CEH Tools, Labs & Practical Training
CEH Tools, Labs & Practical Training
Section titled “CEH Tools, Labs & Practical Training”The CEH exam is multiple choice, but the practical CEH credential and real-world employer expectations require hands-on skill. This document maps the practical training ecosystem around the CEH v13 curriculum: EC-Council’s own labs, third-party platforms, the toolset, an 8-12 week free study plan, and a single-laptop home lab.
Key takeaway: Spend 60% of prep time at the keyboard. The cheapest path to passing CEH and CEH Practical is TryHackMe Premium (~$10.50/mo annual) + PortSwigger Web Security Academy (free) + a self-hosted Kali/Metasploitable lab on VirtualBox.
7.1 EC-Council’s official iLab, iRange, CEH Engage & CodeRed
Section titled “7.1 EC-Council’s official iLab, iRange, CEH Engage & CodeRed”EC-Council operates its own cloud-based practice infrastructure. Four distinct products exist.
iLab is EC-Council’s cloud-hosted range of vulnerable VMs and guided exercises, accessed via browser (RDP/SSH into preconfigured victims). The library covers Ethical Hacking (107+ exercises), Penetration Testing (15), Computer Forensics (34), Secure Programming (68), and Disaster Recovery. 2026 price: $199 per 6-month subscription; a free 7-day trial of one System Hacking module is available. Source: https://ilabs.eccouncil.org/store/
iRange
Section titled “iRange”The older term for EC-Council’s red-team cyber range that iLab now sits inside. Bundled with higher-tier CEH training packages; not sold standalone. Unguided practice against multi-host networks.
CEH Engage (v13 practice range)
Section titled “CEH Engage (v13 practice range)”The v13 addition. A four-phase, flag-capturing engagement against a simulated company “ABCD” with persistent vulnerable targets. Each phase is 4 hours (16 hours total). Candidates get only a Parrot Security console and one Windows desktop - no walkthrough, no objectives. Reserved for CEH v13 Elite package holders; not sold standalone. Source: https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh-engage/
CodeRed
Section titled “CodeRed”EC-Council’s general-purpose video/course subscription. Marketed via limited-time bundles (e.g. “Ultimate Red Team Cyber Suite” - promo $49.99 from $399 for 15 courses + 3 bonus courses, 1 year access). Individual courses $11.99. Not required for CEH. Source: https://nextgen.eccouncil.org/the-ultimate-red-team-cyber-suite-exclusive-offer/
Key takeaway: For CEH itself, you do not need iLab or CodeRed. The exam is voucher + self-study + free platforms. Buy iLab only if you want the guided EC-Council experience and have $199 on top of your exam voucher. CEH main package: ~$1,699 on-demand, ~$2,499 live, ~$3,999 unlimited (source: https://pricingsaas.com/companies/eccouncil).
7.2 Alternative hands-on platforms (free + paid)
Section titled “7.2 Alternative hands-on platforms (free + paid)”These cover the same CEH domains (recon, scanning, enumeration, exploitation, web, wireless, cloud) with comparable realism to iLab, often for less money.
TryHackMe (THM)
Section titled “TryHackMe (THM)”- Free tier: hundreds of beginner rooms, 1-hour/day AttackBox, free OpenVPN
- Premium: $16.99/mo or $10.50/mo annual ($126/yr) - unlocks 1,000+ rooms, all learning paths, unlimited AttackBox, 15% off THM certs
- MAX (June 2026): $18.99/mo annual - adds advanced paths, persistent AttackBox, AWS/Azure 101 cloud paths, 40% cert discount
- “Jr Pentester” and “Cyber Security 101” map almost 1:1 to CEH v13 domain weights
- Source: https://tryhackme.com/pricing
HackTheBox (HTB)
Section titled “HackTheBox (HTB)”- VIP: $14/mo - all retired machines, personal OpenVPN
- VIP+: $20/mo - adds Pro Labs (Dante, Zephyr, Offshore) and dedicated lab access
- HTB Academy: Silver $223/yr, Gold Annual $490/yr (Gold includes a free CPTS voucher)
- TJ Null’s OSCP-like HTB list is the de-facto CEH/OSCP box checklist (Lame, Active, Forest, Sauna, etc.)
- CPTS ($210) is widely considered OSCP-comparable at one-eighth the price
- Source: https://certcompass.org/tryhackme-vs-hackthebox/
PortSwigger Web Security Academy (free)
Section titled “PortSwigger Web Security Academy (free)”- Cost: 100% free. 250+ browser-based labs (SQLi, XSS, SSRF, HTTP request smuggling, OAuth, JWT, prototype pollution), solvable with Burp Suite Community Edition
- Best for: OWASP Top 10, CEH’s “Web Application Hacking” domain, modern web attack surfaces
- Burp Suite Certified Practitioner (BSCP): $99 - practical web pentest cert that complements CEH
- Source: https://portswigger.net/web-security
PentesterLab PRO
Section titled “PentesterLab PRO”- 700+ hands-on web exploitation exercises + video walkthroughs
- $19.99/mo or $199.99/yr (Student: $34.99/3-mo)
- Best for: code-review and CVE-driven exploitation practice
- Source: https://pentesterlab.com/pro
VulnHub (free)
Section titled “VulnHub (free)”- 800+ downloadable vulnerable VMs (OVA/VMDK) - run locally in VirtualBox/VMware
- No cloud, no subscription, no internet needed after download
- Classic OSCP-prep machines: Kioptrix 1-5, Mr. Robot, DC-1, Stapler, FristiLeaks
- Source: https://secverse.net/cybersecurity-resources/cybersecurity-virtual-labs/vulnhub-oscp-practice/
PicoCTF / CyLab Security Academy (free)
Section titled “PicoCTF / CyLab Security Academy (free)”- Free gamified CTF by Carnegie Mellon; ages 13+
- 2026 competition ran March 9-19; platform stays open year-round in the picoGym
- Categories: crypto, web, forensics, reverse engineering, binary exploitation
- Source: https://picoctf.org/
CyberDefenders (blue team)
Section titled “CyberDefenders (blue team)”- Free blue-team CTF challenges, paid “CCD” credential path
- Best for: SOC/IR practice that complements CEH’s “Incident Response” domain
- Source: https://cyberdefenders.org/
RangeForce, CloudRange, LetsDefend (enterprise blue-team)
Section titled “RangeForce, CloudRange, LetsDefend (enterprise blue-team)”- RangeForce: enterprise live-fire team exercises, MITRE ATT&CK/D3FEND aligned
- CloudRange: instructor-led SOC simulation programs
- LetsDefend: SOC analyst path, recently acquired by Hack The Box
- All three are enterprise-priced and best suited to corporate SOC teams
- Source: https://www.cloudrangecyber.com/blue-team-programs, https://letsdefend.io/
Platform comparison table
Section titled “Platform comparison table”| Platform | Free/Paid (2026) | CEH relevance | Cost | Best for |
|---|---|---|---|---|
| EC-Council iLab | Paid | Exact (v13 syllabus) | $199 / 6 mo | Guided EC-Council experience |
| CEH Engage | Bundle-only (Elite) | Exact | incl. w/ Elite pkg | 4-phase flag capture exam-style |
| TryHackMe Premium | Freemium | High (Jr Pentester path) | $10.50/mo annual | Beginners, structured paths |
| HackTheBox VIP+ | Freemium | High (TJ Null list) | $20/mo | OSCP-style retired machines |
| HTB Academy Gold | Paid | Medium-High | $490/yr | Role paths + free CPTS voucher |
| PortSwigger Academy | Free | High (web domain) | $0 | OWASP Top 10, web attacks |
| PentesterLab PRO | Free tier + paid | High (web) | $199.99/yr | Code review, CVE exploitation |
| VulnHub | Free | High (offline labs) | $0 | Offline unlimited practice |
| PicoCTF / CyLab | Free | Medium (beginner) | $0 | Absolute beginners, schools |
| CyberDefenders / LetsDefend | Freemium | Medium (IR) | $0-$ | Blue team / SOC analysts |
| CloudRange / RangeForce | Enterprise | Low (blue team) | Custom | Corporate SOC teams |
Key takeaway: Buy one annual subscription. For CEH the best ROI is THM Premium annual ($126/yr) or HTB VIP+ ($240/yr). Everything else (PortSwigger, VulnHub, PicoCTF) is free and can be done in parallel.
7.3 Tool ecosystem
Section titled “7.3 Tool ecosystem”The CEH v13 syllabus is tool-heavy. The official reference OS is Kali Linux; the practical exam is graded on Parrot Security console access plus a Windows desktop.
Kali Linux 2026.x (canonical CEH attack OS)
Section titled “Kali Linux 2026.x (canonical CEH attack OS)”Kali 2026.2 ships GNOME 50 / KDE Plasma 6.6, kernel 6.19, and adds ~9 tools per release (recent: AdaptixC2, GEF, Fluxion, MetasploitMCP, SSTImap, WPProbe, XSStrike, arsenal-ng, legba, hydra-gtk, oletools, penelope, shell-gpt, tailscale). 600+ pre-installed tools; rolling release; quarterly snapshots. Source: https://www.kali.org/blog/kali-linux-2026-2-release/
Parrot OS (Security Edition)
Section titled “Parrot OS (Security Edition)”- Debian 13 (Trixie) based; 800+ tools; KDE Plasma 6 default
- Lighter than Kali (4 GB RAM min), ships Tor/Anonsurf + AI-security tools
- Parrot is the OS candidates see in the CEH Practical range
- Source: https://anonhaven.com/en/best-linux-distros-for-ethical-hacking-which-one-should-you-choose/
BlackArch
Section titled “BlackArch”- Arch-based rolling release; 2,800+ tools
- Terminal-only install, ~330 MB RAM idle
- Best for: Arch-comfortable power users. Not for CEH beginners.
Kali tool categories (CEH-aligned)
Section titled “Kali tool categories (CEH-aligned)”| Category | Tools | CEH Domain |
|---|---|---|
| Recon / OSINT | Maltego, theHarvester, recon-ng, spiderfoot | Footprinting & Reconnaissance |
| Scanning | Nmap, Masscan, RustScan, Netdiscover | Scanning Networks |
| Enumeration | enum4linux(-ng), smbclient, rpcclient, dnsenum, snmpwalk | Enumeration |
| Web app | Burp Suite, OWASP ZAP, Nikto, sqlmap, wfuzz, gobuster, wpscan | Web app hacking |
| Exploitation | Metasploit Framework, searchsploit, exploit-db, RouterSploit | System hacking |
| Wireless | Aircrack-ng, Wifite, Fluxion, Wifipumpkin3, EvilTwin | Wireless hacking |
| Passwords | John the Ripper, hashcat, Hydra, hydra-gtk, legba | Cryptography / password attacks |
| Sniffing | Wireshark, tcpdump, Bettercap, Ettercap | Sniffing & MITM |
| Reverse engineering | Ghidra, radare2, GEF, oletools | Malware analysis |
| Forensics | Volatility, Autopsy, binwalk, foremost | Forensics / IR |
| Reporting | Dradis, Faraday, CherryTree, Joplin | Reporting |
Windows attack tools (AD / Windows domains)
Section titled “Windows attack tools (AD / Windows domains)”- Mimikatz - LSASS dump, pass-the-hash, DCSync, Kerberos ticket extraction. https://github.com/gentilkiwi/mimikatz
- BloodHound CE - graph-based attack-path mapping for AD/Azure. https://github.com/SpecterOps/BloodHound
- PowerView / SharpHound - AD situational awareness
- Responder - LLMNR/NBT-NS/MDNS poisoner with rogue auth servers. https://github.com/lgandx/Responder
- Impacket (python) - psexec/wmiexec/smbexec/secretsdump
- Rubeus - Kerberos abuse (Kerberoasting, AS-REP, S4U)
- NetExec (nxc) / CrackMapExec - SMB/WMI spray & lateral movement
- Cain & Abel - legacy recovery tool; historically in CEH, largely superseded
Cloud security tools
Section titled “Cloud security tools”- ScoutSuite (NCC Group) - multi-cloud posture audit for AWS/Azure/GCP/OCI/Alibaba. https://github.com/nccgroup/ScoutSuite
- Prowler - AWS-focused CIS benchmark scanner
- Pacu (Rhino Security Labs) - open-source AWS exploitation framework. https://github.com/RhinoSecurityLabs/pacu
- CloudGoat / Damn Vulnerable Cloud - intentionally vulnerable AWS environments
Mobile security tools
Section titled “Mobile security tools”- MobSF - automated static + dynamic analysis of Android/iOS/Windows apps. https://github.com/MobSF/Mobile-Security-Framework-MobSF
- Frida + objection - dynamic instrumentation, runtime exploration. https://github.com/sensepost/objection
- APKTool, jadx - Android reverse engineering
Container / Kubernetes tools
Section titled “Container / Kubernetes tools”- Trivy - comprehensive scanner for containers, K8s, IaC, secrets, SBOM. https://github.com/aquasecurity/trivy
- kube-bench - CIS Kubernetes Benchmark compliance checker. https://github.com/aquasecurity/kube-bench
- kube-hunter - pentest-style weakness scanner. https://github.com/aquasecurity/kube-hunter
Key takeaway: For CEH, master the core Kali toolkit (Nmap, Burp, Metasploit, Wireshark, Hydra, John, Aircrack) and the AD toolchain (Mimikatz, BloodHound, Impacket, Responder). Cloud/mobile/container tools are bonus depth for CEH Practical and adjacent certs.
7.4 Recommended free study plan (10 weeks, 8-10 hours/week)
Section titled “7.4 Recommended free study plan (10 weeks, 8-10 hours/week)”This plan assumes you have basic networking, basic Linux, and a small amount of Python. If you don’t, do Pre-Security and the Linux Fundamentals path on TryHackMe free first (add 1 week).
Prerequisite check
Section titled “Prerequisite check”Before starting, confirm you can:
- Explain TCP three-way handshake, subnetting, ARP, DNS
- Use the Linux command line (
ls,cd,grep,find,chmod,cat,ps,kill) - Read and modify a small Python script
- Install VirtualBox/VMware and import a
.ovafile
If any of these are shaky, add 1-2 weeks of THM’s free Pre-Security + Linux Fundamentals paths.
Week-by-week plan (THM Premium annual + PortSwigger + VulnHub + free)
Section titled “Week-by-week plan (THM Premium annual + PortSwigger + VulnHub + free)”- Week 1 - Networking & recon (8h). THM: Pre-Security / Intro to Networking (free);
OhSINT,Shodan.io,Google Dorkingrooms. Build your VirtualBox lab (Kali + Metasploitable 2, host-only). - Week 2 - Scanning & enumeration (9h). THM:
Nmap,Nmap Live Host Discovery,Protocols and Servers;SMB Enumeration,SMTP,DNS in Detail. Practicenmap -sV -sC -p- <target>against Metasploitable 2. - Week 3 - Web app hacking core (10h). PortSwigger: SQLi (8 labs), XSS (10 labs). Install Burp Suite Community; route through
127.0.0.1:8080. THM:OWASP Top 10room. - Week 4 - Web app hacking deeper (9h). PortSwigger: Access control (5), Path traversal (4), Authentication (5). THM:
Juice Shop,Vulnversity. Post one walkthrough to a blog/GitHub. - Week 5 - System hacking & exploitation (10h). THM:
Metasploit: Intro/Exploitation,Blue(EternalBlue),Windows PrivEsc,Linux PrivEsc. VulnHub: rootKioptrix Level 1andMr. Robot. - Week 6 - AD, password attacks, sniffing (10h). THM:
Attacktive Directory,Post-Exploitation Basics,Hydra,John the Ripper,Crack the Hash. Wireshark:Packet OperationsandTraffic Analysis. - Week 7 - Wireless, malware, social engineering (8h). THM:
Wireless Exploitation,Wifi Hacking 101(theory only - never attack real APs),Intro to Malware Analysis,REMnux,Phishing. - Week 8 - Cloud + mobile + container (8h). THM:
AWS Fundamentals,Cloud Security. PortSwigger: Web LLM attacks (7 labs) - the new CEH v13 area. Install MobSF locally and scan a sample APK. - Week 9 - Cryptography, forensics, IR (8h). THM:
Cryptographyrooms,Intro to Digital Forensics. CyberDefenders: any “Easy” challenge. - Week 10 - Mock exam + review (10h). THM:
Jr Pentesterpath final review rooms. 100-question EC-Council official practice exam. Re-do failed PortSwigger labs.
Total: ~90 hours. With 12 weeks instead of 10, stretch Weeks 5-6 and add a dedicated HTB VIP week for retired boxes.
Key takeaway: This plan costs $0-$126 total (free if you skip THM Premium) and covers the CEH v13 exam weights. One hour every weekday plus 4 hours on weekend days finishes in 10 weeks with real hands-on skill, not just memorized answers.
7.5 Lab setup
Section titled “7.5 Lab setup”Hypervisor choice
Section titled “Hypervisor choice”- VirtualBox (free): best for beginners; most prebuilt VulnHub images target it. Recommended for the first 6 months.
- VMware Workstation Pro (now free for personal use in 2026): smoother Windows guests, more stable snapshots. Recommended once you outgrow VirtualBox.
- Hyper-V: built into Windows Pro/Enterprise; harder to mix with VirtualBox, networking quirks.
- WSL2 + VMware/Kali VM hybrid: best of both worlds for Windows users. Cap WSL2 memory (
%UserProfile%\.wslconfigwithmemory=4GB) to avoid RAM cannibalism. Source: https://kioptrix.com/wsl2-kali-vmware-hybrid-setup/ - Proxmox VE (free, bare-metal): for a dedicated homelab box; web UI, clustering, snapshots, ZFS.
Recommended hardware
Section titled “Recommended hardware”- Minimum: dual-core CPU with VT-x/AMD-V, 16 GB RAM, 100 GB free disk (SSD strongly preferred)
- Recommended: quad-core+, 32 GB RAM, 500 GB NVMe SSD
- Bare-metal server: Intel NUC or used mini-PC with 32 GB RAM, 1 TB NVMe (~$200-$400 used) when you outgrow the laptop
- Source: https://breachfolio.com/lab/build-a-home-lab-on-one-laptop/
Minimal viable lab (4 VMs, host-only network)
Section titled “Minimal viable lab (4 VMs, host-only network)”- Kali Linux (attacker) - 4 GB RAM, 50 GB disk
- Metasploitable 2 (Linux target) - 512 MB RAM, 8 GB disk
- DVWA / OWASP Juice Shop (web target) - 1 GB RAM, 10 GB disk
- Windows 10/11 evaluation VM (endpoint target) - 4 GB RAM, 40 GB disk
Total ~10 GB RAM, 110 GB disk. Add more targets as RAM allows.
Network isolation
Section titled “Network isolation”- Always use Host-Only network adapter for vulnerable targets - never bridge to your home LAN
- Kali typically needs two adapters: NAT (for outbound internet -
apt update, exploit-db pulls) + Host-Only (for talking to targets) - Verify isolation: from a target VM,
ping 8.8.8.8must fail
Apple Silicon note
Section titled “Apple Silicon note”M-series Macs cannot run most classic x86 VulnHub images. Use UTM with ARM64 Kali/Parrot and OWASP Juice Shop as your target. Or buy a $200-$400 used x86 mini-PC and SSH into it.
Key takeaway: Don’t over-engineer the lab. One laptop with 16 GB RAM, VirtualBox, Kali, and Metasploitable 2 on a host-only network covers 90% of CEH practice. Scale up only when you start running multi-host AD forests.
Sources
Section titled “Sources”- EC-Council iLab Store: https://ilabs.eccouncil.org/store/
- EC-Council Labs CEH: https://store.eccouncil.org/product/labs-ceh/
- CEH Engage: https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh-engage/
- CodeRed offer: https://nextgen.eccouncil.org/the-ultimate-red-team-cyber-suite-exclusive-offer/
- EC-Council pricing: https://pricingsaas.com/companies/eccouncil
- TryHackMe pricing: https://tryhackme.com/pricing
- TryHackMe ROI 2026: https://tryhackme.com/resources/blog/cyber-security-training-subscriptions-compared-cost-features-roi-2026
- HackTheBox vs TryHackMe: https://certcompass.org/tryhackme-vs-hackthebox/
- TJ Null OSCP list: https://0xdf.gitlab.io/cheatsheets/offsec
- PortSwigger Web Security Academy: https://portswigger.net/web-security
- PentesterLab PRO: https://pentesterlab.com/pro
- VulnHub OSCP practice: https://secverse.net/cybersecurity-resources/cybersecurity-virtual-labs/vulnhub-oscp-practice/
- picoCTF 2026: https://www.cylab.cmu.edu/news/2026/02/26-picoctf.html
- CyberDefenders: https://cyberdefenders.org/
- Cloud Range: https://www.cloudrangecyber.com/blue-team-programs
- LetsDefend: https://letsdefend.io/
- Kali Linux 2026.2: https://www.kali.org/blog/kali-linux-2026-2-release/
- Pentest distros 2026: https://anonhaven.com/en/best-linux-distros-for-ethical-hacking-which-one-should-you-choose/
- Mimikatz: https://github.com/gentilkiwi/mimikatz
- BloodHound CE: https://github.com/SpecterOps/BloodHound
- Responder: https://github.com/lgandx/Responder
- ScoutSuite: https://github.com/nccgroup/ScoutSuite
- Pacu (AWS): https://github.com/RhinoSecurityLabs/pacu
- MobSF: https://github.com/MobSF/Mobile-Security-Framework-MobSF
- objection: https://github.com/sensepost/objection
- Trivy: https://github.com/aquasecurity/trivy
- kube-bench: https://github.com/aquasecurity/kube-bench
- kube-hunter: https://github.com/aquasecurity/kube-hunter
- Home lab on one laptop: https://breachfolio.com/lab/build-a-home-lab-on-one-laptop/
- CEH v13 home lab: https://www.ituonline.com/blogs/best-practices-for-setting-up-a-home-lab-to-practice-ceh-v13-skills-safely/
- WSL2 + Kali hybrid: https://kioptrix.com/wsl2-kali-vmware-hybrid-setup/