<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>badsignals</title><link>https://badsignals.pages.dev/</link><description>Recent content on badsignals</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://badsignals.pages.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Hello</title><link>https://badsignals.pages.dev/posts/hello/</link><pubDate>Thu, 27 Aug 2026 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/posts/hello/</guid><description>&lt;p&gt;This is where I&amp;rsquo;ll write about detection engineering, log pipelines, and&#10;whatever broke at 2am and turned out to be interesting.&lt;/p&gt;&#10;&lt;p&gt;More soon.&lt;/p&gt;</description></item><item><title>about</title><link>https://badsignals.pages.dev/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/about/</guid><description>&lt;p&gt;Hi,&lt;/p&gt;&#10;&lt;p&gt;My name is Miguel Cardoso, born in 22-09-2026, connected to the internet ever since I can remember.&lt;/p&gt;&#10;&lt;p&gt;I speak Portuguese, English, Spanish, and I&amp;rsquo;m currently learning German. With computers, I mainly speak Python, and I&amp;rsquo;m learning the basics of the beautiful C language.&lt;/p&gt;&#10;&lt;p&gt;I&amp;rsquo;m completely self-taught.&lt;/p&gt;&#10;&lt;p&gt;I work as a CSIRT engineer at a managed security provider, mostly on&#10;detection engineering and log pipelines across a multi-tenant SOC.&lt;/p&gt;&#10;&lt;h2 id="about-this-blog" id="about-this-blog"&gt;&#10; &lt;a class="anchor" href="#about-this-blog" aria-label="Link to this section"&gt;##&lt;/a&gt;&#10; about this blog&#10;&lt;/h2&gt;&#10;&lt;p&gt;This site is where I write things down so I stop re-deriving them. Most&#10;posts start as something that broke at 2am and ended up being interesting.&lt;/p&gt;</description></item><item><title>contact</title><link>https://badsignals.pages.dev/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/contact/</guid><description>&lt;ul&gt;&#10;&lt;li&gt;email: &lt;a href="mailto:miguelamcard@gmail.com"&gt;miguelamcard@gmail.com&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;github: &lt;a href="https://github.com/your-user"&gt;github.com/your-user&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;rss: &lt;a href="https://badsignals.pages.dev/index.xml"&gt;/index.xml&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Nothing here is my employer&amp;rsquo;s position.&lt;/p&gt;</description></item><item><title>now</title><link>https://badsignals.pages.dev/now/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/now/</guid><description>&lt;p&gt;Last updated 2026-08-27.&lt;/p&gt;&#10;&lt;p&gt;Working detection engineering and log pipeline problems across a&#10;multi-tenant SOC — mostly FortiGate, rsyslog, and Splunk right now, with&#10;Entra ID sign-in and consent-grant detections in the mix.&lt;/p&gt;&#10;&lt;p&gt;Outside of that: getting more comfortable in C, and picking up German.&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://badsignals.pages.dev/posts/"&gt;posts&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="https://badsignals.pages.dev/uses/"&gt;uses&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;</description></item><item><title>projects</title><link>https://badsignals.pages.dev/projects/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/projects/</guid><description>&lt;p&gt;Nothing published here yet — most of what I build lives inside client&#10;environments and can&amp;rsquo;t be shared as-is.&lt;/p&gt;&#10;&lt;p&gt;When something&amp;rsquo;s generalisable enough to release (a Sigma rule, a parsing&#10;config, a small tool), it&amp;rsquo;ll show up here first.&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="https://github.com/your-user"&gt;github&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;</description></item><item><title>uses</title><link>https://badsignals.pages.dev/uses/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://badsignals.pages.dev/uses/</guid><description>&lt;p&gt;A short list of what shows up most in the posts here.&lt;/p&gt;&#10;&lt;h2 id="detection--log-pipelines" id="detection--log-pipelines"&gt;&#10; &lt;a class="anchor" href="#detection--log-pipelines" aria-label="Link to this section"&gt;##&lt;/a&gt;&#10; detection &amp;amp; log pipelines&#10;&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;FortiGate syslog, normalised before it hits the index&lt;/li&gt;&#10;&lt;li&gt;rsyslog as the collector/forwarder layer&lt;/li&gt;&#10;&lt;li&gt;Splunk for search and detections&lt;/li&gt;&#10;&lt;li&gt;Microsoft Entra ID sign-in and consent-grant logs via KQL&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="languages" id="languages"&gt;&#10; &lt;a class="anchor" href="#languages" aria-label="Link to this section"&gt;##&lt;/a&gt;&#10; languages&#10;&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Python, day to day&lt;/li&gt;&#10;&lt;li&gt;C, still learning&lt;/li&gt;&#10;&lt;/ul&gt;</description></item></channel></rss>