<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>Thriving Defense</title>
      <link>https://thrivingdefense.com</link>
      <description>Last 10 notes on Thriving Defense</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>acre_output-example</title>
    <link>https://thrivingdefense.com/raw/acre_output-example</link>
    <guid>https://thrivingdefense.com/raw/acre_output-example</guid>
    <description><![CDATA[ ACRE Score Report — 2026-04-13 Scores PlatformACRE ScoreCovered TechniquesWeighted ScoreWindows0.1115 (11.2%)25 / 226 detectable35.0 / 314.0Linux0.1561 (15.6%)15 / 98 detectable21.0 / 134.5macOS0.1038 (10.4%)4 / 39 detectable5.5 / 53.0 Detectable threshold: ≥5 open-source rules (Sigma + Splunk + Ela... ]]></description>
    <pubDate>Mon, 13 Apr 2026 17:44:39 GMT</pubDate>
  </item><item>
    <title>platform-coverage</title>
    <link>https://thrivingdefense.com/raw/platform-coverage</link>
    <guid>https://thrivingdefense.com/raw/platform-coverage</guid>
    <description><![CDATA[ Platform Coverage Analysis Produce a technique × platform coverage matrix across Sigma, Splunk Security Content, and Elastic detection rule repos. ]]></description>
    <pubDate>Mon, 13 Apr 2026 17:42:15 GMT</pubDate>
  </item><item>
    <title>acre-coverage</title>
    <link>https://thrivingdefense.com/raw/acre-coverage</link>
    <guid>https://thrivingdefense.com/raw/acre-coverage</guid>
    <description><![CDATA[ ACRE Coverage Calculator Calculate your organization’s ACRE (ATT&amp;CK Coverage Ratio Evaluation) score by comparing your custom detection rules against the detectable ATT&amp;CK technique baseline. ]]></description>
    <pubDate>Mon, 13 Apr 2026 03:48:07 GMT</pubDate>
  </item><item>
    <title>Technique matrices</title>
    <link>https://thrivingdefense.com/reference/Technique-matrices</link>
    <guid>https://thrivingdefense.com/reference/Technique-matrices</guid>
    <description><![CDATA[ A collection of ATT&CK-adjacent matrices — SITF, PR3TACK, and others — to expand ACRE's coverage denominator. ]]></description>
    <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Summiting the Pyramid Levels</title>
    <link>https://thrivingdefense.com/reference/Summiting-the-Pyramid-Levels</link>
    <guid>https://thrivingdefense.com/reference/Summiting-the-Pyramid-Levels</guid>
    <description><![CDATA[ StP levels classify detection rule brittleness from easily-evaded indicators to hard-to-evade behaviors. ]]></description>
    <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>comprehensively detect the middle of the attack</title>
    <link>https://thrivingdefense.com/principles/comprehensively-detect-the-middle-of-the-attack</link>
    <guid>https://thrivingdefense.com/principles/comprehensively-detect-the-middle-of-the-attack</guid>
    <description><![CDATA[ Defenders should focus comprehensive detection mid-attack — after initial access but before impact. ]]></description>
    <pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Welcome</title>
    <link>https://thrivingdefense.com/</link>
    <guid>https://thrivingdefense.com/</guid>
    <description><![CDATA[ An introduction to Thriving Defense, a site dedicated to helping detection engineers reach a thriving state. ]]></description>
    <pubDate>Fri, 10 Apr 2026 18:18:23 GMT</pubDate>
  </item><item>
    <title>MITRE ATT&amp;CK® PRE</title>
    <link>https://thrivingdefense.com/reference/MITRE-ATT-and-CK%C2%AE-PRE</link>
    <guid>https://thrivingdefense.com/reference/MITRE-ATT-and-CK%C2%AE-PRE</guid>
    <description><![CDATA[ I learned about the PRE platform while pivoting through MITRE ATT&amp;CK® data looking for patterns. ]]></description>
    <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Mutually Exclusive and Collectively Exhaustive (MECE)</title>
    <link>https://thrivingdefense.com/reference/Mutually-Exclusive-and-Collectively-Exhaustive-(MECE)</link>
    <guid>https://thrivingdefense.com/reference/Mutually-Exclusive-and-Collectively-Exhaustive-(MECE)</guid>
    <description><![CDATA[ It’s very human to categorize, especially with small sets of data, but creating categories that meet the titular standard is very difficult. ]]></description>
    <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>implement tests based on TRRs</title>
    <link>https://thrivingdefense.com/methodology/implement-tests-based-on-TRRs</link>
    <guid>https://thrivingdefense.com/methodology/implement-tests-based-on-TRRs</guid>
    <description><![CDATA[ There is a pending change to the TRR repo that will make it much easier to implement this, and then we can complete this post!. ]]></description>
    <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
  </item>
    </channel>
  </rss>