Your First Cybersecurity Homelab
Build a small cyber range, expose a real service, generate traffic, observe what changed, and connect the dots between self-hosting and security.
The conference lab already had the required tools installed for attendees. If you're recreating the workshop on your own Ubuntu machine, install the prerequisites below first. This covers the tools used in the exercises, including Docker, Docker Compose, Nmap, tcpdump, dig, and curl.
sudo apt update
sudo apt install -y docker.io docker-compose-v2 nmap tcpdump dnsutils curl
sudo systemctl enable --now docker
sudo usermod -aG docker "$USER"
Do this before continuing. Docker version commands can work even when your current shell still cannot access the Docker daemon.
newgrp docker
docker ps
Do not continue until docker ps works without sudo. If you prefer, log out and back in instead of running newgrp docker.
docker --version
docker compose version
nmap --version
tcpdump --version
dig -v
curl --version
The commands below create the Pi-hole Compose file used for the lab. They automatically detect your main network interface and timezone. The lab password is homelabvillage. Change it before using this outside a temporary lab.
mkdir -p ~/labs/pihole
cd ~/labs/pihole
PIHOLE_IFACE=$(ip route show default | awk '/default/ {print $5; exit}')
PIHOLE_TZ=$(timedatectl show -p Timezone --value)
cat > compose.yml <<EOF
services:
pihole:
container_name: pihole
image: pihole/pihole:latest
network_mode: host
environment:
TZ: "$PIHOLE_TZ"
FTLCONF_webserver_api_password: "homelabvillage" # LAB PASSWORD - CHANGE THIS
FTLCONF_dns_upstreams: "1.1.1.1;9.9.9.9"
FTLCONF_dns_interface: "$PIHOLE_IFACE"
FTLCONF_dns_listeningMode: "BIND"
volumes:
- "./etc-pihole:/etc/pihole"
restart: unless-stopped
EOF
docker compose config
docker compose up -d
docker compose ps
For a permanent Pi-hole install, give the Ubuntu machine a static IP or DHCP reservation so its address does not change. Ubuntu may already use systemd-resolved on local port 53. This lab uses Pi-hole's BIND mode so Pi-hole can bind to the detected network interface without disabling Ubuntu's local resolver.