<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>ThreatLab Blog</title>
        <link>https://threatlabsandbox.com/blog/</link>
        <description>Malware analysis, sandboxing, and detection engineering notes from the team building ThreatLab.</description>
        <language>en-us</language>
        <lastBuildDate>Thu, 08 Oct 2026 12:00:00 GMT</lastBuildDate>
        <docs>https://www.rssboard.org/rss-specification</docs>
        <atom:link href="https://threatlabsandbox.com/blog/feed.xml" rel="self" type="application/rss+xml" />
        <item>
            <title>Building a malware sandbox on Hyper-V: the problems nobody documents</title>
            <link>https://threatlabsandbox.com/blog/malware-sandbox-hyper-v/</link>
            <guid isPermaLink="true">https://threatlabsandbox.com/blog/malware-sandbox-hyper-v/</guid>
            <pubDate>Thu, 08 Oct 2026 12:00:00 GMT</pubDate>
            <description>Most guides to building a malware lab start with VirtualBox or VMware. We built on Hyper-V instead and found almost nothing written about it. What the platform actually gives you for telemetry, containment and fast resets - and the quirk that will quietly take your ports.</description>
            <dc:creator>Andrew, ThreatLab Founder</dc:creator>
        </item>        
        <item>
            <title>Analyzing suspicious files under CMMC: the boundary problem</title>
            <link>https://threatlabsandbox.com/blog/cmmc-malware-analysis/</link>
            <guid isPermaLink="true">https://threatlabsandbox.com/blog/cmmc-malware-analysis/</guid>
            <pubDate>Wed, 24 Jun 2026 12:00:00 GMT</pubDate>
            <description>When a suspicious file shows up in a CMMC-scoped environment, where do you actually analyze it? Uploading to a cloud sandbox can move CUI outside your boundary - exactly what the framework exists to prevent. A look at the analysis-boundary problem and the considerations behind it.</description>
            <dc:creator>Andrew, ThreatLab Founder</dc:creator>
        </item>
        <item>
            <title>Living off the land: how attackers use your own tools against you</title>
            <link>https://threatlabsandbox.com/blog/lolbins-living-off-the-land/</link>
            <guid isPermaLink="true">https://threatlabsandbox.com/blog/lolbins-living-off-the-land/</guid>
            <pubDate>Wed, 03 Jun 2026 12:00:00 GMT</pubDate>
            <description>A lot of modern intrusions don&apos;t involve a foreign binary at all - attackers use programs already on the machine, signed by Microsoft, used legitimately every day. What LOLBins are, why they work, and what catching them actually looks like.</description>
            <dc:creator>Andrew, ThreatLab Founder</dc:creator>
        </item>
        <item>
            <title>Command and control in 2026: how malware actually phones home</title>
            <link>https://threatlabsandbox.com/blog/c2-in-2026/</link>
            <guid isPermaLink="true">https://threatlabsandbox.com/blog/c2-in-2026/</guid>
            <pubDate>Sun, 24 May 2026 12:00:00 GMT</pubDate>
            <description>Most people&apos;s mental model of malware C2 hasn&apos;t moved in a decade. A tour of where C2 actually lives now - DGAs, fast-flux, legitimate services as channels, DoH abuse, traffic mimicry - and what catching it requires.</description>
            <dc:creator>Andrew, ThreatLab Founder</dc:creator>
        </item>
        <item>
            <title>Cloud sandbox vs local sandbox: which is right for your team?</title>
            <link>https://threatlabsandbox.com/blog/cloud-vs-local-sandbox/</link>
            <guid isPermaLink="true">https://threatlabsandbox.com/blog/cloud-vs-local-sandbox/</guid>
            <pubDate>Tue, 19 May 2026 12:00:00 GMT</pubDate>
            <description>Both have real strengths. A direct look at where each one wins, when each one loses, and a framework for picking the right tool for your team.</description>
            <dc:creator>Andrew, ThreatLab Founder</dc:creator>
        </item>
    </channel>
</rss>
