A home lab is the single best investment you can make in a cybersecurity career. It’s where you break things safely, run the attacks you’re learning, and watch what they leave behind — all on hardware you own, with no one to answer to. This is Part 3 of the Cover6 Home Lab series, and it’s the part that turns a couple of VMs into a real, assessment-ready environment.
Use this post as your build checklist, then come back to it when you’re wiring up the domain.
Where the series stands
In Part 1 we built the foundation — the virtualization host and networking. In Part 2 we stood up a Kali Linux attacker and a custom Ubuntu target. Part 3 completes the picture with the piece that makes a lab feel like a real network: a Windows domain.
By the end of tonight you’ll have:
- Windows Server 2022 promoted to a Domain Controller — the heart of the network, running Active Directory.
- A Windows workstation joined to the domain — a normal user endpoint, the kind an attacker actually lands on.
- Nessus Essentials scanning the lab network — so you can see your environment the way a vulnerability scanner does.
- Basic log visibility in Windows Event Viewer — because an attack you can’t see is an attack you can’t learn from.
That combination — a domain, an endpoint, a scanner, and logs — is what “assessment-ready” means. It’s a miniature enterprise you can attack and defend.
Why the domain is the point
Almost every real network runs on Active Directory, and almost every serious attack goes through it. Building a domain in your lab means the techniques you practice — the logons, the privilege changes, the lateral movement — are the same ones that matter in a real environment. A standalone VM teaches you a tool. A domain teaches you a network.
And once the domain is up, the logs start telling a story. Turning on log visibility in Event Viewer now means that when you run an attack later, you can switch to the defender’s chair and watch it happen — which is the entire value of owning both sides of the lab.
Build it in the cloud if you’re short on hardware
You don’t need a powerful machine sitting in a closet. If local resources are tight, you can stand the whole thing up in the cloud and tear it down when you’re done. The session uses DigitalOcean, which gives new accounts credit to spin up VMs instantly — enough to build and run this lab without buying anything.
This lab is the Odapeeka environment
Here’s the part that connects everything: every account you create tonight becomes a target in the Cover6 SOC Lab series — the same Odapeeka University environment used in Cover6: First Watch. The lab you build here isn’t a throwaway exercise; it’s the exact scenario you’ll later attack and defend. Build it once, use it everywhere.
Use your lab, free
Once the lab is standing, the next move is to actually work it — and you don’t have to wait to build the whole thing locally to start.
- 🔵 Defend: First Watch drops you into the hosted version of this exact environment — a live Splunk lab and your first SOC shift, free.
- 🔴 Attack: First Shell gives you an authorized target to land your first exploits on, free.
Build the lab, then run the loop on it: break it, catch it, fix it, prove it.
Where this path leads
A home lab is the foundation under both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and add your lab build as a project employers can see.
- Read the SOC Analyst Roadmap 2026 and the Pentester Roadmap 2026.
- Not sure which lane? Take the free career path assessment.
- Use the Cover6 Field Manual as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We built this live in the Cover6 Community — the Domain Controller, the joined workstation, the Nessus scan, and log visibility, step by step. Planning to attend a future meetup? Use this post as your build checklist, and catch the replay above.
