<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>War Room</title>
	<atom:link href="https://warroom.rsmus.com/category/defense/feed/" rel="self" type="application/rss+xml" />
	<link>https://warroom.rsmus.com</link>
	<description>Shells From Above</description>
	<lastBuildDate>Thu, 03 Sep 2026 21:14:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://warroom.rsmus.com/wp-content/uploads/2018/09/cropped-favicon-32x32.png</url>
	<title>War Room</title>
	<link>https://warroom.rsmus.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Signal Hidden in the Noise</title>
		<link>https://warroom.rsmus.com/the-signal-hidden-in-the-noise/</link>
		
		<dc:creator><![CDATA[Justin Dolgos]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 21:02:07 +0000</pubDate>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6383</guid>

					<description><![CDATA[How the RSM Defense Threat Hunting Team uncovered a sophisticated fileless RAT using one of their 300+ in-house custom detections. . Published by the RSM Defense Threat Hunting Team Author: Justin Dolgos, Threat Hunting Supervisor The Short Version Every organization generates noise. Millions of events, thousands of alerts, and endless telemetry pour into a security [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>The Threat That Slipped Past the Machines, and Ran Into a Human</title>
		<link>https://warroom.rsmus.com/the-threat-that-slipped-past-the-machines-and-ran-into-a-human/</link>
		
		<dc:creator><![CDATA[Justin Dolgos]]></dc:creator>
		<pubDate>Fri, 12 Jun 2026 13:41:44 +0000</pubDate>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[RSM Defense]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6360</guid>

					<description><![CDATA[How proactive threat hunting caught an attack engineered to evade the industry&#8217;s leading endpoint platforms. By Justin Dolgos, Senior Threat Hunter at RSM Defense Most malware tries to avoid your security tools. This one knew them by name. Modern attackers have learned that the fastest way past a hardened security stack is not to break [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>When Your Browser Becomes the Attacker: Detecting Drive-By Script Execution in the Wild</title>
		<link>https://warroom.rsmus.com/when-your-browser-becomes-the-attacker-detecting-drive-by-script-execution-in-the-wild/</link>
		
		<dc:creator><![CDATA[Justin Dolgos]]></dc:creator>
		<pubDate>Wed, 11 Mar 2026 19:46:54 +0000</pubDate>
				<category><![CDATA[Defense]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6331</guid>

					<description><![CDATA[Published by The RSM Defense Threat Hunting Team Author: Justin Dolgos &#8211; Sr. Threat Hunter MITRE ATT&#38;CK: T1204.002 · T1059 · T1218 · T1219 · T1222 &#160; ⚠  TLDR Executive Summary Our threat hunters built a custom detection that fires the moment a browser or Windows Explorer spawns a script or suspicious executable from a [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>Fake Captcha Chains – Portable Behaviors, Practical Detections, And Field Notes</title>
		<link>https://warroom.rsmus.com/fake-captcha-chains/</link>
		
		<dc:creator><![CDATA[Justin Dolgos]]></dc:creator>
		<pubDate>Tue, 14 Oct 2025 18:28:19 +0000</pubDate>
				<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Fake Captcha]]></category>
		<category><![CDATA[Fake Captcha Chains]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6301</guid>

					<description><![CDATA[Executive Summary RSM Defense’s Threat Hunting Team performed a focused investigation after reviewing recent intelligence on the “Fake CAPTCHA” campaign. Our hypothesis was: “If the actor is in the environment, we may observe escaped or obfuscated PowerShell commands (for example h^t^t^p) used to download and stage payloads.” The hunt confirmed activity that occurred over a [&#8230;]]]></description>
		
		
		
			</item>
	</channel>
</rss>
