating your lab network from your home network
That pfSense box is the piece people skip and shouldn't. It's how you learn firewall rules, NAT, and traffic segmentation without touching your actual home router. It also means your intentionally vulnerable Windows box isn't sitting exposed on the same subnet as your laptop and smart TV.
Logging and detection, not just attacking
If you're aiming for blue team or SOC roles, add a Security Onion or a standalone Elastic Stack (Elasticsearch, Logstash, Kibana) VM early. Point your Windows target's Sysmon logs at it. Now when you run an exploit from Kali, you can pivot to the detection side and watch the alert fire — or not fire, which teaches you just as much. This dual-perspective habit is what separates candidates who can talk fluently in interviews from candidates who can only recite tool names.
Keep a build log, not just notes on the attack
Document the lab itself: IP scheme, VM specs, what broke and how you fixed it. Recruiters and hiring managers do look at GitHub repos with a documented home lab — it's concrete proof you can stand up infrastructure, not just click through a CTF. Screenshot your pfSense rules, your network diagram, your Sysmon config. That documentation becomes portfolio material later.
Start small, then expand deliberately
Week one: Kali plus one Metasploitable target, no fancy networking. Week three: add pfSense and a second subnet. Month two: add the SIEM. Don't try to build the whole thing on day one — the rebuild cycles from getting overwhelmed cost more time than the incremental approach ever does.
Once your lab is running, pair it with Korra Studio's Breaking In and Certifications tracks to turn hands-on practice into a plan that actually lands interviews.
Rédigé avec l'aide de l'IA, relu et publié par Michal Pilch (CISSP), Korra Studio.
Ceci est une note de la base de connaissances de Korra Studio — la plateforme associe chaque sujet à un mentorat individuel.
Commencer gratuitementarrow_forward