<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Jacob Santos - Blog</title><description>Threat research, security automation, and cybersecurity insights.</description><link>https://jacobsantos.pages.dev/</link><item><title>Infrastructure Hunting Beyond IOCs</title><link>https://jacobsantos.pages.dev/blog/2026-02-05-infrastructure-hunting-beyond-iocs/</link><guid isPermaLink="true">https://jacobsantos.pages.dev/blog/2026-02-05-infrastructure-hunting-beyond-iocs/</guid><description>Moving up the Pyramid of Pain — from hash-based detection to hunting adversary infrastructure through behavioral fingerprints and network patterns.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>MCP Servers for Threat Intelligence</title><link>https://jacobsantos.pages.dev/blog/2026-01-15-building-mcp-servers/</link><guid isPermaLink="true">https://jacobsantos.pages.dev/blog/2026-01-15-building-mcp-servers/</guid><description>How I set up Model Context Protocol servers to bridge AI assistants with threat intelligence platforms — and what I learned about tool design along the way.</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate></item><item><title>What Ransomware Hunting Actually Looks Like</title><link>https://jacobsantos.pages.dev/blog/2025-12-08-ransomware-hunting-daily-workflow/</link><guid isPermaLink="true">https://jacobsantos.pages.dev/blog/2025-12-08-ransomware-hunting-daily-workflow/</guid><description>The daily reality of proactive ransomware hunting — from YARA triggers and VirusTotal dashboards to naming new families and building attack chains from telemetry.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Automating Inquiry Triage with AI</title><link>https://jacobsantos.pages.dev/blog/2025-11-10-automating-inquiry-triage/</link><guid isPermaLink="true">https://jacobsantos.pages.dev/blog/2025-11-10-automating-inquiry-triage/</guid><description>How I built a 9-phase AI pipeline to handle threat intelligence inquiries that used to take a week — and what it taught me about building tools from real pain points.</description><pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate></item><item><title>From OSINT to Internal Hunting</title><link>https://jacobsantos.pages.dev/blog/2025-09-20-from-osint-to-internal-hunting/</link><guid isPermaLink="true">https://jacobsantos.pages.dev/blog/2025-09-20-from-osint-to-internal-hunting/</guid><description>How shifting from external OSINT to internal telemetry hunting changed the way I approach threat research — and where most of my published work actually comes from.</description><pubDate>Sat, 20 Sep 2025 00:00:00 GMT</pubDate></item></channel></rss>