<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://blueteamnotes.com/</loc>
    <lastmod>2026-02-11T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/</loc>
    <lastmod>2025-10-14T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/</loc>
    <lastmod>2026-02-11T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-soc/</loc>
    <lastmod>2025-10-02T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-misc/</loc>
    <lastmod>2026-01-30T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/parental-control-lsm/</loc>
    <lastmod>2026-02-11T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/ebpf-and-cybersec/</loc>
    <lastmod>2026-02-05T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-misc/http-quic-udp/</loc>
    <lastmod>2026-01-30T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/linux-access-no-sshvnc/</loc>
    <lastmod>2026-01-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-misc/aws-iam-prefixes/</loc>
    <lastmod>2025-10-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/monitoring-aurora-edr/</loc>
    <lastmod>2025-10-14T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-soc/speed-of-future-attacks/</loc>
    <lastmod>2025-10-02T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-soc/detection-rules-priority/</loc>
    <lastmod>2025-09-30T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/syncing-auditd-containers/</loc>
    <lastmod>2025-09-27T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/execve-process-auditing/</loc>
    <lastmod>2025-06-30T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-soc/quick-log-parsing-splunk/</loc>
    <lastmod>2025-06-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/what-can-event-4624-tell/</loc>
    <lastmod>2025-06-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-soc/splunk-for-incident-response/</loc>
    <lastmod>2025-06-14T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/how-sysmon-logs-dns/</loc>
    <lastmod>2025-06-06T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-linux/ioc-search-using-ctime/</loc>
    <lastmod>2025-06-05T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/useful-sysmon-fields/</loc>
    <lastmod>2025-05-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://blueteamnotes.com/blog-windows/why-you-need-sysmon/</loc>
    <lastmod>2025-05-25T00:00:00+00:00</lastmod>
  </url>
</urlset>
