<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>noob2root</title>
    <link>https://noob2root.com</link>
    <description>Offensive security field notes — CVE analysis, proof-of-concept write-ups and tooling.</description>
    <language>en</language>
    <atom:link href="https://noob2root.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>PurpleForest, Part 1: Building an AD Purple-Team Lab from Zero</title>
      <link>https://noob2root.com/blog/purpleforest-part-1-building-the-lab</link>
      <guid>https://noob2root.com/blog/purpleforest-part-1-building-the-lab</guid>
      <category>Blog</category>
      <description>Stand up a Windows domain, a Graylog SIEM and Sysmon + Vector telemetry on one Windows host with VMware Workstation, Vagrant and Ansible.</description>
      <pubDate>Fri, 25 Sep 2026 05:02:05 GMT</pubDate>
    </item>
    <item>
      <title>PurpleForest: An Active Directory Lab That Fights Back</title>
      <link>https://noob2root.com/blog/purpleforest-ad-purple-team-lab</link>
      <guid>https://noob2root.com/blog/purpleforest-ad-purple-team-lab</guid>
      <category>Blog</category>
      <description>Most AD labs teach one half of the job. PurpleForest builds both: a Windows domain to attack, full telemetry through Vector, and Graylog to catch you. Run the attack, read the logs, write the rule, watch it fire, then evade it.</description>
      <pubDate>Fri, 25 Sep 2026 05:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Pi-hole, Unbound, a Honeypot and Grafana: A Home Security Box on a Raspberry Pi</title>
      <link>https://noob2root.com/blog/pihole-unbound-honeypot-grafana-telegram</link>
      <guid>https://noob2root.com/blog/pihole-unbound-honeypot-grafana-telegram</guid>
      <category>Blog</category>
      <description>Whole-house DNS filtering with Pi-hole + Unbound, an OpenCanary honeypot tripwire, a lightweight SIEM with Grafana + Loki + Alloy, real-time Telegram alerts, and a nightly AI summary from Hermes Agent. Every command included.</description>
      <pubDate>Thu, 24 Sep 2026 04:05:40 GMT</pubDate>
    </item>
    <item>
      <title>Running Hermes Agent on a Raspberry Pi for Under US$10 a Month (OpenRouter + DeepSeek)</title>
      <link>https://noob2root.com/blog/hermes-agent-raspberry-pi-openrouter-deepseek</link>
      <guid>https://noob2root.com/blog/hermes-agent-raspberry-pi-openrouter-deepseek</guid>
      <category>Blog</category>
      <description>Self-host Nous Research&apos;s Hermes Agent on a Raspberry Pi 4, talk to it from Telegram, and power it with DeepSeek through OpenRouter on a hard-capped budget.</description>
      <pubDate>Mon, 21 Sep 2026 10:55:35 GMT</pubDate>
    </item>
    <item>
      <title>What Three Years in a SOC Taught Me About Breaking In</title>
      <link>https://noob2root.com/blog/soc-to-offensive-what-carried-over</link>
      <guid>https://noob2root.com/blog/soc-to-offensive-what-carried-over</guid>
      <category>Blog</category>
      <description>The first post on noob2root — where it all started.</description>
      <pubDate>Wed, 16 Sep 2026 02:28:48 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2024-3094 — Backdoor in xz-utils liblzma</title>
      <link>https://noob2root.com/cve/cve-2024-3094-xz-backdoor</link>
      <guid>https://noob2root.com/cve/cve-2024-3094-xz-backdoor</guid>
      <category>CVE</category>
      <description>A multi-year social engineering campaign planted a backdoor in the xz release tarballs, hooking sshd via liblzma.</description>
      <pubDate>Fri, 07 Aug 2026 12:10:40 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2023-4966 — CitrixBleed: session token leak in NetScaler ADC</title>
      <link>https://noob2root.com/cve/cve-2023-4966-citrixbleed</link>
      <guid>https://noob2root.com/cve/cve-2023-4966-citrixbleed</guid>
      <category>CVE</category>
      <description>An unauthenticated buffer over-read leaks session tokens from memory, allowing MFA to be bypassed by replaying a hijacked session.</description>
      <pubDate>Wed, 29 Jul 2026 12:10:40 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2022-22965 — Spring4Shell: RCE in Spring Framework</title>
      <link>https://noob2root.com/cve/cve-2022-22965-spring4shell</link>
      <guid>https://noob2root.com/cve/cve-2022-22965-spring4shell</guid>
      <category>CVE</category>
      <description>Data binding in Spring MVC on JDK 9+ could be abused to reach class-loader properties and write a web shell, giving remote code execution.</description>
      <pubDate>Sat, 25 Jul 2026 22:46:39 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2021-26855 — ProxyLogon: pre-auth SSRF in Exchange</title>
      <link>https://noob2root.com/cve/cve-2021-26855-proxylogon</link>
      <guid>https://noob2root.com/cve/cve-2021-26855-proxylogon</guid>
      <category>CVE</category>
      <description>An SSRF in Microsoft Exchange chained to arbitrary file write for unauthenticated RCE. Mass-exploited against on-prem Exchange worldwide.</description>
      <pubDate>Tue, 21 Jul 2026 22:46:39 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2019-0708 — BlueKeep: pre-auth RCE in RDP</title>
      <link>https://noob2root.com/cve/cve-2019-0708-bluekeep</link>
      <guid>https://noob2root.com/cve/cve-2019-0708-bluekeep</guid>
      <category>CVE</category>
      <description>A use-after-free in Remote Desktop Services allowed unauthenticated, wormable remote code execution against a huge installed base of Windows hosts.</description>
      <pubDate>Wed, 15 Jul 2026 22:46:39 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2021-44228 — Log4Shell: JNDI lookup injection in Log4j 2</title>
      <link>https://noob2root.com/cve/cve-2021-44228-log4shell</link>
      <guid>https://noob2root.com/cve/cve-2021-44228-log4shell</guid>
      <category>CVE</category>
      <description>User-controlled strings reaching a Log4j 2 logging call trigger a JNDI lookup, giving remote code execution.</description>
      <pubDate>Mon, 13 Jul 2026 12:10:40 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2017-0144 — EternalBlue: RCE in SMBv1</title>
      <link>https://noob2root.com/cve/cve-2017-0144-eternalblue</link>
      <guid>https://noob2root.com/cve/cve-2017-0144-eternalblue</guid>
      <category>CVE</category>
      <description>A flaw in Microsoft SMBv1 allowed remote code execution from a crafted packet. Weaponised by WannaCry and NotPetya into some of the costliest malware outbreaks on record.</description>
      <pubDate>Thu, 09 Jul 2026 22:46:39 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2014-6271 — Shellshock: arbitrary code execution in Bash</title>
      <link>https://noob2root.com/cve/cve-2014-6271-shellshock</link>
      <guid>https://noob2root.com/cve/cve-2014-6271-shellshock</guid>
      <category>CVE</category>
      <description>Bash evaluated trailing code in specially crafted environment variables, giving RCE through anything that passed attacker input into the environment — CGI especially.</description>
      <pubDate>Sun, 05 Jul 2026 22:46:39 GMT</pubDate>
    </item>
    <item>
      <title>CVE-2014-0160 — Heartbleed: memory disclosure in OpenSSL</title>
      <link>https://noob2root.com/cve/cve-2014-0160-heartbleed</link>
      <guid>https://noob2root.com/cve/cve-2014-0160-heartbleed</guid>
      <category>CVE</category>
      <description>A missing bounds check in the OpenSSL TLS heartbeat extension let anyone read up to 64KB of server memory per request — including private keys.</description>
      <pubDate>Fri, 03 Jul 2026 22:46:39 GMT</pubDate>
    </item>
  </channel>
</rss>