<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>paidsec</title><link>https://paidsec.com/</link><description>Recent content on paidsec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 15:00:19 -0400</lastBuildDate><atom:link href="https://paidsec.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Breachlab Sentinel. A real dive into Blue Team Operations</title><link>https://paidsec.com/posts/sentinel/</link><pubDate>Wed, 22 Jul 2026 15:00:19 -0400</pubDate><guid>https://paidsec.com/posts/sentinel/</guid><description>&lt;h1 id="whoami"&gt;whoami&lt;/h1&gt;
&lt;hr&gt;
&lt;p&gt;If you haven&amp;rsquo;t read my &lt;a href="https://paidsec.com/about"&gt;about page&lt;/a&gt;, I am a full time blue team employee who enjoys doing red team on the side. Blue team pays the bills and red team keeps my brain happy. I&amp;rsquo;ve been working in a SOC like environment for a few years now and would like to share in this post how &lt;a href="https://breachlab.org"&gt;Breachlab.org&lt;/a&gt; Sentinel compares to a real world SOC environment. One thing I do need to preface before the rest of this post is that at my current employment we do not have a &amp;ldquo;by the book&amp;rdquo; SOC team. We are missing a few members which means that we all need to fill multiple roles all at the same time. &amp;ldquo;Wearing many different hats&amp;rdquo; as my boss would say. One day I could be just doing triage, and the next I could be working on system architecture and detection rules.&lt;/p&gt;</description></item><item><title>About</title><link>https://paidsec.com/about/</link><pubDate>Tue, 16 Jun 2026 11:25:26 -0400</pubDate><guid>https://paidsec.com/about/</guid><description>&lt;p&gt;I defend networks for a living and attack them for fun — and I&amp;rsquo;ve
started to suspect the second part is where I&amp;rsquo;m headed.&lt;/p&gt;
&lt;h2 id="the-day-job-blue-team"&gt;The day job: blue team&lt;/h2&gt;
&lt;p&gt;My professional home is on the defensive side. There&amp;rsquo;s a particular
satisfaction in blue team work that doesn&amp;rsquo;t always get talked about:
the quiet win of an alert that fires exactly when it should, the slow
craft of tuning detections until the noise falls away and the real
signal stands out. I like building the systems that catch things,
reading the logs nobody else wants to read, and knowing that on a good
day the most interesting thing that happens is nothing at all.&lt;/p&gt;</description></item></channel></rss>