<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">

  <!-- Homepage -->
  <url>
    <loc>https://zonforge.com/</loc>
    <image:image>
      <image:loc>https://zonforge.com/logo-zonforge.png</image:loc>
      <image:title>ZonForge Sentinel — AI-Native Cybersecurity Platform</image:title>
      <image:caption>ZonForge Sentinel platform logo</image:caption>
    </image:image>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>ZonForge Sentinel — AI SOC Analyst, Threat Detection &amp; Security Automation</image:title>
      <image:caption>ZonForge Sentinel platform overview — AI-powered SOC, threat detection, behavioral analytics</image:caption>
    </image:image>
  </url>

  <!-- Blog index -->
  <url>
    <loc>https://zonforge.com/blog/</loc>
    <image:image>
      <image:loc>https://zonforge.com/logo-zonforge.png</image:loc>
      <image:title>ZonForge Security Blog</image:title>
      <image:caption>Practical cybersecurity insights from the ZonForge Sentinel team</image:caption>
    </image:image>
  </url>

  <!-- AI SOC posts -->
  <url>
    <loc>https://zonforge.com/blog/ai-soc-analyst-end-alert-fatigue</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>How an AI SOC Analyst Ends Alert Fatigue</image:title>
      <image:caption>AI SOC Analyst automates alert triage to reduce false positives and analyst burnout</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/automated-alert-triage</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Automated Alert Triage: How AI Is Replacing Tier-1 SOC Analysis</image:title>
      <image:caption>AI-powered automated alert triage replaces manual Tier-1 SOC analysis</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/what-is-autonomous-soc</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>What Is an Autonomous SOC?</image:title>
      <image:caption>The 5 levels of SOC autonomy and how to build toward a fully autonomous security operations center</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/soar-vs-ai-security-automation</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>SOAR vs AI Security Automation</image:title>
      <image:caption>SOAR vs AI-native automation comparison for security operations teams</image:caption>
    </image:image>
  </url>

  <!-- Threat Detection posts -->
  <url>
    <loc>https://zonforge.com/blog/behavioral-vs-signature-threat-detection</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Behavioral vs Signature-Based Threat Detection</image:title>
      <image:caption>Comparing behavioral analytics vs signature-based detection for modern cybersecurity threats</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/cloud-threat-detection-aws-azure-gcp</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Cloud Threat Detection: AWS, Azure, and GCP</image:title>
      <image:caption>Security monitoring guidance for AWS, Azure, and GCP cloud environments</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/how-to-write-detection-rules</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>How to Write Detection Rules That Work</image:title>
      <image:caption>Detection rule writing guide using SIGMA — quality over quantity to reduce alert noise</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/reduce-false-positives-security-monitoring</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>False Positive Reduction Playbook</image:title>
      <image:caption>Security engineering playbook for reducing false positive alerts in SOC environments</image:caption>
    </image:image>
  </url>

  <!-- Threat Intelligence posts -->
  <url>
    <loc>https://zonforge.com/blog/what-are-indicators-of-compromise</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Indicators of Compromise (IOCs) Guide</image:title>
      <image:caption>Complete guide to IOC types, the Pyramid of Pain model, and automated IOC correlation</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/operationalize-threat-intelligence-feeds</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>How to Operationalize Threat Intelligence Feeds</image:title>
      <image:caption>5-step process for operationalizing threat intelligence feeds without drowning in IOCs</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/threat-hunting-methodology</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Threat Hunting Methodology</image:title>
      <image:caption>Practical threat hunting framework for teams of any size using MITRE ATT&amp;CK</image:caption>
    </image:image>
  </url>

  <!-- Security Operations posts -->
  <url>
    <loc>https://zonforge.com/blog/soc-metrics-security-teams</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>12 SOC Metrics Every Security Team Should Track</image:title>
      <image:caption>Key SOC metrics including MTTD, MTTR, false positive rate, and analyst utilization</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/soc-maturity-model-explained</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>SOC Maturity Model Explained</image:title>
      <image:caption>5-level SOC maturity model from reactive to adaptive security operations</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/incident-response-workflow-guide</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Incident Response Workflow Guide</image:title>
      <image:caption>Complete NIST incident response workflow from first alert to closed case</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/investigate-security-alerts-faster</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Investigate Security Alerts 5x Faster</image:title>
      <image:caption>Context-first security alert investigation approach to reduce investigation time by 80%</image:caption>
    </image:image>
  </url>

  <!-- Cloud Security posts -->
  <url>
    <loc>https://zonforge.com/blog/aws-cloudtrail-security-monitoring</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>AWS CloudTrail Security Monitoring Guide</image:title>
      <image:caption>Critical AWS CloudTrail events for security monitoring — authentication, privilege escalation, data access</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/microsoft-365-security-monitoring</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Microsoft 365 Security Monitoring Guide</image:title>
      <image:caption>M365 audit log monitoring for BEC detection, OAuth grants, and Azure AD anomalies</image:caption>
    </image:image>
  </url>

  <!-- Identity Security posts -->
  <url>
    <loc>https://zonforge.com/blog/why-mfa-is-not-enough</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Why MFA Is Not Enough</image:title>
      <image:caption>MFA bypass techniques — fatigue attacks, AiTM phishing, session token theft — and what to do beyond MFA</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/privileged-access-risk-management</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Privileged Access Risk Management</image:title>
      <image:caption>PAM guide — privileged account discovery, JIT access, behavioral monitoring, and abuse detection</image:caption>
    </image:image>
  </url>

  <!-- Compliance posts -->
  <url>
    <loc>https://zonforge.com/blog/soc2-security-monitoring-requirements</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>SOC 2 Type II Security Monitoring Requirements</image:title>
      <image:caption>SOC 2 CC6, CC7, CC9 monitoring requirements and audit evidence package guidance</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/pci-dss-log-monitoring-guide</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>PCI DSS Log Monitoring Requirements</image:title>
      <image:caption>PCI DSS Requirement 10 log monitoring — what to log, daily review, retention, and v4.0 changes</image:caption>
    </image:image>
  </url>

  <!-- Category pages -->
  <url>
    <loc>https://zonforge.com/blog/threat-detection/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Threat Detection — ZonForge Security Blog</image:title>
      <image:caption>Behavioral detection, detection engineering, and false positive reduction articles</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/threat-intelligence/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Threat Intelligence — ZonForge Security Blog</image:title>
      <image:caption>IOCs, threat intel feeds, and threat hunting articles</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/security-operations/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Security Operations — ZonForge Security Blog</image:title>
      <image:caption>SOC metrics, maturity models, and incident response articles</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/cloud-security/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Cloud Security — ZonForge Security Blog</image:title>
      <image:caption>AWS, Azure, GCP, and M365 security monitoring articles</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/identity-security/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Identity Security — ZonForge Security Blog</image:title>
      <image:caption>MFA, privileged access, and insider threat articles</image:caption>
    </image:image>
  </url>

  <url>
    <loc>https://zonforge.com/blog/compliance/</loc>
    <image:image>
      <image:loc>https://zonforge.com/og-image.png</image:loc>
      <image:title>Compliance — ZonForge Security Blog</image:title>
      <image:caption>SOC 2, PCI DSS, and HIPAA security monitoring compliance articles</image:caption>
    </image:image>
  </url>

</urlset>
