<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Vedran Dojčinović</title><description>Detection engineering, Active Directory security, and pentest research notes.</description><link>https://vedrandojcinovic.com/</link><item><title>What the SOC Analyst path actually taught me — running my own SIEM alongside it</title><link>https://vedrandojcinovic.com/blog/soc-analyst-path-htb/</link><guid isPermaLink="true">https://vedrandojcinovic.com/blog/soc-analyst-path-htb/</guid><description>Going through HTB&apos;s SOC Analyst path while running a purple team lab changed what stuck. The detections aren&apos;t the point. Seeing where they break is.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>soc</category><category>detection-engineering</category><category>blue-team</category><category>wazuh</category><category>splunk</category><category>hack-the-box</category><category>cdsa</category></item><item><title>Detecting Kerberoasting with Wazuh</title><link>https://vedrandojcinovic.com/blog/detecting-kerberoasting-with-wazuh/</link><guid isPermaLink="true">https://vedrandojcinovic.com/blog/detecting-kerberoasting-with-wazuh/</guid><description>The rule is six lines of XML. The part that actually mattered was a query I ran before writing any of it.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>wazuh</category><category>detection-engineering</category><category>active-directory</category><category>kerberos</category><category>blue-team</category><category>mitre-attack</category></item></channel></rss>