<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Security-Operations on Compile My Mind</title>
		<link>https://www.compilemymind.com/tags/security-operations/</link>
		<description>Recent content in Security-Operations on Compile My Mind</description>
		<generator>Hugo</generator>
		<language>en</language>
		
		
		
		
			<lastBuildDate>Sun, 14 Jun 2026 09:31:00 +0300</lastBuildDate>
		
			<atom:link href="https://www.compilemymind.com/tags/security-operations/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>SIEM vs XDR vs SOAR: What They Do and When to Use Each</title>
				<link>https://www.compilemymind.com/posts/siem-vs-xdr-vs-soar/</link>
				<pubDate>Sun, 14 Jun 2026 09:31:00 +0300</pubDate>
				<guid>https://www.compilemymind.com/posts/siem-vs-xdr-vs-soar/</guid>
				<description>&lt;p&gt;Security teams have more telemetry than ever: endpoint alerts, identity logs, firewall events, email detections, cloud audit trails, SaaS activity, vulnerability data, DNS logs, EDR timelines, and threat intelligence feeds. The hard part is not only collecting that data. The hard part is turning it into decisions fast enough to stop an incident.&lt;/p&gt;&#xA;&lt;p&gt;That is where &lt;strong&gt;SIEM&lt;/strong&gt;, &lt;strong&gt;XDR&lt;/strong&gt;, and &lt;strong&gt;SOAR&lt;/strong&gt; come in.&lt;/p&gt;&#xA;&lt;p&gt;They are often discussed together because they all live in the security operations center (SOC), but they are not the same thing:&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
