<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Anton Ovrutsky — #AIForBlueTeam</title><description>#AIForBlueTeam daily tips and longform blogs on using AI for defensive security work.</description><link>https://antonlovesdnb.com/</link><item><title>Agent credential protection with fishbowl</title><link>https://antonlovesdnb.com/blog/fishbowl/</link><guid isPermaLink="true">https://antonlovesdnb.com/blog/fishbowl/</guid><description>Building an auditing perimeter around AI agents to generate telemetry when credentials are accessed - demonstrated with a simulated malicious NPM package exfiltrating Azure tokens</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category></item><item><title>Day 25: AD Deception</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7448112342367637504-dj_9</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7448112342367637504-dj_9</guid><description>Use Claude to scan your existing Active Directory environment and provision you a PowerShell script &amp; corresponding Splunk queries for deception/honey accounts.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 24: AgentFence Preview</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447750438289838080-ckdJ</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447750438289838080-ckdJ</guid><description>Preview of my new AgentFence tool!</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 23: ATT&amp;CK Heatmap</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447391669114679297-93tp</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447391669114679297-93tp</guid><description>Have Claude query your existing SIEM data and build you an ATT&amp;CK Navigator heatmap.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 22: AI Powered Hunt Helper</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447021615437107200-aUrP</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7447021615437107200-aUrP</guid><description>- Ingest a threat intel report. - Map it to ATT&amp;CK</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 21: Detection Peer Review</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7446541316391346176-zauG</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7446541316391346176-zauG</guid><description>Reads a Splunk query from Obsidian, benchmarks it, auto-converts to tstats via accelerated data models, and compares performance. 7.9x faster.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 20: Log Compliance Auditor</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7446225165178265601-6_fb</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7446225165178265601-6_fb</guid><description>Multi-agent skill that audits Linux (SSH) and Windows (WinRM) in parallel against 20 CIS Benchmark checks, mapped to NIST, PCI-DSS, and ATT&amp;CK.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 19: AI Cyber Defense Ops Course</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-claudeforblueteam-share-7445865516042375168-E5HQ</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-claudeforblueteam-share-7445865516042375168-E5HQ</guid><description>Full course release for using Claude in defensive security workflows. 10 modules covering MCP servers, skills, hooks, and end-to-end workflows.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 18: Sysmon Config Heatmap</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7445483931899957248-5_CG</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7445483931899957248-5_CG</guid><description>Paste Sysmon XML, get a visual ATT&amp;CK coverage heatmap. Color-coded: green (covered), yellow (partial), red (blind spot), grey (disabled).</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 17: Sysmon Config Review</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7445211989569765376-dswP</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7445211989569765376-dswP</guid><description>Feed any Sysmon XML config to Claude for an instant sanity check. Identifies disabled event IDs, coverage gaps, and stale exclusions.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 16: Supply Chain Audit</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7444720513429573633--x7-</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7444720513429573633--x7-</guid><description>Scans dependencies with pip-audit and osv-scanner, then triages by reachability. 37 CVEs found, only 5 actually matter.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 15: K8s RBAC Audit</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7444490310593839104-KHYG</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7444490310593839104-KHYG</guid><description>Full RBAC audit of a K8s cluster. Claude reasons over the RBAC graph to find escalation paths, dormant privileges, and blast radius.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 14: Blue Team Docker Toolkit</title><link>https://www.linkedin.com/feed/update/urn:li:activity:7444027153488261120/</link><guid isPermaLink="true">https://www.linkedin.com/feed/update/urn:li:activity:7444027153488261120/</guid><description>One prompt builds a cross-platform Docker container with 17 security tools: Hayabusa, Chainsaw, tshark, YARA, capa, Volatility3, and more.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 13: K8s Security Sparring Partner</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443696120259653632-JO3O</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443696120259653632-JO3O</guid><description>Auto-provisions misconfigured pods on minikube (plaintext secrets, privileged containers, wildcard RBAC) then tutors you through fixing them.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 12: SIEM Health Check</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443399092774387712-Sigf</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443399092774387712-Sigf</guid><description>5 parallel Splunk queries for host inventory, volume anomalies, ingestion delay, data model status, and internal errors. Adaptive deep-dive with cross-signal correlation.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 11: Log Noise Analysis</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443030111668363264-OqrE</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7443030111668363264-OqrE</guid><description>Drills into the noisiest SIEM events by sourcetype and event ID. Traces noise generators and provides tuning recommendations with events/sec savings.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 10: ATT&amp;CK Coverage Gap Analysis</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7442680089307172864-tHyi</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7442680089307172864-tHyi</guid><description>Links ATT&amp;CK data sources to SIEM event IDs, shows technique coverage with TUI bar charts, and ranks priority gaps by bang-for-buck.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 9: PCAP Analysis with tshark</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7442315915901251584-oPMk</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7442315915901251584-oPMk</guid><description>Claude + tshark analyzes PCAPs, maps findings to ATT&amp;CK, and writes an Obsidian note with all tshark commands for verification.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 8: AD Security Briefing Hook</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7441941454748409856-3Ofz</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-share-7441941454748409856-3Ofz</guid><description>A SessionStart hook that queries Splunk for AD account changes, group membership, logon events, and failures. Claude reasons over the data and flags what matters.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 7: Host Software Inventory</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7441507618206060544-64Fx</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7441507618206060544-64Fx</guid><description>Queries Sysmon Event IDs 1, 3, 6, 7, 22 from Splunk and categorizes third-party software with framework detection via DLL analysis.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 6: splunk-run Slash Command</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7441121804884131840-AVxo</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7441121804884131840-AVxo</guid><description>Reads a Splunk query from an Obsidian note, runs it via REST API, builds a Sysmon process tree, and appends results.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 5: Threat Report Pipeline</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440862677863817216-ijV-</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440862677863817216-ijV-</guid><description>URL to defensive playbook in one command. ATT&amp;CK mapping, data sources, and Atomic Red Team tests.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 4: attack-note Slash Command</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440497257281552384-arHm</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440497257281552384-arHm</guid><description>A slash command that builds ATT&amp;CK notes with frontmatter, backlinks, and relationships via Obsidian CLI.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 3: ATT&amp;CK Obsidian Vault</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440138486013136896-IlFT</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7440138486013136896-IlFT</guid><description>Generated 2,396 interlinked notes covering Tactics, Techniques, and Data Components with graph view.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 2: MITRE ATT&amp;CK MCP Server</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7439780669049688064-64fO</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7439780669049688064-64fO</guid><description>Built an MCP server with 10 tools for querying ATT&amp;CK data. Packaged as .mcpb for Claude Desktop.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item><item><title>Day 1: ATT&amp;CK as JSON</title><link>https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7439425696059289601-WjG7</link><guid isPermaLink="true">https://www.linkedin.com/posts/antonovrutsky_claudeforblueteam-activity-7439425696059289601-WjG7</guid><description>Downloaded enterprise-attack.json and used Claude to analyze data sources. Process Creation alone covers 65% of ATT&amp;CK techniques.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><category>#AIForBlueTeam</category></item></channel></rss>