<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://www.stephenshaffer.io/blog/determining-epss-score-thresholds-for-prioritization</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/flipping-the-vulnerability-management-model-cvss-ssvc</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/hacking-reality-why-data-science-is-the-blue-teams-ultimate-exploit</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/introducing-the-local-exploit-hazard-model</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/learning-how-to-quantify-risk-using-bayes</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/modeling-asset-risk-using-epss</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/quantifying-swiss-cheese-the-bayesian-way</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/sabermetrics-and-cyber-risk-quantification</loc></url>
  <url><loc>https://www.stephenshaffer.io/blog/vulnerability-information-cones</loc></url>
  <url><loc>https://www.stephenshaffer.io/code</loc></url>
  <url><loc>https://www.stephenshaffer.io/</loc></url>
  <url><loc>https://www.stephenshaffer.io/research</loc></url>
</urlset>
