Labs

Build a home SOC lab

Practice detection and investigation on your own machine with free tools — plus five projects to get you started.

Updated October 2026 · Beginner to intermediate

A home lab lets you generate real logs, simulate attacks safely and investigate them with the same kinds of tools used in a SOC. It is also one of the best things to talk about in interviews. You can build a useful lab entirely with free software.

Stay legal and isolated. Only run attack simulations against machines you own, inside an isolated lab network. Never test techniques on systems you do not have explicit permission to use.

What you need

  • A computer with enough memory. 16 GB of RAM is a comfortable minimum for several virtual machines; 32 GB is better.
  • A hypervisor such as VirtualBox, VMware Workstation or Hyper-V.
  • Operating systems: a Windows evaluation image, a Linux server distribution and optionally a Windows Server evaluation for Active Directory.

A simple lab design

  1. Windows endpoint with Sysmon installed for detailed logging.
  2. SIEM server running Wazuh, Elastic or Splunk’s free license to collect logs.
  3. Optional domain controller to practice Active Directory and identity investigations.
  4. Optional network sensor such as Security Onion to capture traffic.
  5. An isolated virtual network connecting the machines, with internet access only when needed.

Five lab projects to try

1. Detect a brute-force attack

Generate repeated failed logons against a test account, then find the 4625 events in your SIEM and build an alert. Check whether you can spot a successful logon afterwards.

2. Trace a suspicious process

Run a harmless PowerShell command with an encoded argument, then use Sysmon event 1 to find the process, its parent and its full command line. Decode it with CyberChef.

3. Analyze your own traffic

Capture traffic with Wireshark while browsing, then identify DNS lookups, TLS handshakes and the hosts contacted.

4. Simulate attacker techniques

Use an open-source adversary emulation library such as Atomic Red Team — only inside your lab — to run individual MITRE ATT&CK techniques and check which ones your logging catches.

5. Write it up

For each project, write a short investigation report: what happened, the evidence, and how you detected it. These write-ups become portfolio pieces for job applications.

Cyber Career Lab labs

Short, focused Cyber Career Lab labs for drilling individual skills — log analysis, email headers and query writing — are in development. In the meantime, the SOC Analyst simulator lets you investigate complete incidents without building any infrastructure.

FAQ

Home lab questions

Do I need a home lab to get a SOC job?

No, but it helps. A lab gives you hands-on experience and concrete projects to discuss. Browser-based simulations are a faster alternative if you do not have the hardware.

Can I build a lab in the cloud instead?

Yes. Cloud providers offer free tiers and credits, but watch costs carefully and shut resources down when you finish.

Is it legal to run attack tools in a home lab?

Running tools against machines you own in an isolated lab is generally fine. Using them against systems you do not own or have permission to test is illegal in most countries.

No lab? No problem

Practice full investigations in your browser.

Skip the setup and investigate realistic incidents in the SOC Analyst simulator.

Start free. No experience required.