<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Threat Machines</title>
    <link>https://threatmachines.com/</link>
    <description>Essays on threat intelligence and threat modelling: design-time modelling, intelligence requirements, attribution, adversary infrastructure tracking, attacker economics, and tabletop exercises.</description>
    <language>en</language>
    <atom:link href="https://threatmachines.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Threat, Vulnerability, Risk — Three Words, Three Jobs</title>
      <link>https://threatmachines.com/threat-vulnerability-risk-three-words/</link>
      <guid isPermaLink="true">https://threatmachines.com/threat-vulnerability-risk-three-words/</guid>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <category>Fundamentals</category>
      <description>The three terms are used interchangeably and they describe different objects with different owners. The confusion is not pedantry; it shows up directly in how budgets get argued.</description>
    </item>
    <item>
      <title>A Tabletop That Fails Is Working</title>
      <link>https://threatmachines.com/a-tabletop-that-fails-is-working/</link>
      <guid isPermaLink="true">https://threatmachines.com/a-tabletop-that-fails-is-working/</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate>
      <category>Exercises</category>
      <description>An exercise that everyone passes has told you nothing. The value is in the decisions nobody could make, the dependency nobody had mapped, and the question nobody could answer.</description>
    </item>
    <item>
      <title>The Adversary Has a Budget</title>
      <link>https://threatmachines.com/the-adversary-has-a-budget/</link>
      <guid isPermaLink="true">https://threatmachines.com/the-adversary-has-a-budget/</guid>
      <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
      <category>Adversary Economics</category>
      <description>Intrusions have a cost structure — access, tooling, infrastructure, labour, time and the risk of burning a capability. Controls work by moving one of those lines, and most programmes never ask which.</description>
    </item>
    <item>
      <title>Infrastructure Outlives the Payload</title>
      <link>https://threatmachines.com/infrastructure-outlives-the-payload/</link>
      <guid isPermaLink="true">https://threatmachines.com/infrastructure-outlives-the-payload/</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate>
      <category>Adversary Tracking</category>
      <description>A file hash changes for free; a hosting arrangement does not. Tracking the machinery an operation has to keep standing is slower, harder to automate, and considerably more durable.</description>
    </item>
    <item>
      <title>Attribution Is Fascinating; Ask What It Changes</title>
      <link>https://threatmachines.com/attribution-and-the-decision-it-changes/</link>
      <guid isPermaLink="true">https://threatmachines.com/attribution-and-the-decision-it-changes/</guid>
      <pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate>
      <category>Attribution</category>
      <description>Naming the adversary satisfies something real, but most incident decisions are identical whoever is behind the keyboard. The useful question is which specific choice would differ.</description>
    </item>
    <item>
      <title>Why Purchased Threat Intelligence Sits Unread</title>
      <link>https://threatmachines.com/why-threat-feeds-go-unread/</link>
      <guid isPermaLink="true">https://threatmachines.com/why-threat-feeds-go-unread/</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Intelligence Programmes</category>
      <description>Most intelligence feeds fail not because the data is bad but because nobody defined the decision the data was supposed to inform. Requirements first, subscriptions second.</description>
    </item>
    <item>
      <title>Threat Modelling Is Design Work, Not Review Work</title>
      <link>https://threatmachines.com/threat-modelling-is-design-work/</link>
      <guid isPermaLink="true">https://threatmachines.com/threat-modelling-is-design-work/</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <category>Threat Modelling</category>
      <description>A threat model produced after the architecture is fixed can only describe problems. Produced while the boxes and arrows are still soft, it changes them — which is the whole point.</description>
    </item>
  </channel>
</rss>
