<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress.com" -->
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd"
	xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
	xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
	xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"
	>
<url><loc>https://socdfir.com/2026/05/20/912/</loc><news:news><news:publication><news:name>Ramblings of a CyberSecurity Nerd</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-20T12:58:51+00:00</news:publication_date><news:title></news:title><news:keywords>dfir, threat-intelligence, threat-hunting, soc, detection-engineering, splunk, windows, yara, sigma, microsoft, cloud-filter-driver, mini plasma, ioctl, local-privilege-escalation, windows-11, chaotic eclipse, registry-manipulation, driver-security, privilege-escalation, cve-2020-17103, sysmon, cldflt, kernel-driver, google-project-zero</news:keywords></news:news></url></urlset>
