Hands-on writeups from my TryHackMe rooms and CTF work, documenting my path from SEC0 to OSCP. Each one covers the full flow — recon, vulnerability research, exploitation, and the flag — plus the bits that didn't work, because that's usually where the real learning is.
Coming from a trucking background with zero formal IT experience, so these are written the way I wish walkthroughs were: plain-English first, commands explained, no skipped steps.
Tested, not trusted. More at rootfox.dev
| Room | Difficulty | Topic | Writeup |
|---|---|---|---|
| Vulnerability Capstone | Easy | Fuel CMS RCE — CVE-2018-16763 | Link |
More on the way.
Most of these run out of a home lab or the TryHackMe AttackBox — Kali,
searchsploit, nmap, Burp, and whatever public PoCs the box calls for.