<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://jon.glass/blog/sharpening-the-acks/</loc>
<lastmod>2013-03-29T19:24:43+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/war-driving/</loc>
<lastmod>2013-07-08T08:41:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/lists-tshark-commands/</loc>
<lastmod>2013-07-10T06:55:14+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/talks_about_sysmon/</loc>
<lastmod>2014-08-29T07:24:59+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/shows-more-process-mapping-crap/</loc>
<lastmod>2014-09-12T07:24:37+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/uses_his_github/</loc>
<lastmod>2014-09-15T07:17:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/offers-remote-process-mapping-with-wmi/</loc>
<lastmod>2014-09-17T08:54:29+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/mentions-lfo-with-powershell/</loc>
<lastmod>2014-09-24T06:06:35+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/queries-sysmon-for-execution-times/</loc>
<lastmod>2014-09-25T23:28:50+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/reads-e-mail-with-powershell/</loc>
<lastmod>2014-09-29T16:32:27+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/get-internet-headers-from-mailitem-in-powershell/</loc>
<lastmod>2014-10-08T07:44:41+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/talks-about-zip-files/</loc>
<lastmod>2014-11-14T05:05:03+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/makes-zip-seeking-missile/</loc>
<lastmod>2014-11-22T05:03:37+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/has-fun-with-zlib/</loc>
<lastmod>2014-11-25T21:33:47+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/attempts-to-parse-webcachev01-dat/</loc>
<lastmod>2014-12-10T14:48:36+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/misadventures-in-parsing-the-webcachev01-dat-part-2/</loc>
<lastmod>2014-12-10T22:02:37+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/misadventures-in-parsing-the-webcachev01-dat-part-3/</loc>
<lastmod>2014-12-15T04:04:53+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/discovers-stupid-vbs-tricks/</loc>
<lastmod>2014-12-28T20:19:03+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/discusses-sysmon-v2/</loc>
<lastmod>2015-01-21T16:09:07+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/discusses-sysmon-v2-filtering-rules/</loc>
<lastmod>2015-02-03T03:33:48+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/looks-at-the-win10-boot-process/</loc>
<lastmod>2015-02-17T03:03:50+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/posts-a-few-sysmonmaps-for-referrence/</loc>
<lastmod>2015-02-17T13:08:59+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/mass-undelete-from-the-recycle-bin/</loc>
<lastmod>2015-02-20T16:03:47+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/notes-about-windows-process-ids/</loc>
<lastmod>2015-02-20T16:05:14+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/examines-usb-transfer-cable/</loc>
<lastmod>2015-02-28T03:07:21+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/34-file-entries-on-a-brand-new-mft/</loc>
<lastmod>2015-03-03T02:51:08+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/lists-some-wmic-commands/</loc>
<lastmod>2015-03-13T19:48:48+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/analyzes-dridex-malware-p1/</loc>
<lastmod>2015-03-20T15:11:48+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/analyzes-dridex-malware-p2/</loc>
<lastmod>2015-03-23T23:01:16+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/uses-python-to-encrypt-huge-files/</loc>
<lastmod>2015-05-29T03:42:25+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/adventure-in-parsing-the-webcachev01-dat/</loc>
<lastmod>2015-09-28T10:07:59+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/parses-chrome-stuff-with-python/</loc>
<lastmod>2015-10-09T03:03:41+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/parsing-chrome-artifacts-with-python-part-2/</loc>
<lastmod>2015-10-11T13:28:03+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/parsing-chrome-artifacts-with-python-part-3/</loc>
<lastmod>2015-10-25T23:55:08+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/quarantines-junk/</loc>
<lastmod>2015-11-03T04:34:30+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/reviews_mastering_python_forensics/</loc>
<lastmod>2015-11-25T02:01:16+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Unxoring-a-rat/</loc>
<lastmod>2016-02-05T19:52:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/TwasTheGrepBeforeXmas/</loc>
<lastmod>2016-12-27T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/RogueUsers/</loc>
<lastmod>2017-02-03T19:52:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/My_ELK_Stack/</loc>
<lastmod>2017-03-07T00:52:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/My_ELK_Stack2/</loc>
<lastmod>2017-03-11T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/grep-like-you-mean-it/</loc>
<lastmod>2017-03-11T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/tips/FullEventLogView/</loc>
<lastmod>2018-02-19T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/tips/ChangeBitlockerKeys/</loc>
<lastmod>2018-02-20T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/tips/LookForWindowsTimestamps/</loc>
<lastmod>2018-02-20T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/adfirwmc/Ch0/</loc>
<lastmod>2018-03-01T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/adfirwmc/Ch1/</loc>
<lastmod>2018-03-02T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/adfirwmc/Ch2/</loc>
<lastmod>2018-03-03T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/adfirwmc/Ch3/</loc>
<lastmod>2018-03-04T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/adfirwmc/Ch4/</loc>
<lastmod>2018-03-05T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Hacking-BRBbot/</loc>
<lastmod>2018-12-08T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Fiesta-Analysis/</loc>
<lastmod>2018-12-26T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/CyberChef-Slides-From-RVASec/</loc>
<lastmod>2019-06-23T20:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/AutoITXOR/</loc>
<lastmod>2020-03-15T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/BotTricker/</loc>
<lastmod>2020-03-24T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/MDEAPIMFA/</loc>
<lastmod>2022-03-06T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Building-API-Wrapper/</loc>
<lastmod>2022-03-09T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/MDE-Live-Response-via-API/</loc>
<lastmod>2022-03-10T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Running-Arbitrary-Commands/</loc>
<lastmod>2022-03-13T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/Live-Response-Kernel-Access/</loc>
<lastmod>2022-03-13T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/blog/chatgpt-writes-the-blog/</loc>
<lastmod>2023-02-27T17:33:28+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/ADFIRWMC/Whole%20Course/</loc>
</url>
<url>
<loc>https://jon.glass/</loc>
</url>
<url>
<loc>https://jon.glass/tags/</loc>
</url>
<url>
<loc>https://jon.glass/theme-setup/</loc>
</url>
<url>
<loc>https://jon.glass/tips/</loc>
</url>
<url>
<loc>https://jon.glass/adfirwmc/</loc>
</url>
<url>
<loc>https://jon.glass/blog/</loc>
</url>
<url>
<loc>https://jon.glass/about/</loc>
</url>
<url>
<loc>https://jon.glass/PlaybookChef/BundleAnalyzerReport.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/PlaybookChef/</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/2604052_PM_EN.pdf</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/Win10-Sysmonmap.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/Win7SysmonMap.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/Win8SysmonMap.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/Windows10-sysmonmap.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
<url>
<loc>https://jon.glass/images/sysmonmap-Win10x64.html</loc>
<lastmod>2025-09-01T19:23:51+00:00</lastmod>
</url>
</urlset>
