A home lab with no targets is just a fancy VM manager. In Part 1 you built the foundation — a hypervisor and the discipline to keep the lab off your home network. This Cover6 Community session changes that: by the end, your attacker and your target are talking to each other, you’ve opened real services, and you’ve looked up your first vulnerability the way an attacker would.
Use this post as your read-ahead, then come back to it as you build.
Two machines, one isolated network
The lab is two VMs that only talk to each other:
- Kali Linux — your attack machine, loaded with the tooling you’ll actually use.
- Metasploitable 2 — a deliberately vulnerable target built for exactly this. You’re supposed to break it.
The session covers the hypervisor options so you can follow along on whatever you own — UTM on an Apple-silicon Mac, VMware Workstation Pro on Windows, or Proxmox if you’re running a dedicated box. The architecture matters here: ARM64 (M-series Macs) and AMD64 (most everything else) aren’t interchangeable, and knowing which you’re on saves you an hour of confusing errors.
The one rule that isn’t optional: keep the lab network isolated from your home network. You’re about to run vulnerable services and attack them. That traffic stays in the lab.
Prove the two machines can talk
Before you attack anything, confirm the plumbing works. A single ping from Kali to the target tells you the network is configured correctly:
ping <target-ip>
Replies coming back means your isolated network is live. No replies means you fix the network before you do anything else — most “the exploit didn’t work” problems are really “the two machines were never talking.”
Watch ports appear as you open services
Here’s the move that makes scanning click. Start with a baseline scan of the fresh target:
nmap <target-ip>
On a clean box, you’ll see a thousand ports reported closed — nothing to attack yet. Now install a service on the target and scan again:
- Install vsftpd (an FTP server), rescan, and watch port 21 appear.
- Install Apache2 (a web server), rescan, and watch port 80 appear.
Doing it in that order — scan, change one thing, scan again — teaches you what a scan actually measures. An open port is a service someone turned on. That’s the whole mental model behind reading a scan.
Research a vulnerability like an attacker
Once a service is exposed, the next question is the real one: is there a known attack for this? The session walks through Exploit-DB — the public database of known exploits — to research the FTP service you just stood up. You read the service and version, search for it, and see whether someone has already published a way in.
That loop — scan, identify the service, research the exploit — is penetration testing in miniature. Your home lab is where you run it a hundred times until it’s second nature.
Your challenge: add Nessus
The session ends with a challenge rather than a solution: add Nessus, a vulnerability scanner, to your lab and let it tell you what it finds. Then compare its findings to what you discovered by hand. Learning where an automated scanner helps — and where it misses what a human would catch — is a skill in itself.
Part 3 crosses over to the defender’s side: Security Onion, Wazuh, and incident response — watching the same attacks from the blue-team seat.
Practice on a target that’s always ready
Building the lab is worth it — but if you want to start attacking today while your VMs download, First Shell is the free Cover6 lab that runs in your browser. You get an authorized target, so you can scan it, find the open services, and prove your first exploit without configuring a single VM.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
Want to see the defender’s side early? First Watch gives you a live Splunk lab and your first SOC shift, free — the blue-team view of the same attacks: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
Where this path leads
A working home lab is foundational on the Penetration Tester path on Chrysalus. Build your free profile and add your lab build as a project.
- Read the Pentester Roadmap 2026 and the SOC Analyst Roadmap 2026.
- Not sure which lane? Take the free career path assessment.
- Keep the Cover6 Field Manual handy as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We built this live in the Cover6 Community — Kali and Metasploitable 2, an isolated network, a ping test, nmap before and after opening ports, and an Exploit-DB research walkthrough. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
