<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Tracemill Blog</title>
    <link>https://tracemill.io/blog</link>
    <atom:link href="https://tracemill.io/blog/rss.xml" rel="self" type="application/rss+xml"/>
    <description>Articles and reproducible research on detection pipelines.</description>
    <language>en</language>
    <item>
      <title>Detection testing needs a monitor, not a calendar</title>
      <link>https://tracemill.io/blog/detection-testing-needs-a-monitor-not-a-calendar</link>
      <guid isPermaLink="true">https://tracemill.io/blog/detection-testing-needs-a-monitor-not-a-calendar</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>Article</category>
      <description>A detection can run successfully while its data is filtered, transformed, or lost. How do you know it still works?</description>
    </item>
    <item>
      <title>TM-2026-001: One add-on upgrade, one blind detection: current Splunk AWS TA fragments AssumedRole recon</title>
      <link>https://tracemill.io/research/aws-assumed-role-aggregation-fragments-reconnaissance</link>
      <guid isPermaLink="true">https://tracemill.io/research/aws-assumed-role-aggregation-fragments-reconnaissance</guid>
      <pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate>
      <category>Investigation</category>
      <description>A 2025 update to the Splunk Add-on for AWS re-attributes 39 read-only CloudTrail events from the assumed role to the individual session - enough to fragment a role's reconnaissance below AWS Excessive Security Scanning's threshold and silence it.</description>
    </item>
    <item>
      <title>TM-2026-003: Cribl's CloudTrail pack: 60-80% fewer events, eight silent Splunk detections</title>
      <link>https://tracemill.io/research/cribl-cloudtrail-filtering-drops-aws-read-events</link>
      <guid isPermaLink="true">https://tracemill.io/research/cribl-cloudtrail-filtering-drops-aws-read-events</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <category>Investigation</category>
      <description>An A/B validation of 38 Splunk ESCU AWS detections with the official CloudTrail pack in and out of the data ingestion pipeline, or what a cost-saving reduction quietly does to your detections.</description>
    </item>
  </channel>
</rss>
