<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Detection on BlueSquadron — Security engineering for AI systems</title><link>https://bluesquadron.dev/tags/detection/</link><description>Recent content in Detection on BlueSquadron — Security engineering for AI systems</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>florent.batard@gmail.com (Florent Batard)</managingEditor><webMaster>florent.batard@gmail.com (Florent Batard)</webMaster><lastBuildDate>Tue, 04 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bluesquadron.dev/tags/detection/index.xml" rel="self" type="application/rss+xml"/><item><title>Secrust: When Adding Cores Made It Slower</title><link>https://bluesquadron.dev/posts/secrust-when-adding-cores-made-it-slower/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><author>florent.batard@gmail.com (Florent Batard)</author><guid>https://bluesquadron.dev/posts/secrust-when-adding-cores-made-it-slower/</guid><description>A single-process Sigma correlation engine in Rust. Eight optimisation passes took the realistic workload up 301% — and then four threads made it 23% slower than two. Why that happened, what I shipped as the default, and the things I decided not to build.</description></item><item><title>Cutting 90% of the Noise: Agent-Driven Security Operations</title><link>https://bluesquadron.dev/posts/agent-driven-security-operations/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><author>florent.batard@gmail.com (Florent Batard)</author><guid>https://bluesquadron.dev/posts/agent-driven-security-operations/</guid><description>Tuning detections until the volume fits your headcount means choosing your visibility based on your staffing. The fix is not more analysts — it is separating the three layers of triage by what each one is allowed to be wrong about.</description></item></channel></rss>