1. Understand Virtual Machines
A virtual machine is a full computer running inside a file on your real machine, isolated from it. This whole lab depends on that isolation, so it's worth understanding before touching a hypervisor.
2. Install Kali Linux
Your attacking machine, pre-loaded with the tools this site uses throughout. See connecting Kali Linux once Metasploitable 2 is also ready.
3. Install Metasploitable 2
Your target machine. Full walkthrough: installation guide.
4. Configure an Isolated Network
The step that keeps this lab safe. See network configuration.
5. Learn Basic Linux Commands
You'll spend most of your time in a terminal on both VMs. See the command reference for the core set used across this site.
6. Understand TCP/IP and Ports
Every scan you run is built on the idea of ports and services listening on them. See the glossary for the core terms if any of this is new.
7. Learn Nmap
The primary discovery and scanning tool used throughout this site. See the Nmap scanning tutorial.
8. Learn Service Enumeration
Once you know what's open, the next question is what it's running and how it's configured. The vulnerabilities overview is written around exactly this question, service by service.
9. Study Vulnerabilities
Work through the vulnerability categories one at a time: why each exists, how it's identified, and how it's fixed in the real world.
10. Practice in the Lab
Put it together: scan, enumerate, and investigate every service on your own Metasploitable 2 VM, and write down what you find and why it matters, the same way a real assessment gets documented.
You don't need to master each step before moving to the next. The sequence is meant to be revisited — most learners circle back to earlier steps once later ones make certain details click.