<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Posts on Corey Farley</title>
    <link>https://coreyfarley.com/posts/</link>
    <description>Recent content in Posts on Corey Farley</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://coreyfarley.com/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Extplorer | OffSec</title>
      <link>https://coreyfarley.com/posts/extplorer-offsec/</link>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/extplorer-offsec/</guid>
      <description>A Linux box built around eXtplorer, a PHP file manager. Default creds get a webshell, leaked credentials pivot to a local user, and disk group membership leads straight to root.</description>
    </item>
    <item>
      <title>Remote | HackTheBox</title>
      <link>https://coreyfarley.com/posts/remote-htb/</link>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/remote-htb/</guid>
      <description>An easy Windows box running Umbraco CMS. Creds leak from a world-readable NFS share, an authenticated Umbraco exploit gets a foothold, and a Print Spooler abuse gets SYSTEM.</description>
    </item>
    <item>
      <title>GroundWorm | HackTheBox</title>
      <link>https://coreyfarley.com/posts/groundworm-htb/</link>
      <pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/groundworm-htb/</guid>
      <description>A walkthrough of GroundWorm, a hard-rated DFIR Sherlock on HackTheBox, tracing a simulated APT attack from initial access through ransomware deployment using Splunk and API Monitor.</description>
    </item>
    <item>
      <title>Infostealer Analysis</title>
      <link>https://coreyfarley.com/posts/infostealer-analysis/</link>
      <pubDate>Thu, 21 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/infostealer-analysis/</guid>
      <description>An investigation into a simple infostealer, following the retired TeleStealer Lab from CyberDefenders, covering static and dynamic malware analysis.</description>
    </item>
    <item>
      <title>Intro to Malware Analysis</title>
      <link>https://coreyfarley.com/posts/intro-to-malware-analysis/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/intro-to-malware-analysis/</guid>
      <description>A high-level overview of the steps taken in the MalaCrypt lab from CyberDefenders, covering static and dynamic malware analysis.</description>
    </item>
    <item>
      <title>Linux Privilege Escalation | TryHackMe</title>
      <link>https://coreyfarley.com/posts/linux-privilege-escalation/</link>
      <pubDate>Tue, 20 May 2025 00:00:00 +0000</pubDate>
      <guid>https://coreyfarley.com/posts/linux-privilege-escalation/</guid>
      <description>A walk-through of the Linux Privilege Escalation room in the Jr Penetration Tester pathway on TryHackMe, covering eight core privilege escalation techniques.</description>
    </item>
  </channel>
</rss>
