<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Shahrukh Khan — Cybersecurity Blog</title>
    <link>https://heyshahrukh.me/blogs</link>
    <description>Cybersecurity essays on detection engineering, AI security, SOC automation, and threat intelligence.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 08 Jun 2026 13:46:33 GMT</lastBuildDate>
    <atom:link href="https://heyshahrukh.me/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>10 Cybersecurity Case Studies Every Security Engineer Should Study</title>
      <link>https://heyshahrukh.me/blogs/10-cybersecurity-case-studies-every-security-engineer-should-study</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/10-cybersecurity-case-studies-every-security-engineer-should-study</guid>
      <pubDate>Thu, 04 Jun 2026 17:36:24 GMT</pubDate>
      <description>Ten cybersecurity case studies every security engineer should study, what happened, how it unfolded, and the key lesson.</description>
    </item>
    <item>
      <title>MITRE ATLAS: The Security Framework Built for the Age of AI</title>
      <link>https://heyshahrukh.me/blogs/mitre-atlas-the-security-framework-built-for-the-age-of-ai</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/mitre-atlas-the-security-framework-built-for-the-age-of-ai</guid>
      <pubDate>Wed, 03 Jun 2026 17:47:10 GMT</pubDate>
      <description>Learn what MITRE ATLAS is, how it works, and why every security team needs it. The complete guide to defending AI systems against real-world adversarial attacks</description>
    </item>
    <item>
      <title>What is an Agentic AI SOC Analyst? A Comprehensive Guide</title>
      <link>https://heyshahrukh.me/blogs/what-is-an-agentic-ai-soc-analyst-a-comprehensive-guide</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/what-is-an-agentic-ai-soc-analyst-a-comprehensive-guide</guid>
      <pubDate>Wed, 03 Jun 2026 17:21:39 GMT</pubDate>
      <description>Learn how Agentic AI SOC Analysts automate threat detection, investigation, and response, transforming modern SOC operations with AI-driven security.</description>
    </item>
    <item>
      <title>Essential SOC Tools and Technologies</title>
      <link>https://heyshahrukh.me/blogs/essential-soc-tools-and-technologies</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/essential-soc-tools-and-technologies</guid>
      <pubDate>Sun, 31 May 2026 06:39:17 GMT</pubDate>
      <description>Explore the essential tools used by SOC analysts, including SIEM, EDR, SOAR, TIPs, XDR, CSPM, UEBA, and vulnerability scanners.</description>
    </item>
    <item>
      <title>AI in Modern Email Security</title>
      <link>https://heyshahrukh.me/blogs/ai-in-modern-email-security</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/ai-in-modern-email-security</guid>
      <pubDate>Sat, 30 May 2026 18:31:05 GMT</pubDate>
      <description>Discover how AI enhances email security through phishing detection, threat analysis, anomaly detection, and automated response.</description>
    </item>
    <item>
      <title>Email Security Triage Framework</title>
      <link>https://heyshahrukh.me/blogs/email-security-triage-framework</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/email-security-triage-framework</guid>
      <pubDate>Sat, 30 May 2026 18:32:47 GMT</pubDate>
      <description>A step by step framework for investigating phishing emails, analyzing URLs, attachments, and indicators before responding to threats.</description>
    </item>
    <item>
      <title>SOC L1 Email Investigation Guide</title>
      <link>https://heyshahrukh.me/blogs/soc-l1-email-investigation-guide</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/soc-l1-email-investigation-guide</guid>
      <pubDate>Sat, 30 May 2026 18:35:01 GMT</pubDate>
      <description>Learn how SOC L1 analysts investigate suspicious emails using headers, URLs, attachments, domain checks, and phishing analysis techniques.</description>
    </item>
    <item>
      <title>Email Security Best Practices for Modern Organizations</title>
      <link>https://heyshahrukh.me/blogs/email-security-best-practices-for-modern-organizations</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/email-security-best-practices-for-modern-organizations</guid>
      <pubDate>Sat, 30 May 2026 18:37:15 GMT</pubDate>
      <description>Explore modern email threats, phishing risks, BEC attacks, and practical security controls to protect your organization from compromise</description>
    </item>
    <item>
      <title>MITRE ATT&amp;CK v19 Explained</title>
      <link>https://heyshahrukh.me/blogs/mitre-attck-v19-explained</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/mitre-attck-v19-explained</guid>
      <pubDate>Sat, 30 May 2026 18:39:12 GMT</pubDate>
      <description>Explore MITRE ATT&amp;CK v19, including the retirement of Defense Evasion and the introduction of Stealth and Defense Impairment tactics.</description>
    </item>
    <item>
      <title>MITRE ATT&amp;CK v19: Why the New Tactic Matters for SOC Teams</title>
      <link>https://heyshahrukh.me/blogs/mitre-attck-v19-why-the-new-tactic-matters-for-soc-teams</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/mitre-attck-v19-why-the-new-tactic-matters-for-soc-teams</guid>
      <pubDate>Sat, 30 May 2026 18:40:29 GMT</pubDate>
      <description>Learn how MITRE ATT&amp;CK v19 splits Defense Evasion into Stealth and Impair Defenses, reshaping detection and SOC operations.</description>
    </item>
    <item>
      <title>Why Most SOC Detections Fail</title>
      <link>https://heyshahrukh.me/blogs/why-most-soc-detections-fail</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/why-most-soc-detections-fail</guid>
      <pubDate>Sat, 30 May 2026 18:41:31 GMT</pubDate>
      <description>Learn why behavior based detections outperform basic IOC alerts and how modern SOC teams can reduce noise and improve threat visibility.</description>
    </item>
    <item>
      <title>OWASP AI Top 10 with MITRE ATLAS</title>
      <link>https://heyshahrukh.me/blogs/owasp-ai-top-10-with-mitre-atlas</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/owasp-ai-top-10-with-mitre-atlas</guid>
      <pubDate>Sat, 30 May 2026 18:43:00 GMT</pubDate>
      <description>Explore the OWASP AI Top 10 risks and their MITRE ATLAS mappings, with real world examples of attacks against LLM applications.</description>
    </item>
    <item>
      <title>AI Security Monitoring Logs Guide</title>
      <link>https://heyshahrukh.me/blogs/ai-security-monitoring-logs-guide</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/ai-security-monitoring-logs-guide</guid>
      <pubDate>Sat, 30 May 2026 18:44:42 GMT</pubDate>
      <description>Learn which logs are critical for AI security monitoring, prompt injection detection, agent tracing, and MITRE ATLAS aligned visibility.</description>
    </item>
    <item>
      <title>Why Great Products Still Fail</title>
      <link>https://heyshahrukh.me/blogs/why-great-products-still-fail</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/why-great-products-still-fail</guid>
      <pubDate>Sat, 30 May 2026 18:46:30 GMT</pubDate>
      <description>Innovation alone is not enough. Learn why onboarding, training, and user experience determine whether products succeed or become shelfware.</description>
    </item>
    <item>
      <title>Application Detection &amp; Response</title>
      <link>https://heyshahrukh.me/blogs/application-detection-response</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/application-detection-response</guid>
      <pubDate>Sat, 30 May 2026 18:48:31 GMT</pubDate>
      <description>Discover how ADR enhances application security by detecting runtime threats, zero day exploits, and logic flaws beyond traditional WAFs.</description>
    </item>
    <item>
      <title>Building an Email Header Filter</title>
      <link>https://heyshahrukh.me/blogs/building-an-email-header-filter</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/building-an-email-header-filter</guid>
      <pubDate>Sat, 30 May 2026 18:50:11 GMT</pubDate>
      <description>Learn how origin based email filters use header analysis to block phishing, spam, and spoofed emails before content inspection begins.</description>
    </item>
    <item>
      <title>The Hidden Risk of Hero Culture</title>
      <link>https://heyshahrukh.me/blogs/the-hidden-risk-of-hero-culture</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/the-hidden-risk-of-hero-culture</guid>
      <pubDate>Sat, 30 May 2026 18:52:31 GMT</pubDate>
      <description>Discover how RACI and CMMI help organizations eliminate key person dependency and build resilient, process driven operations.</description>
    </item>
    <item>
      <title>Why 90% of Products Fail</title>
      <link>https://heyshahrukh.me/blogs/why-90-of-products-fail</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/why-90-of-products-fail</guid>
      <pubDate>Sat, 30 May 2026 18:55:47 GMT</pubDate>
      <description>Discover why planning, process maturity, and strategic execution matter more than funding, vision, or technical expertise.</description>
    </item>
    <item>
      <title>T1036.003-Rename System Utilities</title>
      <link>https://heyshahrukh.me/blogs/t1036003-rename-system-utilities</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1036003-rename-system-utilities</guid>
      <pubDate>Thu, 28 May 2026 19:25:48 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1036.003-Rename System Utilities. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1105-Ingress Tool Transfer</title>
      <link>https://heyshahrukh.me/blogs/t1105-ingress-tool-transfer</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1105-ingress-tool-transfer</guid>
      <pubDate>Sat, 30 May 2026 19:27:39 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1105 Ingress Tool Transfer. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1218.011-Rundll32</title>
      <link>https://heyshahrukh.me/blogs/t1218011-rundll32</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1218011-rundll32</guid>
      <pubDate>Sat, 30 May 2026 19:31:37 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1218.011 Rundll32. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1003-OS Credential Dumping</title>
      <link>https://heyshahrukh.me/blogs/t1003-os-credential-dumping</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1003-os-credential-dumping</guid>
      <pubDate>Sat, 30 May 2026 19:34:30 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1003 OS Credential Dumping. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1114.003-Email Forwarding Rule</title>
      <link>https://heyshahrukh.me/blogs/t1114003-email-forwarding-rule</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1114003-email-forwarding-rule</guid>
      <pubDate>Sat, 30 May 2026 19:37:40 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1114.003-Email Forwarding Rule. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1027-Obfuscated Files or Information</title>
      <link>https://heyshahrukh.me/blogs/t1027-obfuscated-files-or-information</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1027-obfuscated-files-or-information</guid>
      <pubDate>Sat, 30 May 2026 19:40:03 GMT</pubDate>
      <description>Trending MITRE ATT&amp;CK Technique: T1027-Obfuscated Files or Information. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1078.004-Cloud Accounts</title>
      <link>https://heyshahrukh.me/blogs/t1078004-cloud-accounts</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1078004-cloud-accounts</guid>
      <pubDate>Sat, 30 May 2026 19:41:52 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1078.004-Cloud Accounts. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1047-Windows Management Instrumentation</title>
      <link>https://heyshahrukh.me/blogs/t1047-windows-management-instrumentation</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1047-windows-management-instrumentation</guid>
      <pubDate>Sat, 30 May 2026 19:43:10 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1047-Windows Management Instrumentation. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1059.003 - Windows Command Shell</title>
      <link>https://heyshahrukh.me/blogs/t1059003-windows-command-shell</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1059003-windows-command-shell</guid>
      <pubDate>Wed, 03 Jun 2026 17:05:36 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1059.003 - Windows Command Shell. Detections, visibility, use cases and real world attack insights.</description>
    </item>
    <item>
      <title>T1059.001 - PowerShell</title>
      <link>https://heyshahrukh.me/blogs/t1059001-powershell</link>
      <guid isPermaLink="true">https://heyshahrukh.me/blogs/t1059001-powershell</guid>
      <pubDate>Wed, 03 Jun 2026 17:12:10 GMT</pubDate>
      <description>MITRE ATT&amp;CK Technique: T1059.001 - PowerShell. Detections, visibility, use cases and real world attack insights.</description>
    </item>
  </channel>
</rss>
