Ravindra BagaleCourses & study guides

18. Ethics, the Law and a Safe Kali Lab

18.6 The Pre-Engagement Checklist

Pratyek lab session aadhi ha checklist manatun ghya. Ha tumhala kaydyachya aani technical donhi chuka pasun vachavto.

Before you touch any tool Done?
Target is my own VM / app, inside my host-only range (e.g. 192.168.56.0/24) ☐
Vulnerable VMs have no bridged/NAT adapter (host-only only) ☐
I have a written scope note listing the exact in-scope targets ☐
Clean snapshots taken so I can roll back ☐
Terminal logging on (script) or notes open ☐
I will record every command and its result ☐
I will pair every attack I try with the defence that stops it ☐
Nothing outside the lab range will be touched, ever ☐

This checklist is the habit that separates a professional from someone who gets into trouble. In a paid job you replace "my own VM" with "the signed scope document", but the discipline is identical.

Why this matters for security

A checklist turns good intentions into a repeatable process. Real engagements begin with exactly this kind of pre-flight: confirm scope, confirm you can restore, confirm you are logging. It protects the client's systems and protects you legally.

Ravindra Bagale's Tip

Snapshot ghyayla visarne hi students chi common chuk – exploit ne Metasploitable kharab hote aani punha suruvatis suru karava lagta. Clean snapshot asel tar ek click madhe parat! Aani session log thevla tar report lihitana sagle commands tayar astat. Ya don savayi lavun ghya.

Lab

Fill in the checklist above for your lab, take a fresh snapshot of Kali and Metasploitable 2, start script logging, and confirm from Kali that you can reach 192.168.56.20 but not the internet.