<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Corey Farley</title>
    <link>https://coreyfarley.com/</link>
    <description>Recent content on Corey Farley</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://coreyfarley.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Extplorer | OffSec</title>
      <link>https://coreyfarley.com/posts/extplorer-offsec/</link>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/extplorer-offsec/</guid>
      <description>A Linux box built around eXtplorer, a PHP file manager. Default creds get a webshell, leaked credentials pivot to a local user, and disk group membership leads straight to root.</description>
    </item>
    <item>
      <title>Remote | HackTheBox</title>
      <link>https://coreyfarley.com/posts/remote-htb/</link>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/remote-htb/</guid>
      <description>An easy Windows box running Umbraco CMS. Creds leak from a world-readable NFS share, an authenticated Umbraco exploit gets a foothold, and a Print Spooler abuse gets SYSTEM.</description>
    </item>
    <item>
      <title>Pentest Report | BHIS Interview</title>
      <link>https://coreyfarley.com/projects/pentest-report/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/projects/pentest-report/</guid>
      <description>Mock pentest report that I had as apart of a recent technical interview.</description>
    </item>
    <item>
      <title>nxc-sweep | NetExec Automation</title>
      <link>https://coreyfarley.com/projects/nxc-sweep/</link>
      <pubDate>Sun, 10 May 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/projects/nxc-sweep/</guid>
      <description>A Bash wrapper for NetExec to quickly validate compromised credentials across SMB, WinRM, RDP, MSSQL, and FTP.</description>
    </item>
    <item>
      <title>CVE-2026-27897: Path Traversal &amp; Arbitrary File Write in Vociferous</title>
      <link>https://coreyfarley.com/projects/cve-2026-27897/</link>
      <pubDate>Wed, 11 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/projects/cve-2026-27897/</guid>
      <description>A technical breakdown of CVE-2026-27897, a high-severity path traversal and arbitrary file write vulnerability I discovered during a security audit of the Vociferous application.</description>
    </item>
    <item>
      <title>GroundWorm | HackTheBox</title>
      <link>https://coreyfarley.com/posts/groundworm-htb/</link>
      <pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/groundworm-htb/</guid>
      <description>A walkthrough of GroundWorm, a hard-rated DFIR Sherlock on HackTheBox, tracing a simulated APT attack from initial access through ransomware deployment using Splunk and API Monitor.</description>
    </item>
    <item>
      <title>Creating a Keylogger in Python</title>
      <link>https://coreyfarley.com/projects/python-keylogger/</link>
      <pubDate>Sun, 21 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/projects/python-keylogger/</guid>
      <description>Building and obfuscating a covert Python keylogger, from writing the core logic to packaging it as an executable and running test deployments.</description>
    </item>
    <item>
      <title>Infostealer Analysis</title>
      <link>https://coreyfarley.com/posts/infostealer-analysis/</link>
      <pubDate>Thu, 21 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/infostealer-analysis/</guid>
      <description>An investigation into a simple infostealer, following the retired TeleStealer Lab from CyberDefenders, covering static and dynamic malware analysis.</description>
    </item>
    <item>
      <title>Intro to Malware Analysis</title>
      <link>https://coreyfarley.com/posts/intro-to-malware-analysis/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/intro-to-malware-analysis/</guid>
      <description>A high-level overview of the steps taken in the MalaCrypt lab from CyberDefenders, covering static and dynamic malware analysis.</description>
    </item>
    <item>
      <title>Linux Privilege Escalation | TryHackMe</title>
      <link>https://coreyfarley.com/posts/linux-privilege-escalation/</link>
      <pubDate>Tue, 20 May 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/linux-privilege-escalation/</guid>
      <description>A walk-through of the Linux Privilege Escalation room in the Jr Penetration Tester pathway on TryHackMe, covering eight core privilege escalation techniques.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://coreyfarley.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/about/</guid>
      <description></description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://coreyfarley.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/contact/</guid>
      <description></description>
    </item>
  </channel>
</rss>
