
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Mansour Jalaly — Security Engineering</title>
      <link>https://jalaly.com/blog</link>
      <description>Mansour Jalaly is a London-based security engineer specialising in detection engineering, cloud security, incident response, and threat intelligence. CISSP and GSEC certified, with experience across Oracle and S-RM.</description>
      <language>en-gb</language>
      <managingEditor>mansour@jalaly.com (Mansour Jalaly)</managingEditor>
      <webMaster>mansour@jalaly.com (Mansour Jalaly)</webMaster>
      <lastBuildDate>Thu, 28 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://jalaly.com/tags/detection-engineering/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://jalaly.com/blog/project-vivarium</guid>
    <title>Project Vivarium: AI Agents as Red Team and Blue Team</title>
    <link>https://jalaly.com/blog/project-vivarium</link>
    <description>An experiment in adversarial AI: local, air-gapped agent crews playing attacker and defender against each other in a sealed, fully observable lab.</description>
    <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    <author>mansour@jalaly.com (Mansour Jalaly)</author>
    <category>AI</category><category>Agents</category><category>Red Team</category><category>Blue Team</category><category>Detection Engineering</category><category>Project Vivarium</category>
  </item>

  <item>
    <guid>https://jalaly.com/blog/detection-as-code</guid>
    <title>Detection as Code: Treating Your Rules Like Software</title>
    <link>https://jalaly.com/blog/detection-as-code</link>
    <description>Version control, CI testing, and ATT&amp;CK coverage mapping turned a folder of SIEM rules into an engineering discipline. What changed, what it cost, and what I would do differently.</description>
    <pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate>
    <author>mansour@jalaly.com (Mansour Jalaly)</author>
    <category>Detection Engineering</category><category>Detection as Code</category><category>Sigma</category><category>MITRE ATT&CK</category><category>CI/CD</category>
  </item>

  <item>
    <guid>https://jalaly.com/blog/ai-in-the-soc</guid>
    <title>Where AI Actually Helps in the SOC — and Where It Does Not</title>
    <link>https://jalaly.com/blog/ai-in-the-soc</link>
    <description>Lessons from building ML-assisted detection in production: the places machine learning genuinely moves the needle, and the places it quietly makes things worse.</description>
    <pubDate>Fri, 22 Aug 2025 00:00:00 GMT</pubDate>
    <author>mansour@jalaly.com (Mansour Jalaly)</author>
    <category>AI</category><category>Machine Learning</category><category>Security Operations</category><category>Detection Engineering</category><category>SOC</category>
  </item>

    </channel>
  </rss>
