<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
<title>CoreFlareSec Blog</title>
<link>https://blog.coreflaresec.com</link>
<description>Writeups, security notes and things I build.</description>
<item>
<title>[Writeup] Dante Pro Lab — เส้นทางเต็ม 3 segment</title>
<link>https://blog.coreflaresec.com/posts/dante-writeup/</link>
<guid>https://blog.coreflaresec.com/posts/dante-writeup/</guid>
<pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
<description>Writeup ฉบับเต็มของ Dante Pro Lab — เส้นทางจริงตั้งแต่ foothold ยัน domain dominance ครบทั้งสาม segment ล็อกไว้ด้วยรหัสผ่าน</description>
</item>
<item>
<title>[THM] Kaboomm — OT/ICS writeup</title>
<link>https://blog.coreflaresec.com/posts/thm-kaboomm-ot-ics-writeup-en/</link>
<guid>https://blog.coreflaresec.com/posts/thm-kaboomm-ot-ics-writeup-en/</guid>
<pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
<description>Writeup for TryHackMe's Kaboomm — talking to the PLC directly over Modbus, reading the holding register, then switching the cooler off.</description>
</item>
<item>
<title>[THM] — Kaboomm OT/ICS writeup</title>
<link>https://blog.coreflaresec.com/posts/thm-kaboomm-ot-ics-writeup/</link>
<guid>https://blog.coreflaresec.com/posts/thm-kaboomm-ot-ics-writeup/</guid>
<pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
<description>Writeup โจทย์ Kaboomm จาก TryHackMe — คุยกับ PLC ตรง ๆ ผ่าน Modbus อ่าน holding register แล้วสั่งปิด cooler</description>
</item>
<item>
<title>Building my own static site generator</title>
<link>https://blog.coreflaresec.com/posts/hello-world/</link>
<guid>https://blog.coreflaresec.com/posts/hello-world/</guid>
<pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
<description>Why this blog runs on ~200 lines of my own code instead of a framework — and what that buys me in supply-chain security.</description>
</item>
<item>
<title>[THM] Brr — ScadaBR writeup</title>
<link>https://blog.coreflaresec.com/posts/thm-brr-scadabr-writeup-th/</link>
<guid>https://blog.coreflaresec.com/posts/thm-brr-scadabr-writeup-th/</guid>
<pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
<description>Writeup โจทย์ Brr จาก TryHackMe — จาก nmap ไปเจอ ScadaBR บนพอร์ต 8080 แล้วไต่ต่อเข้าระบบ OT/ICS</description>
</item>
<item>
<title>[THM] Brr — ScadaBR writeup</title>
<link>https://blog.coreflaresec.com/posts/thm-brr-scadabr-writeup/</link>
<guid>https://blog.coreflaresec.com/posts/thm-brr-scadabr-writeup/</guid>
<pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
<description>Writeup for TryHackMe's Brr — from an nmap scan to a ScadaBR panel on port 8080, then onward into the OT/ICS network.</description>
</item>
<item>
<title>RastaLabs (HTB) — is it worth it?</title>
<link>https://blog.coreflaresec.com/posts/rastalabs-htb-en/</link>
<guid>https://blog.coreflaresec.com/posts/rastalabs-htb-en/</guid>
<pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
<description>A review of RastaLabs — a full corporate Active Directory environment with GPO abuse, Pass-the-Hash and DCSync. Worth the money? Let's find out.</description>
</item>
<item>
<title>[รีวิว] Rastalabs-HTB คุ้มไหม</title>
<link>https://blog.coreflaresec.com/posts/rastalabs-htb/</link>
<guid>https://blog.coreflaresec.com/posts/rastalabs-htb/</guid>
<pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
<description>รีวิว RastaLabs — Active Directory แบบ corporate เต็มรูปแบบ ทั้ง GPO abuse, Pass-the-Hash และ DCSync คุ้มไหมมาดูกัน</description>
</item>
<item>
<title>Dante Pro Lab (HTB) — review</title>
<link>https://blog.coreflaresec.com/posts/dante-prolab-en/</link>
<guid>https://blog.coreflaresec.com/posts/dante-prolab-en/</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<description>A review of Dante Pro Lab — the multi-segment enterprise network HackTheBox recommends for anyone preparing for OSCP.</description>
</item>
<item>
<title>[รีวิว] DANTE PROLAB-ยี่ฮ๊า</title>
<link>https://blog.coreflaresec.com/posts/dante-prolab/</link>
<guid>https://blog.coreflaresec.com/posts/dante-prolab/</guid>
<pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
<description>รีวิว Dante Pro Lab — enterprise network จำลองหลาย segment ที่ HackTheBox แนะนำสำหรับคนเตรียมสอบ OSCP</description>
</item>
<item>
<title>HTB Zephyr Pro Lab — AD is genuinely scary</title>
<link>https://blog.coreflaresec.com/posts/htb-zephyr-prolab-ad-en/</link>
<guid>https://blog.coreflaresec.com/posts/htb-zephyr-prolab-ad-en/</guid>
<pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
<description>A review of Zephyr Pro Lab (Red Team Operator I) — a simulated enterprise across 2 forests plus a child domain, with Active Directory front and centre.</description>
</item>
<item>
<title>[รีวิว]HTB Zephyr ProLab — อยู่ไม่ไหวๆ เฮ้ย AD น่ากลัว กลัว กลัว</title>
<link>https://blog.coreflaresec.com/posts/htb-zephyr-prolab-ad/</link>
<guid>https://blog.coreflaresec.com/posts/htb-zephyr-prolab-ad/</guid>
<pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
<description>รีวิว Zephyr Pro Lab ระดับ Red Team Operator I — องค์กรจำลอง 2 forest พร้อม child domain และ Active Directory เต็มรูปแบบ</description>
</item>
<item>
<title>HTB Alchemy Pro Lab — a realistic ICS/OT environment</title>
<link>https://blog.coreflaresec.com/posts/htb-alchemy-pro-lab-realistic-ics-ot-environment-en/</link>
<guid>https://blog.coreflaresec.com/posts/htb-alchemy-pro-lab-realistic-ics-ot-environment-en/</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
<description>A review of HackTheBox's Alchemy Pro Lab — a simulated ICS/OT environment built around the Sogard Brewing plant, from the IT side all the way down to the PLCs.</description>
</item>
<item>
<title>[รีวิว]HTB Alchemy Pro Lab — realistic ICS/OT environment</title>
<link>https://blog.coreflaresec.com/posts/htb-alchemy-pro-lab-realistic-ics-ot-environment/</link>
<guid>https://blog.coreflaresec.com/posts/htb-alchemy-pro-lab-realistic-ics-ot-environment/</guid>
<pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
<description>รีวิว Alchemy Pro Lab ของ HackTheBox — สภาพแวดล้อม ICS/OT จำลองโรงเบียร์ Sogard Brewing ตั้งแต่ฝั่ง IT ไปจนถึง PLC</description>
</item>
</channel></rss>
