<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Vassilis Mandrakis</title><description>Vassilis Mandrakis — CISO at the University of Western Macedonia, moving from defensive security operations to red team practice. Detection engineering, tradecraft, and field notes.</description><link>https://mandrakis.com/</link><language>en-us</language><item><title>Why this site, why now</title><link>https://mandrakis.com/blog/why-this-site/</link><guid isPermaLink="true">https://mandrakis.com/blog/why-this-site/</guid><description>After twenty years of doing security work quietly, a few words on why I&apos;m finally writing in public — and what I intend to put here.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>meta</category><category>career</category></item><item><title>Building a university SOC: Wazuh, MISP and CrowdSec</title><link>https://mandrakis.com/blog/building-a-university-soc/</link><guid isPermaLink="true">https://mandrakis.com/blog/building-a-university-soc/</guid><description>Why I built a detection-and-response stack from open-source parts instead of buying one, how the enrichment loop fits together, and two lessons that only show up once it&apos;s running in production.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>soc</category><category>detection-engineering</category><category>wazuh</category><category>threat-intelligence</category><category>blue-team</category></item></channel></rss>