<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>daemon // security logs</title>
    <link>https://daemon.cushard.dev</link>
    <description>Field notes from a detection-platform operator at MSSP scale.</description>
    <language>en-us</language>
    <item>
      <title><![CDATA[Why we killed the SOAR mock fleet]]></title>
      <link>https://daemon.cushard.dev/transmissions/why-we-killed-the-soar-mock-fleet</link>
      <guid>https://daemon.cushard.dev/transmissions/why-we-killed-the-soar-mock-fleet</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Mock-first SOAR tests gave us green CI and red prod. Here's what replaced them and why synthetic alerts are a better contract.]]></description>
      <category>WARN</category>
    </item>
    <item>
      <title><![CDATA[Detection drift at MSSP scale]]></title>
      <link>https://daemon.cushard.dev/transmissions/detection-drift-at-mssp-scale</link>
      <guid>https://daemon.cushard.dev/transmissions/detection-drift-at-mssp-scale</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Forking rules per client doesn't scale past a dozen tenants. A short note on why we track drift instead.]]></description>
      <category>INFO</category>
    </item>
  </channel>
</rss>