Ravindra BagaleCourses & study guides

18. Ethics, the Law and a Safe Kali Lab

18.6 The Pre-Engagement Checklist

Pratyek lab session aadhi ha checklist manatun ghya. Ha tumhala kaydyachya aani technical donhi chuka pasun vachavto.

Before you touch any tool Done?
Target is my own VM / app, inside my host-only range (e.g. 192.168.56.0/24) ☐
Vulnerable VMs have no bridged/NAT adapter (host-only only) ☐
I have a written scope note listing the exact in-scope targets ☐
Clean snapshots taken so I can roll back ☐
Terminal logging on (script) or notes open ☐
I will record every command and its result ☐
I will pair every attack I try with the defence that stops it ☐
Nothing outside the lab range will be touched, ever ☐

This checklist is the habit that separates a professional from someone who gets into trouble. In a paid job you replace "my own VM" with "the signed scope document", but the discipline is identical.

Why this matters for security

A checklist turns good intentions into a repeatable process. Real engagements begin with exactly this kind of pre-flight: confirm scope, confirm you can restore, confirm you are logging. It protects the client's systems and protects you legally.

Ravindra Bagale's Tip

Forgetting to take a snapshot is a common student mistake – an exploit breaks Metasploitable and you have to start again from scratch. With a clean snapshot, you're back in one click! And if you keep a session log, all your commands are ready when you write the report. Build these two habits.

Lab

Fill in the checklist above for your lab, take a fresh snapshot of Kali and Metasploitable 2, start script logging, and confirm from Kali that you can reach 192.168.56.20 but not the internet.