<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>https://thiebaut.dev/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/series/archived/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/generating-ida-type-information-libraries-from-windows-type-libraries/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/ida/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/reverse-engineering/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/series/</loc><lastmod>2023-11-07T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/anubis/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/dark-cat/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/icedid/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/icedid-and-qakbot-vnc-backdoors-dark-cat-anubis-keyhole/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/keyhole/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/pcap/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/qakbot/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/vnc/</loc><lastmod>2023-03-20T00:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/cve-2022-41120/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/diffing/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/series/diffing-patches/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/diffing-sysmon-clipboardchange-for-arbitrary-write/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/exploit/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/patch/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/proof-of-concepts/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/sysmon/</loc><lastmod>2022-11-14T11:15:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/series/building-a-monitoring-stack/</loc><lastmod>2022-06-30T15:19:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/enforcing-a-sysmon-archive-quota/</loc><lastmod>2022-06-30T15:19:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/forensics/</loc><lastmod>2022-06-30T15:19:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/logging/</loc><lastmod>2022-06-30T15:19:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/monitoring/</loc><lastmod>2022-06-30T15:19:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/azure/</loc><lastmod>2022-05-18T18:41:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/detecting-and-preventing-rogue-azure-subscriptions/</loc><lastmod>2022-05-18T18:41:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/automated-sigma-rule-generation-from-misp-threat-intelligence/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/detection/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/ids/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/misp/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/open-source/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/sigma/</loc><lastmod>2020-06-09T21:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/articles/automated-anomaly-detection-in-dns-records/</loc><lastmod>2020-01-17T14:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/dns/</loc><lastmod>2020-01-17T14:00:00+01:00</lastmod></url><url><loc>https://thiebaut.dev/categories/honeypots/</loc><lastmod>2020-01-17T14:00:00+01:00</lastmod></url></urlset>