<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library Research Blog</title>
    <link>https://cyberattackcaselibrary.pages.dev/blog/</link>
    <description>Analysis of court indictments, primary evidence, and adversary techniques.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 25 Sep 2026 00:07:43 GMT</lastBuildDate>
    <atom:link href="https://cyberattackcaselibrary.pages.dev/blog/rss.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Walkthrough of a Well-Documented Case: Sandworm and NotPetya]]></title>
      <link>https://cyberattackcaselibrary.pages.dev/blog/walkthrough-of-a-well-documented-case-notpetya-sandworm/</link>
      <guid>https://cyberattackcaselibrary.pages.dev/blog/walkthrough-of-a-well-documented-case-notpetya-sandworm/</guid>
      <description><![CDATA[A detailed forensic breakdown of the October 2020 federal indictment of Russian GRU Unit 74455 officers for NotPetya, Olympic Destroyer, and electric grid attacks.]]></description>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
      <author>Cyberattack Case Library Research Team</author>
    </item>
    <item>
      <title><![CDATA[Why Prosecution Records Are a Better Teaching Source Than News]]></title>
      <link>https://cyberattackcaselibrary.pages.dev/blog/why-prosecution-records-are-a-better-teaching-source-than-news/</link>
      <guid>https://cyberattackcaselibrary.pages.dev/blog/why-prosecution-records-are-a-better-teaching-source-than-news/</guid>
      <description><![CDATA[News headlines often distort cyber incidents through speculation and anonymous quotes. Primary prosecution records provide sworn evidence and verifiable technical facts.]]></description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <author>Cyberattack Case Library Research Team</author>
    </item>
    <item>
      <title><![CDATA[How to Read an Indictment for Technique Evidence]]></title>
      <link>https://cyberattackcaselibrary.pages.dev/blog/how-to-read-an-indictment-for-technique-evidence/</link>
      <guid>https://cyberattackcaselibrary.pages.dev/blog/how-to-read-an-indictment-for-technique-evidence/</guid>
      <description><![CDATA[A practitioner guide to locating verified adversary techniques, initial access vectors, and persistence mechanisms in federal criminal indictments.]]></description>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
      <author>Cyberattack Case Library Research Team</author>
    </item>
  </channel>
</rss>