<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
    <title>BabySOARus Blog</title>
    <link>https://babysoarus.hisn.io/blog/</link>
    <description>Engineering notes and straight answers.</description>
    <item>
      <title>We Sandboxed Python Inside Splunk</title>
      <link>https://babysoarus.hisn.io/blog/sandboxing-python-inside-splunk.html</link>
      <guid>https://babysoarus.hisn.io/blog/sandboxing-python-inside-splunk.html</guid>
      <pubDate>Thu, 27 Aug 2026 09:00:00 GMT</pubDate>
      <description>Real Python in the search bar, inside a WebAssembly sandbox, with microseconds of warm overhead. How, why, and the parts that fought back.</description>
    </item>
    <item>
      <title>What Happens When You Stop Paying for Your SOAR?</title>
      <link>https://babysoarus.hisn.io/blog/when-you-stop-paying.html</link>
      <guid>https://babysoarus.hisn.io/blog/when-you-stop-paying.html</guid>
      <pubDate>Thu, 27 Aug 2026 09:00:00 GMT</pubDate>
      <description>A published price in a market with none, and expiry behaviour bound in the contract: searches keep running, nothing is deleted, and your detection estate is not a hostage.</description>
    </item>
    <item>
      <title>The Hidden Column in splunkd's Protocol</title>
      <link>https://babysoarus.hisn.io/blog/splunkd-hidden-column.html</link>
      <guid>https://babysoarus.hisn.io/blog/splunkd-hidden-column.html</guid>
      <pubDate>Thu, 27 Aug 2026 09:00:00 GMT</pubDate>
      <description>sorted(events) broke at row 36 with an error no documentation mentions. The answer was inside the splunkd binary, one strings invocation away.</description>
    </item>
</channel></rss>
