<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Detection Diary</title><description>A running diary of detection engineering by Agron Gemajli. Threat models, cloud hardening, and Splunk detections, built and broken in a homelab and written up in the open.</description><link>https://detectiondiary.com/</link><language>en-us</language><item><title>My blog is inside my SIEM</title><link>https://detectiondiary.com/blog/my-blog-is-in-my-siem/</link><guid isPermaLink="true">https://detectiondiary.com/blog/my-blog-is-in-my-siem/</guid><description>Every request to this site/blog lands in my homelab SIEM. The full Cloudfront to Splunk pipeline, some AWS gotchas, and what I actually detect.</description><pubDate>Sat, 15 Aug 2026 23:40:00 GMT</pubDate><category>detection</category><category>splunk</category><category>aws</category><category>cloudfront</category><category>infra</category></item><item><title>Hello, whoami and why I keep a detection diary</title><link>https://detectiondiary.com/blog/hello-detection-diary/</link><guid isPermaLink="true">https://detectiondiary.com/blog/hello-detection-diary/</guid><description>A quick introduction: who I am, what Detection Diary is for, and the kind of security writing you can expect here.</description><pubDate>Sat, 15 Aug 2026 01:23:00 GMT</pubDate><category>intro</category><category>meta</category></item></channel></rss>