VulnHub is where a lot of today's penetration testers rooted their first machine. You download a deliberately vulnerable virtual machine, boot it next to Kali Linux on your own computer, and try to go from "I can see an IP address" to "I am root." No subscription, no VPN, no leaderboard. The catch is that you are also the system administrator, so the first hour often goes to networking instead of hacking. If you want to feel that scan-login-escalate loop before you set anything up, the free Nmap Commands lab on HackerDNA runs the same pattern in your browser in about twenty minutes.
This guide covers what VulnHub is in 2026, whether it is still worth your time, how to build a safe lab in VirtualBox step by step, which five machines to try first, and what to use instead when the setup gets in your way.
TL;DR: VulnHub is a free archive of downloadable vulnerable virtual machines that you attack offline from your own Kali VM. OffSec bought it in 2020 and no new machine has been published since July 2022, but the catalog still downloads and still teaches the full boot-to-root workflow. Run every VulnHub box on a host-only network, start with Basic Pentesting: 1 or DC-1, and switch to browser-based labs if you are on an Apple Silicon Mac or short on RAM.
What Is VulnHub?
VulnHub is a free catalog of intentionally vulnerable virtual machines, built by the security community and mirrored on vulnhub.com so they stay downloadable. Each machine is a self-contained target: you import it into VirtualBox or VMware, attack it from another VM, and capture the flags or root access its author hid inside.
The project's own about page puts the goal plainly: to provide material that lets anyone "gain practical 'hands-on' experience in digital security." Most machines follow the boot-to-root format. You start with nothing but network access, find a way in as a low-privileged user, then escalate to root.
Three facts shape how you should use it today:
- OffSec owns it. Offensive Security, the company behind the OSCP, announced the acquisition on July 29, 2020, and promised that all VulnHub content would stay free (Help Net Security coverage).
- It is an archive now. The newest entry on the timeline is Matrix-Breakout: 2 Morpheus by Jay Beale, released on July 11, 2022. Nothing has been added since.
- The archive still works. Mirrors, checksums, and walkthrough links are all still live on vulnhub.com as of October 2026.
Is VulnHub Still Worth It in 2026?
Yes, with one caveat. The software inside most machines is years out of date, so you will exploit old WordPress plugins, old Samba versions, and old kernels. That is fine for learning methodology: enumerate, find a foothold, escalate. It is less useful if you want to practice against modern stacks like JWT authentication, cloud metadata, or container escapes.
Where VulnHub still beats almost everything is ownership. The VM is on your disk. You can snapshot it, break it, restore it, and attack it at 2 AM on a plane with no Wi-Fi. Building that lab also teaches virtual networking, which you will need later anyway.
What You Need Before You Download Anything
A VulnHub lab is two virtual machines talking to each other on a private network: your attacker (usually Kali Linux) and the target. Before you start, check that your setup can handle both.
- A hypervisor: VirtualBox is free and is what most VulnHub authors test with. VMware Workstation and Fusion work too, but some machines (The Planets: Earth, for example) warn that they were only tested on VirtualBox.
- An attacker VM: the official Kali Linux VirtualBox image saves you an install. Parrot Security works as well.
- Enough memory for two VMs at once: your host, Kali, and the target all need RAM at the same time. If your laptop already struggles with a browser and one VM, a browser-based lab will be less painful.
- Disk space: targets range from 186 MB (Kioptrix: Level 1) to 2.6 GB (Basic Pentesting: 1), and Kali itself is far bigger than any of them.
Apple Silicon Macs: VulnHub machines are built for Intel and AMD (x86) processors. VirtualBox's Apple Silicon build is designed for ARM guests, so on an M-series Mac you would need x86 emulation through UTM and QEMU, which works but runs noticeably slower. If that is your machine, OffSec's PG Play or a browser-based platform is the practical choice.
How to Set Up VulnHub in VirtualBox: Step by Step
This is the setup that avoids the two classic beginner problems: "I cannot find the target's IP" and "I accidentally put a vulnerable machine on my home network."
- Download and verify. Grab the machine from its VulnHub entry page (use the Mirror link if the author's original link is dead). Every entry lists an MD5 and SHA1 checksum. Run
sha1sum file.ovaon Linux orshasum file.ovaon macOS and compare. - Extract if needed. An
.ovafile imports directly. A.zipor.rar(DC-1 and Kioptrix ship this way) needs extracting first, and may contain VMware files rather than an.ova. - Import. In VirtualBox, use File > Import Appliance and select the
.ovaor.ovf. - Switch the network to Host-only. Open the target's Settings > Network and set Adapter 1 to Host-only Adapter. Some machines ship set to Bridged (DC-1's author says so on its page), which would drop a vulnerable box onto your real network. Change it before the first boot.
- Put Kali on the same network. Give your Kali VM a Host-only adapter on the same network. Keep a second NAT adapter on Kali only if you need internet for updates. The target never gets one.
- Snapshot both VMs. Take a snapshot of the target before you touch it. If you break a service with a bad exploit, restore and try again in seconds.
- Boot the target and leave it at the login prompt. You are not supposed to log in from the console. The VulnHub FAQ answers "what's the password?" with: "that's the aim of it!"
By default, VirtualBox's host-only network uses the 192.168.56.0/24 range, with your host at 192.168.56.1. Most VulnHub machines use DHCP, so the target picks up an address in that range automatically. Each entry page has a Networking section that tells you whether the machine expects DHCP or a static IP.
Finding the Target and Running Your First Scan
Your first real task on any VulnHub box is finding it. The target does not tell you its IP, so you discover it the way you would on a real internal network.
From Kali, check which network you are on, then sweep it:
ip a # note your eth interface on 192.168.56.x
sudo netdiscover -r 192.168.56.0/24 # ARP sweep of the host-only network
nmap -sn 192.168.56.0/24 # or a ping sweep with Nmap
On a host-only network, you will typically see the host (.1), the VirtualBox DHCP server, your own Kali address, and one new host: the target. A quick trick: VirtualBox network cards use MAC addresses starting with 08:00:27, which netdiscover labels with the vendor name "PCS Systemtechnik GmbH," so anything else on that list is not one of your VMs.
Then scan the target properly:
nmap -sC -sV -p- -oN target.nmap 192.168.56.103
That command checks all 65,535 TCP ports (-p-), identifies service versions (-sV), runs the default scripts (-sC), and saves the result to a file you will reread ten times. On a local host-only network it usually finishes in a minute or two, which is one quiet advantage of VulnHub over remote labs. If the flags are new to you, keep our Nmap cheat sheet open in another tab.
Target not showing up? Check three things in order: both VMs are on the same host-only network, the target finished booting (watch its console), and the entry page does not list a static IP outside 192.168.56.0/24. If it does, add a second host-only network with that subnet in VirtualBox's Network Manager.
5 Best VulnHub Machines for Beginners
With hundreds of entries and author-assigned difficulty labels that do not always agree with each other, picking a first box is harder than it should be. These five have clear descriptions, beginner-friendly design, and plenty of community write-ups for when you are truly stuck.
| Machine | Released | Download | What you practice |
|---|---|---|---|
| Basic Pentesting: 1 | Dec 2017 | 2.6 GB .ova | Several remote entry points and several escalation paths |
| DC-1 | Feb 2019 | 733 MB .zip | CMS exploitation, five flags with hints |
| The Planets: Earth | Nov 2021 | 2.0 GB .ova | Web enumeration, user and root flags |
| Mr-Robot: 1 | Jun 2016 | 704 MB .ova | WordPress, three hidden keys |
| Kioptrix: Level 1 | Feb 2010 | 186 MB .rar | Old services with public exploits |
1. Basic Pentesting: 1
Josiah Pierce built this one for his university's security club, and the description says it is "specifically intended for newcomers to penetration testing." It has multiple remote vulnerabilities and multiple privilege escalation vectors, so once you root it, go back and find a second path. That habit is worth more than the box itself. It was tested on VirtualBox, which makes it the safest first import.
2. DC-1
DC-1 is a 32-bit Debian machine with five flags, and its author included clues in the early ones specifically for beginners. Experienced players skip straight to root. You should not: read each flag, because each one nudges you toward the next technique. Remember to switch it from Bridged to Host-only before booting.
3. The Planets: Earth
One of the last machines added to VulnHub (November 2021). The author describes it as easy but "on the harder side of easy," with a user flag and a root flag. It is a good second or third box because it rewards careful web enumeration over firing exploits, and it only claims VirtualBox support.
4. Mr-Robot: 1
Themed on the TV series, with three keys that get progressively harder to find. The author rates it beginner-intermediate and promises no advanced exploitation or reverse engineering. It is the most popular box on this list, which means spoilers are everywhere. Avoid searching its name until you are done.
5. Kioptrix: Level 1
The oldest machine here (2010) and a rite of passage. Its goal is simply root "via any means possible." Our honest take: do not make it your first import. It ships as a .rar rather than a ready .ova, and getting a 16-year-old VM to boot cleanly is a networking lesson more than a hacking lesson. Come back to it once your lab works.
How to Work a VulnHub Box Without Reading the Walkthrough
Every VulnHub entry links to community walkthroughs, and that is both the best and worst thing about the platform. Read one too early and you learn the answer to that box, not how to find answers.
In practice, the beginners who improve fastest follow a simple routine:
- Enumerate everything before exploiting anything. Full port scan, then every web directory, every share, every version string. Write it all down in one notes file per box.
- Search versions, not box names. Look up "Drupal 7 exploit" or the exact service version Nmap reported, never "DC-1 walkthrough."
- Set a timer. Allow yourself 45 minutes on one idea. If nothing moves, reread your notes from step 1, because the answer is almost always something you already found and skipped.
- Peek, do not read. When you open a walkthrough, read only the next heading, then close it and continue alone.
- Escalate methodically. Once you have a shell, check sudo rights, SUID binaries, cron jobs, and writable files before trying kernel exploits. The manual enumeration chapter of HackerDNA's Linux privilege escalation course walks through each of these checks in order.
- Write your own short write-up. Three paragraphs: how you got in, how you escalated, what you missed. The Basic Pentesting author asks for exactly this, and it is what turns one solved box into a reusable skill.
If the scanning and enumeration side feels shaky, the active reconnaissance chapter of HackerDNA's network penetration testing course covers the host discovery and scanning you will repeat on every single VulnHub machine.
VulnHub Alternatives When the Setup Gets in the Way
VulnHub is the right tool when you want offline practice and a lab you fully control. When you want new content, guidance, or zero setup, these are better fits:
| Option | Price | Setup | New content | Best for |
|---|---|---|---|---|
| VulnHub | Free | VirtualBox + Kali on your machine | None since 2022 | Offline practice, learning virtual networking |
| OffSec PG Play | Free | In-browser Kali | Limited pool, 3 hours a day | VulnHub-style boxes without the download |
| Vulhub (no "n") | Free, open source | Docker Compose | Actively maintained | Reproducing one specific CVE |
| HackerDNA | Free tier, Pro plan | Browser, no VPN | Regular new labs | Guided boot-to-root labs with user and root flags |
OffSec PG Play is the closest substitute. Its Proving Grounds page lists "50+ training labs with dedicated machines designed by the VulnHub community," played through an in-browser Kali with a 3-hour limit. Many of the boxes you would download from VulnHub are there, already running.
Vulhub is a different project that people confuse with VulnHub all the time. It is an open-source collection of pre-built vulnerable Docker environments, each built around one real vulnerability. Great for studying a specific CVE, but there is no box to root and no flag to capture.
HackerDNA keeps the format VulnHub made popular (find a way in, grab the user flag, escalate, grab the root flag) and removes the setup. Labs run in the browser with an attack terminal included, and many have guided questions that check your progress along the way. Once the Nmap Commands lab feels easy, Infiltrator is a good next step: forge a login token, get a foothold, and work your way to root.
For a wider comparison of paid and free platforms, see our roundup of Hack The Box alternatives.
Legal and Ethical Considerations
Critical reminder: VulnHub machines are built to be attacked. Your router, your school network, and anything on the internet are not. Always get explicit written authorization before testing any system you do not own.
- Treat every download as untrusted code. VulnHub's FAQ is blunt: it cannot check the machines submitted to it, and an unknown VM could try to attack your host or network. Verify checksums and keep targets isolated.
- Never bridge a vulnerable VM. The FAQ recommends you do not run these machines on a home network, a production network, or anything with internet access. Host-only exists for this reason.
- Watch your target IP. A typo in a subnet can point your scanner at a real device. Confirm the target before every exploit, especially if Kali also has a NAT adapter.
- Keep your write-ups to lab machines. Publishing a VulnHub walkthrough is welcome. Publishing techniques used against systems you had no permission to test is not.
Frequently Asked Questions
Is VulnHub free?
Yes. Every machine on VulnHub is free to download, and OffSec committed to keeping it that way when it acquired the project in 2020. There is no account, subscription, or paid tier.
Is VulnHub still active?
The website and downloads still work, but no new machines have been published since July 11, 2022. Treat it as a stable archive of a few hundred classic boxes rather than a platform that grows.
Is VulnHub good for OSCP preparation?
It is a solid foundation for the methodology OSCP tests: enumeration, foothold, privilege escalation, and note-taking. For exam-style practice, OffSec's own Proving Grounds Practice is closer, since those machines are built by the exam's creators.
What is the difference between VulnHub and Vulhub?
VulnHub hosts complete vulnerable virtual machines that you attack from start to root. Vulhub is a separate open-source project of Docker Compose environments, each reproducing one specific vulnerability for study.
Can I run VulnHub machines on a Mac?
On an Intel Mac, yes, with VirtualBox or VMware Fusion. On an Apple Silicon Mac, VulnHub's x86 images need emulation through UTM and QEMU, which is slow. Browser-based labs avoid the problem entirely.
What is the easiest VulnHub machine?
Basic Pentesting: 1 is the safest first choice: its author built it for newcomers and tested it on VirtualBox. DC-1 is a close second because its first flags contain hints that guide beginners toward the next step.
Last verified: October 2026. Release dates, file sizes, and machine descriptions checked on each machine's vulnhub.com entry page. PG Play details checked on OffSec's Proving Grounds page.
Your Next Steps
VulnHub is still one of the best free ways to learn the full boot-to-root workflow, as long as you treat it as an archive and respect its setup. Install VirtualBox, put Kali and one target on a host-only network, and root Basic Pentesting: 1 this week without opening a walkthrough. Then write three paragraphs about how you did it.
If the download and networking are what is stopping you, skip them for now. Start with the free Nmap Commands lab to run the scan, log in, and escalate loop in your browser, then move on to Infiltrator for a full chain from web foothold to root. Between boxes, the Linux privilege escalation course fills in the root half of the workflow, which is where most beginners stall. You can start with HackerDNA's free tier - no credit card required.