Use the Kioptrix Level 1 download mirror below for Kioptrix_Level_1.rar, the original Level 1 (#1) training VM. If an old archive link brought you here, this is the file to check.
Download Kioptrix Level 1 — VulnHub Mirror
View the VulnHub release page and file details
The download is hosted externally by VulnHub. If the direct link does not respond, open the release page and check its available download options.
For a different release, use the Kioptrix downloads index.
On this page
Check That You Have the Right File
- Challenge: Kioptrix: Level 1 (#1).
- Archive:
Kioptrix_Level_1.rar; VulnHub lists 186 MB. - Format: prebuilt VMware virtual machine, Linux guest; not an installer ISO.
- Addressing: DHCP enabled, automatically assigned IP.
These details come from the VulnHub Level 1 listing. Compare the filename and published checksum on that listing with your completed download. A matching checksum checks file identity; it does not make an intentionally vulnerable VM safe.
Looking for KVM3.rar instead? That is a different challenge: Kioptrix Level 1.2 (#3), often called Level 3.
Before You Start
Kioptrix is an intentionally vulnerable practice machine. Run it only in a lab you control, separated from your everyday devices and public networks.
Apple Silicon or another ARM host? Do not assume an older VMware image will run because your ARM Kali VM works. Broadcom’s Fusion compatibility guidance says Fusion on Apple Silicon runs ARM64 guests, not x86 operating systems. An older x86 guest needs a compatible x86 host or a separately supported emulation path. Renaming the archive or adding RAM does not convert its architecture.
Before downloading a large file, check your host CPU, hypervisor version and guest support. This page does not claim a tested Apple Silicon configuration. Prepare:
- A virtualization application compatible with the supplied VMware files.
- An archive utility that can extract
.rarfiles. - A separate testing VM, such as Kali Linux.
- An isolated virtual network for the two machines.
Avoid bridged networking: it puts the vulnerable guest on the physical network. In VirtualBox, Internal Network connects selected VMs; host-only also exposes the host to those VMs. NAT and NAT Network can permit outbound access, so neither means an offline lab. See Oracle’s network-mode comparison. Check every adapter, keep the target off outward-facing adapters, and do not enable port forwarding or Internet sharing.
Read VulnHub’s guidance on protecting yourself and your network before powering on an unfamiliar VM.
Set Up Your Lab
1. Download and Extract the Archive
Download Kioptrix_Level_1.rar, then extract its contents into a dedicated folder. Keep the extracted files together so the VM configuration can locate its virtual disks.
If extraction fails, check whether the download completed before changing any VM settings.
2. Open the Virtual Machine
Use your virtualization application’s option to open an existing virtual machine. With compatible VMware software, select the extracted .vmx configuration file.
Using VirtualBox or unsure which file to open? Follow the VMX, VMDK and appliance import checklist. The supplied VMware archive is not automatically an OVA; do not rename files to force an import.
3. Configure Networking Before Booting
Connect Kioptrix and your testing VM to the same isolated virtual network. Check that neither machine has an extra adapter unintentionally connecting the lab to another network.
Kioptrix’s release listing specifies DHCP. Your isolated network therefore needs a suitable DHCP service if you expect the machine to receive an address automatically.
4. Start the Machines and Check Connectivity
Record the target adapter’s MAC address in the VM settings, then boot both VMs. Confirm Kali’s lab interface and match the target MAC to its current DHCP lease or authorized lab discovery result. A login prompt alone does not identify the target IP.
Do not copy a walkthrough’s IP address. For the complete readiness check, use the beginner lab setup checklist. Stop if you cannot distinguish the target from the host or DHCP service.
5. Save a Clean Starting Point
If your virtualization software supports snapshots, take one before beginning the challenge. Otherwise, keep an untouched copy of the extracted VM so you can start again without downloading it repeatedly.
Having Trouble?
- Download or extraction fails: check completion and RAR support, then compare the release details and mirror.
- Missing disk, import error or no bootable medium: keep all extracted files together and record the exact error. Use the boot and disk troubleshooting guide before changing controllers. For an architecture error, return to the compatibility check above.
- No target IP: verify power, connected virtual cable, the exact lab-network name and DHCP service. Follow the no-address troubleshooting checks; do not widen the scan range.
- Kali cannot find the target or ping fails: check both VMs’ network membership, MAC/IP mapping and routes. The Kali lab-network checks cover the interface and target boundary. A failed ping alone does not prove the VM is down.
Avoid switching to bridged networking just to make discovery work. Resolve the lab’s adapter and addressing settings while keeping it isolated.
First Practice After Setup
Continue only when you have recorded the image source, lab-network name, target MAC/current IP and a clean recovery point. Test only the training VM you own or are explicitly authorized to assess; the host and other discovered devices remain outside scope.
First goal: identify that one target and save an initial service inventory. Open Step 1: scoping and basic reconnaissance, then record what you observe and one question to investigate. Later sections contain solution hints, so stop before them if you want to work independently.
If the command options are unfamiliar, read the Kali discovery and Nmap reference first. You do not need to run every tool to complete a useful first session.
Frequently Asked Questions
Why did an old download link bring me here?
Older tutorials and resource lists may point directly to /dlvm/Kioptrix_Level_1.rar. This page provides a route to the externally hosted download, along with setup guidance and related learning resources.
Is the download hosted on this website?
No. The download button links to the mirror listed by VulnHub. Its availability depends on the external host.
Does this page include the solution?
No. This page covers downloading the VM and preparing your lab. Full walkthroughs are linked separately so you can choose when to consult them.
Can I use this as a normal Linux computer?
It is intended as a vulnerable training target. Keep personal files, passwords, and everyday browsing out of the VM, and use it only within your isolated practice environment.
Ready to begin? Get the Level 1 archive from the VulnHub mirror, then return here for the setup steps.
Source check: October 8, 2026 (UTC). Download details and compatibility guidance were checked against the linked documentation; the archive was not downloaded or boot-tested for this update.