<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Threat Detection Labs</title><description>Detection engineering, threat intelligence, and cybersecurity research.</description><link>https://threatdetectionlabs.com/</link><language>en-us</language><item><title>Writing Your First SIGMA Detection Rule</title><link>https://threatdetectionlabs.com/posts/writing-your-first-sigma-rule/</link><guid isPermaLink="true">https://threatdetectionlabs.com/posts/writing-your-first-sigma-rule/</guid><description>A step-by-step guide to creating SIGMA rules for detecting suspicious process execution on Windows endpoints.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>detection-engineering</category><category>sigma</category><category>detection</category><category>windows</category><category>powershell</category></item><item><title>KQL for Threat Hunting: Essential Queries Every Analyst Should Know</title><link>https://threatdetectionlabs.com/posts/kql-threat-hunting-basics/</link><guid isPermaLink="true">https://threatdetectionlabs.com/posts/kql-threat-hunting-basics/</guid><description>Learn the essential KQL queries for threat hunting in Microsoft Sentinel and Defender.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>threat-intel</category><category>kql</category><category>hunting</category><category>sentinel</category><category>azure</category></item><item><title>MITRE ATT&amp;CK for Detection Engineers: A Practical Guide</title><link>https://threatdetectionlabs.com/posts/understanding-mitre-attack/</link><guid isPermaLink="true">https://threatdetectionlabs.com/posts/understanding-mitre-attack/</guid><description>How to use the MITRE ATT&amp;CK framework to build structured detection coverage for your organization.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>tutorials</category><category>detection</category><category>hunting</category></item></channel></rss>