<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ian Cooper</title><description>Cybersecurity professional focused on automating SOC alert triage, cloud security research, and detection engineering.</description><link>https://example.com/</link><item><title>5 pro tips for detecting in AWS</title><link>https://example.com/blog/expel-5-pro-tips-aws/</link><guid isPermaLink="true">https://example.com/blog/expel-5-pro-tips-aws/</guid><description>Practical detection engineering advice for AWS environments — from CloudTrail tuning to the queries that surface real attacker behavior.</description><pubDate>Wed, 14 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Fog in the sky: logging &amp; visibility issues in the cloud</title><link>https://example.com/blog/fog-in-the-sky/</link><guid isPermaLink="true">https://example.com/blog/fog-in-the-sky/</guid><description>Cloud environments present unique logging challenges that leave security teams flying blind. A look at the gaps attackers exploit and how to close them.</description><pubDate>Mon, 15 Jan 2024 00:00:00 GMT</pubDate></item><item><title>How to navigate five common security challenges in a multi-cloud environment</title><link>https://example.com/blog/expel-multi-cloud-security/</link><guid isPermaLink="true">https://example.com/blog/expel-multi-cloud-security/</guid><description>Multi-cloud environments introduce visibility gaps, inconsistent controls, and complex identity sprawl. Here&apos;s how to tackle the five most common security challenges.</description><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate></item><item><title>Cutting Through the Noise: RIOT Enrichment Drives SOC Clarity</title><link>https://example.com/blog/expel-riot-enrichment/</link><guid isPermaLink="true">https://example.com/blog/expel-riot-enrichment/</guid><description>How RIOT enrichment helps SOC analysts distinguish signal from noise, reducing alert fatigue and improving investigation quality.</description><pubDate>Mon, 18 Sep 2023 00:00:00 GMT</pubDate></item><item><title>How Expel goes detection sprinting in Google Cloud</title><link>https://example.com/blog/expel-detection-sprinting-gcp/</link><guid isPermaLink="true">https://example.com/blog/expel-detection-sprinting-gcp/</guid><description>A behind-the-scenes look at Expel&apos;s detection sprint methodology for Google Cloud — how we systematically build, test, and ship new detections at speed.</description><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate></item><item><title>Incident report: stolen AWS access keys</title><link>https://example.com/blog/expel-stolen-aws-keys/</link><guid isPermaLink="true">https://example.com/blog/expel-stolen-aws-keys/</guid><description>A post-mortem on how attackers used stolen AWS access keys, what they did once inside, and how to detect and respond to this class of incident.</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate></item></channel></rss>