Skip to content

CEH Tools, Labs & Practical Training

The CEH exam is multiple choice, but the practical CEH credential and real-world employer expectations require hands-on skill. This document maps the practical training ecosystem around the CEH v13 curriculum: EC-Council’s own labs, third-party platforms, the toolset, an 8-12 week free study plan, and a single-laptop home lab.

Key takeaway: Spend 60% of prep time at the keyboard. The cheapest path to passing CEH and CEH Practical is TryHackMe Premium (~$10.50/mo annual) + PortSwigger Web Security Academy (free) + a self-hosted Kali/Metasploitable lab on VirtualBox.


7.1 EC-Council’s official iLab, iRange, CEH Engage & CodeRed

Section titled “7.1 EC-Council’s official iLab, iRange, CEH Engage & CodeRed”

EC-Council operates its own cloud-based practice infrastructure. Four distinct products exist.

iLab is EC-Council’s cloud-hosted range of vulnerable VMs and guided exercises, accessed via browser (RDP/SSH into preconfigured victims). The library covers Ethical Hacking (107+ exercises), Penetration Testing (15), Computer Forensics (34), Secure Programming (68), and Disaster Recovery. 2026 price: $199 per 6-month subscription; a free 7-day trial of one System Hacking module is available. Source: https://ilabs.eccouncil.org/store/

The older term for EC-Council’s red-team cyber range that iLab now sits inside. Bundled with higher-tier CEH training packages; not sold standalone. Unguided practice against multi-host networks.

The v13 addition. A four-phase, flag-capturing engagement against a simulated company “ABCD” with persistent vulnerable targets. Each phase is 4 hours (16 hours total). Candidates get only a Parrot Security console and one Windows desktop - no walkthrough, no objectives. Reserved for CEH v13 Elite package holders; not sold standalone. Source: https://www.eccouncil.org/train-certify/certified-ethical-hacker-ceh-engage/

EC-Council’s general-purpose video/course subscription. Marketed via limited-time bundles (e.g. “Ultimate Red Team Cyber Suite” - promo $49.99 from $399 for 15 courses + 3 bonus courses, 1 year access). Individual courses $11.99. Not required for CEH. Source: https://nextgen.eccouncil.org/the-ultimate-red-team-cyber-suite-exclusive-offer/

Key takeaway: For CEH itself, you do not need iLab or CodeRed. The exam is voucher + self-study + free platforms. Buy iLab only if you want the guided EC-Council experience and have $199 on top of your exam voucher. CEH main package: ~$1,699 on-demand, ~$2,499 live, ~$3,999 unlimited (source: https://pricingsaas.com/companies/eccouncil).


7.2 Alternative hands-on platforms (free + paid)

Section titled “7.2 Alternative hands-on platforms (free + paid)”

These cover the same CEH domains (recon, scanning, enumeration, exploitation, web, wireless, cloud) with comparable realism to iLab, often for less money.

  • Free tier: hundreds of beginner rooms, 1-hour/day AttackBox, free OpenVPN
  • Premium: $16.99/mo or $10.50/mo annual ($126/yr) - unlocks 1,000+ rooms, all learning paths, unlimited AttackBox, 15% off THM certs
  • MAX (June 2026): $18.99/mo annual - adds advanced paths, persistent AttackBox, AWS/Azure 101 cloud paths, 40% cert discount
  • “Jr Pentester” and “Cyber Security 101” map almost 1:1 to CEH v13 domain weights
  • Source: https://tryhackme.com/pricing
  • VIP: $14/mo - all retired machines, personal OpenVPN
  • VIP+: $20/mo - adds Pro Labs (Dante, Zephyr, Offshore) and dedicated lab access
  • HTB Academy: Silver $223/yr, Gold Annual $490/yr (Gold includes a free CPTS voucher)
  • TJ Null’s OSCP-like HTB list is the de-facto CEH/OSCP box checklist (Lame, Active, Forest, Sauna, etc.)
  • CPTS ($210) is widely considered OSCP-comparable at one-eighth the price
  • Source: https://certcompass.org/tryhackme-vs-hackthebox/
  • Cost: 100% free. 250+ browser-based labs (SQLi, XSS, SSRF, HTTP request smuggling, OAuth, JWT, prototype pollution), solvable with Burp Suite Community Edition
  • Best for: OWASP Top 10, CEH’s “Web Application Hacking” domain, modern web attack surfaces
  • Burp Suite Certified Practitioner (BSCP): $99 - practical web pentest cert that complements CEH
  • Source: https://portswigger.net/web-security
  • 700+ hands-on web exploitation exercises + video walkthroughs
  • $19.99/mo or $199.99/yr (Student: $34.99/3-mo)
  • Best for: code-review and CVE-driven exploitation practice
  • Source: https://pentesterlab.com/pro
  • Free gamified CTF by Carnegie Mellon; ages 13+
  • 2026 competition ran March 9-19; platform stays open year-round in the picoGym
  • Categories: crypto, web, forensics, reverse engineering, binary exploitation
  • Source: https://picoctf.org/
  • Free blue-team CTF challenges, paid “CCD” credential path
  • Best for: SOC/IR practice that complements CEH’s “Incident Response” domain
  • Source: https://cyberdefenders.org/

RangeForce, CloudRange, LetsDefend (enterprise blue-team)

Section titled “RangeForce, CloudRange, LetsDefend (enterprise blue-team)”
Platform Free/Paid (2026) CEH relevance Cost Best for
EC-Council iLab Paid Exact (v13 syllabus) $199 / 6 mo Guided EC-Council experience
CEH Engage Bundle-only (Elite) Exact incl. w/ Elite pkg 4-phase flag capture exam-style
TryHackMe Premium Freemium High (Jr Pentester path) $10.50/mo annual Beginners, structured paths
HackTheBox VIP+ Freemium High (TJ Null list) $20/mo OSCP-style retired machines
HTB Academy Gold Paid Medium-High $490/yr Role paths + free CPTS voucher
PortSwigger Academy Free High (web domain) $0 OWASP Top 10, web attacks
PentesterLab PRO Free tier + paid High (web) $199.99/yr Code review, CVE exploitation
VulnHub Free High (offline labs) $0 Offline unlimited practice
PicoCTF / CyLab Free Medium (beginner) $0 Absolute beginners, schools
CyberDefenders / LetsDefend Freemium Medium (IR) $0-$ Blue team / SOC analysts
CloudRange / RangeForce Enterprise Low (blue team) Custom Corporate SOC teams

Key takeaway: Buy one annual subscription. For CEH the best ROI is THM Premium annual ($126/yr) or HTB VIP+ ($240/yr). Everything else (PortSwigger, VulnHub, PicoCTF) is free and can be done in parallel.


The CEH v13 syllabus is tool-heavy. The official reference OS is Kali Linux; the practical exam is graded on Parrot Security console access plus a Windows desktop.

Kali Linux 2026.x (canonical CEH attack OS)

Section titled “Kali Linux 2026.x (canonical CEH attack OS)”

Kali 2026.2 ships GNOME 50 / KDE Plasma 6.6, kernel 6.19, and adds ~9 tools per release (recent: AdaptixC2, GEF, Fluxion, MetasploitMCP, SSTImap, WPProbe, XSStrike, arsenal-ng, legba, hydra-gtk, oletools, penelope, shell-gpt, tailscale). 600+ pre-installed tools; rolling release; quarterly snapshots. Source: https://www.kali.org/blog/kali-linux-2026-2-release/

  • Arch-based rolling release; 2,800+ tools
  • Terminal-only install, ~330 MB RAM idle
  • Best for: Arch-comfortable power users. Not for CEH beginners.
Category Tools CEH Domain
Recon / OSINT Maltego, theHarvester, recon-ng, spiderfoot Footprinting & Reconnaissance
Scanning Nmap, Masscan, RustScan, Netdiscover Scanning Networks
Enumeration enum4linux(-ng), smbclient, rpcclient, dnsenum, snmpwalk Enumeration
Web app Burp Suite, OWASP ZAP, Nikto, sqlmap, wfuzz, gobuster, wpscan Web app hacking
Exploitation Metasploit Framework, searchsploit, exploit-db, RouterSploit System hacking
Wireless Aircrack-ng, Wifite, Fluxion, Wifipumpkin3, EvilTwin Wireless hacking
Passwords John the Ripper, hashcat, Hydra, hydra-gtk, legba Cryptography / password attacks
Sniffing Wireshark, tcpdump, Bettercap, Ettercap Sniffing & MITM
Reverse engineering Ghidra, radare2, GEF, oletools Malware analysis
Forensics Volatility, Autopsy, binwalk, foremost Forensics / IR
Reporting Dradis, Faraday, CherryTree, Joplin Reporting

Windows attack tools (AD / Windows domains)

Section titled “Windows attack tools (AD / Windows domains)”
  • Mimikatz - LSASS dump, pass-the-hash, DCSync, Kerberos ticket extraction. https://github.com/gentilkiwi/mimikatz
  • BloodHound CE - graph-based attack-path mapping for AD/Azure. https://github.com/SpecterOps/BloodHound
  • PowerView / SharpHound - AD situational awareness
  • Responder - LLMNR/NBT-NS/MDNS poisoner with rogue auth servers. https://github.com/lgandx/Responder
  • Impacket (python) - psexec/wmiexec/smbexec/secretsdump
  • Rubeus - Kerberos abuse (Kerberoasting, AS-REP, S4U)
  • NetExec (nxc) / CrackMapExec - SMB/WMI spray & lateral movement
  • Cain & Abel - legacy recovery tool; historically in CEH, largely superseded

Key takeaway: For CEH, master the core Kali toolkit (Nmap, Burp, Metasploit, Wireshark, Hydra, John, Aircrack) and the AD toolchain (Mimikatz, BloodHound, Impacket, Responder). Cloud/mobile/container tools are bonus depth for CEH Practical and adjacent certs.


Section titled “7.4 Recommended free study plan (10 weeks, 8-10 hours/week)”

This plan assumes you have basic networking, basic Linux, and a small amount of Python. If you don’t, do Pre-Security and the Linux Fundamentals path on TryHackMe free first (add 1 week).

Before starting, confirm you can:

  • Explain TCP three-way handshake, subnetting, ARP, DNS
  • Use the Linux command line (ls, cd, grep, find, chmod, cat, ps, kill)
  • Read and modify a small Python script
  • Install VirtualBox/VMware and import a .ova file

If any of these are shaky, add 1-2 weeks of THM’s free Pre-Security + Linux Fundamentals paths.

Week-by-week plan (THM Premium annual + PortSwigger + VulnHub + free)

Section titled “Week-by-week plan (THM Premium annual + PortSwigger + VulnHub + free)”
  1. Week 1 - Networking & recon (8h). THM: Pre-Security / Intro to Networking (free); OhSINT, Shodan.io, Google Dorking rooms. Build your VirtualBox lab (Kali + Metasploitable 2, host-only).
  2. Week 2 - Scanning & enumeration (9h). THM: Nmap, Nmap Live Host Discovery, Protocols and Servers; SMB Enumeration, SMTP, DNS in Detail. Practice nmap -sV -sC -p- <target> against Metasploitable 2.
  3. Week 3 - Web app hacking core (10h). PortSwigger: SQLi (8 labs), XSS (10 labs). Install Burp Suite Community; route through 127.0.0.1:8080. THM: OWASP Top 10 room.
  4. Week 4 - Web app hacking deeper (9h). PortSwigger: Access control (5), Path traversal (4), Authentication (5). THM: Juice Shop, Vulnversity. Post one walkthrough to a blog/GitHub.
  5. Week 5 - System hacking & exploitation (10h). THM: Metasploit: Intro/Exploitation, Blue (EternalBlue), Windows PrivEsc, Linux PrivEsc. VulnHub: root Kioptrix Level 1 and Mr. Robot.
  6. Week 6 - AD, password attacks, sniffing (10h). THM: Attacktive Directory, Post-Exploitation Basics, Hydra, John the Ripper, Crack the Hash. Wireshark: Packet Operations and Traffic Analysis.
  7. Week 7 - Wireless, malware, social engineering (8h). THM: Wireless Exploitation, Wifi Hacking 101 (theory only - never attack real APs), Intro to Malware Analysis, REMnux, Phishing.
  8. Week 8 - Cloud + mobile + container (8h). THM: AWS Fundamentals, Cloud Security. PortSwigger: Web LLM attacks (7 labs) - the new CEH v13 area. Install MobSF locally and scan a sample APK.
  9. Week 9 - Cryptography, forensics, IR (8h). THM: Cryptography rooms, Intro to Digital Forensics. CyberDefenders: any “Easy” challenge.
  10. Week 10 - Mock exam + review (10h). THM: Jr Pentester path final review rooms. 100-question EC-Council official practice exam. Re-do failed PortSwigger labs.

Total: ~90 hours. With 12 weeks instead of 10, stretch Weeks 5-6 and add a dedicated HTB VIP week for retired boxes.

Key takeaway: This plan costs $0-$126 total (free if you skip THM Premium) and covers the CEH v13 exam weights. One hour every weekday plus 4 hours on weekend days finishes in 10 weeks with real hands-on skill, not just memorized answers.


  • VirtualBox (free): best for beginners; most prebuilt VulnHub images target it. Recommended for the first 6 months.
  • VMware Workstation Pro (now free for personal use in 2026): smoother Windows guests, more stable snapshots. Recommended once you outgrow VirtualBox.
  • Hyper-V: built into Windows Pro/Enterprise; harder to mix with VirtualBox, networking quirks.
  • WSL2 + VMware/Kali VM hybrid: best of both worlds for Windows users. Cap WSL2 memory (%UserProfile%\.wslconfig with memory=4GB) to avoid RAM cannibalism. Source: https://kioptrix.com/wsl2-kali-vmware-hybrid-setup/
  • Proxmox VE (free, bare-metal): for a dedicated homelab box; web UI, clustering, snapshots, ZFS.
  • Minimum: dual-core CPU with VT-x/AMD-V, 16 GB RAM, 100 GB free disk (SSD strongly preferred)
  • Recommended: quad-core+, 32 GB RAM, 500 GB NVMe SSD
  • Bare-metal server: Intel NUC or used mini-PC with 32 GB RAM, 1 TB NVMe (~$200-$400 used) when you outgrow the laptop
  • Source: https://breachfolio.com/lab/build-a-home-lab-on-one-laptop/

Minimal viable lab (4 VMs, host-only network)

Section titled “Minimal viable lab (4 VMs, host-only network)”
  1. Kali Linux (attacker) - 4 GB RAM, 50 GB disk
  2. Metasploitable 2 (Linux target) - 512 MB RAM, 8 GB disk
  3. DVWA / OWASP Juice Shop (web target) - 1 GB RAM, 10 GB disk
  4. Windows 10/11 evaluation VM (endpoint target) - 4 GB RAM, 40 GB disk

Total ~10 GB RAM, 110 GB disk. Add more targets as RAM allows.

  • Always use Host-Only network adapter for vulnerable targets - never bridge to your home LAN
  • Kali typically needs two adapters: NAT (for outbound internet - apt update, exploit-db pulls) + Host-Only (for talking to targets)
  • Verify isolation: from a target VM, ping 8.8.8.8 must fail

M-series Macs cannot run most classic x86 VulnHub images. Use UTM with ARM64 Kali/Parrot and OWASP Juice Shop as your target. Or buy a $200-$400 used x86 mini-PC and SSH into it.

Key takeaway: Don’t over-engineer the lab. One laptop with 16 GB RAM, VirtualBox, Kali, and Metasploitable 2 on a host-only network covers 90% of CEH practice. Scale up only when you start running multi-host AD forests.