<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Detection Engineering on </title>
    <link>/series/detection-engineering/</link>
    <description>Recent content in Detection Engineering on </description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 07 Aug 2026 15:08:49 -0400</lastBuildDate>
    <atom:link href="/series/detection-engineering/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Detection Engineering: Getting Started with Sigma</title>
      <link>/posts/detection_engineering/sigma_rules/</link>
      <pubDate>Fri, 07 Aug 2026 15:08:49 -0400</pubDate>
      <guid>/posts/detection_engineering/sigma_rules/</guid>
      <description>Introduction Hello everyone and welcome back to another post from yours truly. Today we&amp;rsquo;re going to be doing something slightly different actually. I&amp;rsquo;ve been looking more into detection engineering recently and been wanting to get better at writing detection rules in different formats and whatnot. So today we&amp;rsquo;re going to be actually looking at a threat intelligence post from Cisco Talos covering some malware from the Chaos ransomware group. Specifically, their msaRAT malware that uses the browser for its C2 communications.</description>
    </item>
  </channel>
</rss>
