<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Ryan Williams</title>
  <subtitle>Detection Engineering &amp; Cloud Security</subtitle>
  <link href="https://rwilliams.dev/feed.xml" rel="self"/>
  <link href="https://rwilliams.dev/"/>
  <id>https://rwilliams.dev/</id>
  <updated>2026-10-01T17:44:05+00:00</updated>
  <author><name>Ryan Williams</name></author>
  <entry>
    <title>FedRAMP 2026 vulnerability deadlines, worked through a real scan</title>
    <link href="https://rwilliams.dev/article/fedramp-2026-vulnerability-evaluation/"/>
    <id>https://rwilliams.dev/article/fedramp-2026-vulnerability-evaluation/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Severity-based deadlines are gone. How the new exploitability, reachability and impact evaluation changes what is due when, and how I built a first pass of it into VulnAnalyzer.</summary>
  </entry>
  <entry>
    <title>Five CloudTrail detections to deploy first</title>
    <link href="https://rwilliams.dev/article/cloudtrail-detections/"/>
    <id>https://rwilliams.dev/article/cloudtrail-detections/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Logging tampering, root use, console logins without MFA, credentials created for someone else, and resources opened to the internet. Splunk and Sentinel queries with tuning notes.</summary>
  </entry>
  <entry>
    <title>Catching shadow copy deletion before the encryption starts</title>
    <link href="https://rwilliams.dev/article/inhibit-system-recovery/"/>
    <id>https://rwilliams.dev/article/inhibit-system-recovery/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>One detection for vssadmin, wmic, wbadmin, bcdedit and PowerShell recovery tampering (T1490), written for Splunk, Sentinel and Elastic.</summary>
  </entry>
  <entry>
    <title>Detecting ransomware encryption by behavior, not file extension</title>
    <link href="https://rwilliams.dev/article/ransomware-encryption/"/>
    <id>https://rwilliams.dev/article/ransomware-encryption/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Why extension watchlists fail, and two behavioral detections that hold up: mass renames that collapse many file types into one, and the same note dropped in every folder.</summary>
  </entry>
  <entry>
    <title>AD account deletion: turning event 4726 into a useful alert</title>
    <link href="https://rwilliams.dev/article/ad-account-deletion/"/>
    <id>https://rwilliams.dev/article/ad-account-deletion/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Alerting on every deletion is noise. Three variants that carry signal: who deleted what, bulk deletion, and accounts created and deleted within a day.</summary>
  </entry>
  <entry>
    <title>FedRAMP&#39;s 2026 rules: what changes for continuous monitoring</title>
    <link href="https://rwilliams.dev/article/fedramp-2026/"/>
    <id>https://rwilliams.dev/article/fedramp-2026/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>POA&amp;Ms are gone, ConMon is now Ongoing Certification, and impact levels became classes. A summary of the Consolidated Rules for 2026 and the dates that matter.</summary>
  </entry>
  <entry>
    <title>One-liners for triage</title>
    <link href="https://rwilliams.dev/article/triage-one-liners/"/>
    <id>https://rwilliams.dev/article/triage-one-liners/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Short Python, Bash and PowerShell snippets for hashing, pulling URLs, checking listeners, startup items and AD password expiry.</summary>
  </entry>
  <entry>
    <title>What makes a SOC analyst stand out</title>
    <link href="https://rwilliams.dev/article/analyst-tips/"/>
    <id>https://rwilliams.dev/article/analyst-tips/</id>
    <updated>2026-10-01T00:00:00+00:00</updated>
    <summary>Six habits that separate analysts who close alerts from analysts who improve the SOC.</summary>
  </entry>
</feed>