<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DetectionOps - Field Notes</title>
    <link>https://detectionops.com</link>
    <description>Detection engineering as code - rules in Git, tested in CI, validated against real adversary behaviour. Field notes, an open rule library, a delivery platform and hands-on consulting.</description>
    <language>en</language>
    <atom:link href="https://detectionops.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Detection-as-Code Pipeline That Actually Ships</title>
      <link>https://detectionops.com/blog/detection-as-code-pipeline</link>
      <guid isPermaLink="true">https://detectionops.com/blog/detection-as-code-pipeline</guid>
      <description>Most detection-as-code talks stop at &apos;put your rules in Git&apos;. Here is the rest of it - the lint stage, the unit tests, the deploy gate, and the part nobody mentions: what happens when a rule starts failing in production.</description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>detection-as-code</category>
      <category>ci-cd</category>
      <category>process</category>
    </item>
    <item>
      <title>Your ATT&amp;CK Coverage Map Is Lying to You</title>
      <link>https://detectionops.com/blog/attack-coverage-is-lying-to-you</link>
      <guid isPermaLink="true">https://detectionops.com/blog/attack-coverage-is-lying-to-you</guid>
      <description>A green heat map with 78% coverage is the most comfortable lie in security. Here is why technique counting breaks down, and what to measure instead.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <category>mitre-attack</category>
      <category>metrics</category>
      <category>strategy</category>
    </item>
    <item>
      <title>Kerberoasting: From TTP to a Rule You Can Actually Deploy</title>
      <link>https://detectionops.com/blog/kerberoasting-from-ttp-to-rule</link>
      <guid isPermaLink="true">https://detectionops.com/blog/kerberoasting-from-ttp-to-rule</guid>
      <description>A full walkthrough - the protocol behaviour, the naive rule everyone writes first, why it drowns you, and the tuned version with its test cases.</description>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <category>windows</category>
      <category>active-directory</category>
      <category>walkthrough</category>
    </item>
    <item>
      <title>Sysmon Tuning: Signal Without the Flood</title>
      <link>https://detectionops.com/blog/sysmon-tuning-signal-without-the-flood</link>
      <guid isPermaLink="true">https://detectionops.com/blog/sysmon-tuning-signal-without-the-flood</guid>
      <description>Sysmon out of the box will bury you. A per-event-ID walkthrough of what to keep, what to drop, and how to work out the licence cost before you deploy to 10,000 endpoints.</description>
      <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
      <category>windows</category>
      <category>telemetry</category>
      <category>sysmon</category>
    </item>
  </channel>
</rss>
