Cybersecurity13 min read·

Set Up a Cybersecurity Hack Lab at Home: Docker-Based Practice Environment

Set up a cybersecurity hack lab at home using Docker. Practice penetration testing with DVWA, Juice Shop, WebGoat, and more in isolated containers.

Why a Personal Hack Lab Matters

Cybersecurity is a practical discipline. You cannot learn it by reading alone. A personal hack lab gives you a safe, legal environment to practice offensive and defensive techniques. Every vulnerability you exploit, every system you harden, and every tool you master in your lab builds real skills that employers value.

The biggest advantage of a home lab is unlimited practice time. You can break things, fix them, and try again without any consequences. This iterative learning process is how security professionals develop expertise.

Docker-Based Setup

Docker is the ideal platform for a home hack lab. Containers are lightweight, isolated, and easy to manage. You can deploy entire vulnerable environments with a single command and tear them down just as quickly.

Installing Docker

Install Docker on your system:

Linux:

sudo apt install docker.io docker-compose
sudo usermod -aG docker $USER

macOS: Download Docker Desktop from docker.com

Windows: Download Docker Desktop from docker.com

Network Configuration

Create an isolated network for your lab:

docker network create --driver bridge lab-network

This isolates your lab containers from your production network. Never expose lab containers to the internet.

Target Environments

DVWA (Damn Vulnerable Web Application)

DVWA is a PHP/MySQL web application designed for security testing. It includes vulnerabilities at multiple difficulty levels:

docker run --rm -it -p 80:80 vulnerables/web-dvwa

Practice SQL injection, XSS, command injection, and file inclusion vulnerabilities.

Juice Shop

OWASP Juice Shop is a modern vulnerable web application with hundreds of challenges:

docker run --rm -it -p 3000:3000 bkimminich/juice-shop

Juice Shop covers the OWASP Top 10 and includes challenges ranging from beginner to expert.

WebGoat

WebGoat is an OWASP project designed for teaching web application security:

docker run --rm -it -p 8080:8080 webgoat/webgoat

WebGoat provides structured lessons alongside its vulnerable application.

Metasploitable

Metasploitable is an intentionally vulnerable Linux system:

docker run --rm -it -p 2121:21 --network lab-network metasploit-framework

NodeGoat

NodeGoat demonstrates common Node.js security vulnerabilities:

docker run --rm -it -p 4000:4000 1njected/nodegoat

Tool Installation

Install essential security tools on your host machine:

Nmap

sudo apt install nmap

Metasploit Framework

curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod 755 msfinstall
./msfinstall

Burp Suite

Download the free Community Edition from PortSwigger.

Wireshark

sudo apt install wireshark

John the Ripper

sudo apt install john

Hashcat

sudo apt install hashcat

Practice Scenarios

Scenario 1: Web Application Penetration Test

  1. Deploy DVWA or Juice Shop
  2. Perform reconnaissance and directory discovery
  3. Identify input points and test for injection
  4. Exploit vulnerabilities and document findings
  5. Write a remediation report

Scenario 2: Network Penetration Test

  1. Deploy multiple containers on the lab network
  2. Scan the network with Nmap
  3. Enumerate services and versions
  4. Research and exploit known vulnerabilities
  5. Attempt lateral movement

Scenario 3: Privilege Escalation

  1. Deploy a Linux container with intentional misconfigurations
  2. Enumerate the system for privilege escalation vectors
  3. Exploit SUID binaries, kernel vulnerabilities, or misconfigurations
  4. Gain root access
  5. Document the attack path

Maintaining Your Lab

Regular Updates

Keep your tools and target environments updated:

sudo apt update && sudo apt upgrade -y
docker pull bkimminich/juice-shop
docker pull vulnerables/web-dvwa

Documentation

Maintain a lab journal documenting:

  • What you practiced
  • Techniques you learned
  • Challenges you encountered
  • Solutions you discovered

Reset and Repeat

The beauty of Docker labs is easy reset. Tear down containers and redeploy fresh instances to practice different approaches:

docker stop $(docker ps -q)

XpertClass Pre-Built Labs

XpertClass provides pre-built Docker lab environments with step-by-step instructions. No configuration required - deploy and start practicing immediately. Our labs include cybersecurity, Linux, DevOps, and cloud scenarios.

Ready to practice?

Apply what you learned with free hands-on labs on XpertClass. Deploy real Docker sandboxes — no setup required.