<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DFIR on The Broomstick Brief</title><link>https://broomstick.tymyrddin.dev/tags/dfir/</link><description>Recent content in DFIR on The Broomstick Brief</description><generator>Hugo -- 0.147.3</generator><language>en</language><lastBuildDate>Sun, 05 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://broomstick.tymyrddin.dev/tags/dfir/index.xml" rel="self" type="application/rss+xml"/><item><title>Ghost hunting</title><link>https://broomstick.tymyrddin.dev/posts/ghost-detection/</link><pubDate>Sun, 05 Apr 2026 00:00:00 +0000</pubDate><guid>https://broomstick.tymyrddin.dev/posts/ghost-detection/</guid><description>A detection rule is a bet. It says that if an attacker does something in a given environment, the rule will fire. That bet rests on an understanding of attacker behaviour at the time the rule was written. That understanding was incomplete then and has been drifting ever since.</description></item></channel></rss>