<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress.com" -->
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd"
	xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
	xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
	xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"
	>
<url><loc>https://socdfir.com/2026/04/01/the-ticket-that-let-them-in-how-support-workflows-quietly-extend-breach-dwell-time/</loc><news:news><news:publication><news:name>Ramblings of a CyberSecurity Nerd</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-04-01T20:03:34+00:00</news:publication_date><news:title>The Ticket That Let Them In: How Support Workflows Quietly Extend Breach Dwell Time</news:title><news:keywords>security, cybersecurity, technology, mfa, cyber-security, incident-response, lolbins, mitre-attck, soc, detection-engineering, splunk, iam, multi-factor-authentication, dwell-time, help-desk, it-support, t1078, t1621, t1556-006, t1098, identity-management, accidental-anti-forensics, credential-abuse</news:keywords></news:news></url><url><loc>https://socdfir.com/2026/04/01/they-didnt-break-in-they-logged-in-the-real-problem-with-modern-ransomware/</loc><news:news><news:publication><news:name>Ramblings of a CyberSecurity Nerd</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-04-01T15:57:17+00:00</news:publication_date><news:title>They Didn’t Break In They Logged In: The Real Problem With Modern Ransomware</news:title><news:keywords>security, cybersecurity, technology, cyber-security, phishing, incident-response, dfir, Threat Detection, Living off the Land, threat-hunting, soc, blue-team, ransomware, zero-trust, Security Monitoring, powershell, identity-security, lateral-movement, rdp, psexec, network-segmentation, ueba, access-control</news:keywords></news:news></url></urlset>
